Penetration testing is the only way to know whether your defences actually work under real attack conditions. This guide explains the types, methodology, costs, and what to do with the results.
Before we go further, let us clear up the most common confusion in cybersecurity. A vulnerability scan runs automated software that identifies known weaknesses in your systems. A penetration test employs skilled human hackers who chain those weaknesses together, think creatively around defences, and demonstrate exactly how an attacker would compromise your organisation.
Vulnerability scans tell you what doors might be unlocked. Penetration tests show you what happens when someone actually walks through them — and how far they get.
External Network Penetration Test: Targets your internet-facing infrastructure — websites, APIs, VPN gateways, email servers — simulating an attacker with no prior knowledge of your environment. This is typically the first test organisations should conduct.
Internal Network Penetration Test: Simulates a threat actor who has already gained a foothold inside your network, whether through phishing, a compromised credential, or a rogue insider. Tests lateral movement, privilege escalation, and access to sensitive data.
Web Application Penetration Test: Follows OWASP Top 10 methodology to identify SQL injection, cross-site scripting, authentication flaws, insecure direct object references, and other application-layer vulnerabilities in your web apps and APIs.
Social Engineering Assessment: Tests the human element — phishing simulations, vishing (voice phishing) calls to employees, or physical attempts to gain unauthorised building access (red team).
Red Team Exercise: A full-scope, objective-based assessment where a team of attackers attempts to achieve a specific goal (steal the crown jewels, deploy ransomware, access payroll data) using any combination of technical and social engineering techniques, over weeks or months.
Cloud Penetration Test: Assesses the security of your AWS, Azure, or GCP environment — IAM configurations, storage bucket access, API gateway security, Kubernetes cluster hardening.
Professional penetration tests follow a structured methodology to ensure comprehensive coverage:
Reconnaissance: Passive and active information gathering about the target — DNS records, WHOIS data, employee LinkedIn profiles, technology stack fingerprinting, exposed credentials on paste sites.
Scanning and Enumeration: Active probing of systems to identify open ports, running services, software versions, and potential entry points.
Exploitation: Attempting to compromise identified vulnerabilities using manual techniques and exploit frameworks. This is where the skill of the tester determines the depth of the assessment.
Post-Exploitation: Once access is gained, testers demonstrate the real business impact — can they access customer databases? Escalate to domain administrator? Pivot to the finance network?
Reporting: Detailed findings report with executive summary, technical details, evidence of exploitation, and prioritised remediation recommendations.
A high-quality penetration test report is one of the most valuable security documents your organisation will produce. Demand the following from any testing provider:
Executive Summary: Business-level risk summary suitable for the board, with an overall risk rating and the three to five most critical findings.
Technical Findings: Each finding documented with a title, severity rating, affected systems, detailed description, step-by-step proof of exploitation, business impact, and specific remediation guidance.
Attack Narrative: A chronological story of how the tester moved through the environment — invaluable for understanding attacker mindset and improving detection capabilities.
Remediation Roadmap: Prioritised list of fixes, categorised by effort and impact, with suggested owners and timelines.
The minimum standard for most organisations is annual external and internal network testing, with web application testing after every major release or annually (whichever is more frequent). Organisations in regulated sectors (financial services, healthcare, payments) or those handling large volumes of sensitive data should test more frequently — quarterly external testing is increasingly common.
Testing after significant infrastructure changes — a cloud migration, a major acquisition, a new product launch — is essential regardless of schedule, as these events introduce new attack surfaces.
The report is not the finish line. The value is entirely in the remediation. Within one week of receiving the report, conduct a findings debrief with the testing team to understand the most critical issues. Assign each finding an owner and a remediation deadline. Prioritise critical and high findings for immediate action — most should be remediated within 30 days.
Schedule a retest for all critical and high findings once remediation is complete. A reputable testing firm will include limited retesting as part of the engagement. Verify that fixes actually work — not just that tickets were closed.
The average penetration test costs between £5,000 and £30,000 depending on scope. The average data breach costs £3.4 million in the UK. The maths is straightforward. Penetration testing is not a cost — it is insurance against a vastly larger loss.
CyberPhoenix conducts CREST-aligned penetration testing across all disciplines — network, application, cloud, social engineering, and red team. Contact us for a scoping call and a same-week proposal.