
A penetration test is an authorised, controlled attempt to break into a system in order to find weaknesses before a real attacker does. The result is a report that tells you what was found, how serious it is and how to fix it.
Penetration test vs vulnerability scan
A vulnerability scan is automated. It checks systems against a list of known issues and is good at breadth. A penetration test adds human judgement: a tester chains weaknesses together, tries to exploit them and assesses real impact. Many engagements combine both, which is what the term VAPT refers to.
Authorisation comes first
Testing a system without permission is illegal in most places. A legitimate engagement starts with written authorisation from the owner of every in-scope asset, an agreed scope and rules of engagement.
The typical phases
- Scoping: agree targets, exclusions, timing and contacts.
- Discovery: map the attack surface and gather information.
- Assessment: look for and manually validate weaknesses.
- Verification: within the agreed rules, confirm that findings are real and what their impact is.
- Reporting: document validated findings with remediation advice.
- Remediation: fix the issues. Retesting to verify the fixes is optional and agreed separately.
What a good report contains
- A summary non-technical readers can act on.
- Each finding with evidence and reproduction steps.
- A severity rating that reflects business impact.
- Specific remediation guidance for developers.
How to prepare
- List the systems you want tested and who owns them.
- Prepare test accounts for each user role.
- Agree a testing window and an emergency contact.
- Take backups and tell hosting providers if they require notice.
To see how we work, read about our VAPT service and our VAPT scope and rules of engagement.
- Penetration testing
- VAPT
- Getting started


