What is a penetration test?
A penetration test is an authorised, controlled security test in which specialists attempt to break into your systems the same way a real attacker would. What is a pentest in practice? A structured process: agreement on scope and rules of engagement, reconnaissance, active attack attempts against networks, applications or employees, and finally a report showing exactly where the defences held and where they broke. The test challenges the whole chain: technology such as the firewall and MFA, configuration, and often people too, via simulated phishing. The Danish Centre for Cyber Security generally recommends that businesses test their defences systematically rather than assuming they work.
Penetration test vs. vulnerability scan
The two are often confused, but they solve different problems:
- Vulnerability scanning is automated: a tool scans the systems and lists known vulnerabilities: fast, cheap and well suited to running continuously, for example monthly. The downside is false positives and no assessment of whether the holes can actually be exploited.
- Penetration testing is manual and targeted: specialists exploit the vulnerabilities, chain small findings together into real attack paths and assess the actual business risk. That yields fewer, but far more actionable results.
The best setup is both: continuous scanning as basic hygiene and periodic penetration tests as a reality check of the overall defences, including things the scanner does not see, such as misconfigured access management and weak internal segmentation.
What does a penetration test cost?
The price depends on the scope, not a fixed rate. The most important factors are: scope (a single web application, the external perimeter or the entire internal network), test type (black box with no prior knowledge, grey box with user access or white box with full insight), complexity (number of systems, integrations and environments), and reporting and follow-up needs (for example a re-test after remediation). A narrowly scoped test is considerably less extensive than a full internal test with subsequent verification. Always get a quote based on a concrete scope rather than comparing rough estimates.
How often should you test?
The rule of thumb is at least once a year, and additionally whenever significant changes occur: new internet-facing systems, major infrastructure rebuilds, cloud migrations or after a security incident. Standards and legislation pull in the same direction: both ISO 27001 and NIS2 assume you continuously verify your controls. If you have never been tested, though, the most important thing is not the frequency but getting started. Consider starting with a broader security review that uncovers the obvious holes before the pentest goes deep.
How MI Support IT can help
We help you before, during and after the test: defining the right scope, an initial security review of your environment, remediation of the findings and ongoing hardening of your defences, as part of IT security. Contact us if you want to know where your defences really stand when they are put under pressure.