Security operations

What is Penetration Testing?

A plain-English guide to penetration testing (pentest): what it is, how it works, the main types and methods, plus what NIS2, DORA, GDPR and PCI DSS now expect.

Key takeaways
  • A penetration test is an authorised and controlled attack that safely finds and exploits real weaknesses before criminals do.
  • It goes beyond a vulnerability scan because a human confirms which weaknesses are actually exploitable and how far they lead.
  • In the EU, exploited vulnerabilities were the EU Agency for Cybersecurity (ENISA)’s second most common initial-access vector at 21.3 percent between July 2024 and June 2025, behind only phishing, second only to phishing.
  • Common types include network, web application, wireless, cloud, social engineering and physical testing.
  • Professional tests follow published methods such as OSSTMM, the OWASP Web Security Testing Guide, NIST SP 800-115 and PTES.
  • Equifax (2017), Capital One (2019) and Colonial Pipeline (2021) each turned on a weakness a test would likely have surfaced.
  • GDPR Article 32 and PCI DSS require regular testing, and DORA mandates threat-led testing every three years for significant financial firms.
  • Sweden’s Cybersäkerhetslagen (NIS2) has required risk-management measures including testing since 15 January 2026.
  • A pentest is a point-in-time snapshot, so pair it with continuous scanning and retest after every major change.
  • The value is in the report: ranked, exploitable findings with fixes, then a retest to confirm the gaps are closed.

Penetration Testing Defined in Plain Terms

A penetration test or pentest, is an authorised and controlled cyberattack on your own systems. A skilled tester takes the role of an attacker to find and safely exploit weaknesses in networks, applications and people, then reports exactly what was reachable and how to fix it before a real attacker finds the same gaps.

This is where a penetration test differs from a vulnerability scan. A scan is automated and produces a list of possible weaknesses. A pentest adds a human who confirms which of those weaknesses can actually be exploited, chains them together and shows the real business impact. The two are often bought together as vulnerability assessment and penetration testing, or VAPT.

The need is not abstract. In the EU, exploited vulnerabilities were behind 21.3 percent of intrusions that the EU Agency for Cybersecurity (ENISA) analysed between July 2024 and June 2025, its second most common way in after phishing. Attackers weaponise newly disclosed flaws within days. A penetration test finds the exposed, exploitable gaps on your side first.

How a Penetration Test Works

A good penetration test follows a repeatable method so the results are consistent and defensible. The US National Institute of Standards and Technology sets out the shape in its guide SP 800-115 which groups the work into planning, discovery, attack and reporting. In practice most engagements run through these stages:

How a Penetration Test Works
  • Scoping and rules of engagement: You agree what is in scope, what is off limits and how far the tester may go, in writing before anything starts.
  • Reconnaissance and discovery: The tester maps your attack surface and gathers information the way an attacker would.
  • Vulnerability analysis: Findings are reviewed to work out which weaknesses are worth trying to exploit.
  • Exploitation: The tester safely proves which weaknesses are real by using them to gain access, escalate privileges or reach sensitive data.
  • Post-exploitation and reporting: The tester documents what was reachable, rates each finding by severity and sets out clear remediation steps.
  • Remediation and retest: You fix the issues and the tester checks that the fixes hold.

The report is the deliverable that matters. It ranks each exploitable finding by severity shows the evidence and gives the steps to close it which is what turns a test into fewer real incidents.

Types of Penetration Testing

Penetration testing covers several distinct activities. Each type is scoped to a different attack surface so you test the part of your environment you most need assurance on.

  • Network penetration testing: Tests your servers, firewalls and network devices. External network penetration testing targets internet-facing systems while internal testing looks at what an intruder could reach once inside.
  • Web application penetration testing: Probes your websites, portals and APIs for flaws such as injection, broken authentication and access-control gaps.
  • Wireless penetration testing: Checks Wi-Fi and other wireless networks for weak encryption and rogue access points.
  • Cloud penetration testing: Looks for misconfigured storage, over-permissive roles and exposed services in environments such as AWS or Azure.
  • Social engineering: Tests people and process with phishing and pretext calls to see whether staff can be tricked into granting access.
  • Physical penetration testing: Attempts to reach servers, offices or devices in person, past locks, badges and reception.
  • Mobile and API testing: Assesses mobile apps and the interfaces behind them which now carry much of the sensitive data.

Tests also differ by how much the tester is told at the start. In a black-box test the tester begins blind like an outside attacker. In a grey-box test they get limited information such as a standard user login. In a white-box test they get full detail including source code and architecture.

More knowledge means faster and deeper coverage. Less knowledge gives a more realistic picture of what an outside attacker would find on their own.

Penetration Testing Methods and Standards

Professional testers work to published methodologies rather than improvising. Standards make a test repeatable, comparable and audit-friendly, and several are widely used.

  • OSSTMM: The Open Source Security Testing Methodology Manual, maintained by the non-profit ISECOM, is a peer-reviewed method for measuring operational security across five channels, from data networks to human and physical security.
  • OWASP Web Security Testing Guide: The Open Worldwide Application Security Project publishes the WSTG, the reference method for web application testing, organised into twelve categories. Its companion OWASP Top 10 ranks the most critical web risks.
  • NIST SP 800-115: The US technical guide that frames testing as planning, discovery, attack and reporting, widely used as a baseline in regulated environments.
  • PTES: The Penetration Testing Execution Standard, which describes an engagement in seven phases from pre-engagement to reporting.

Two related terms come up often. Red teaming is a broader and stealthier exercise that tests detection and response against a realistic attacker over weeks rather than a scoped snapshot of one system. Purple teaming runs the attackers and your defenders together so lessons land at once.

For large financial firms in the EU, DORA turns this into a legal duty called threat-led penetration testing built on the European Central Bank’s TIBER-EU framework.

Real-World Cases

The clearest argument for testing is what happens without it. Each case here turned on a weakness a test would very likely have surfaced first.

Real-World Cases

Equifax and the Unpatched Struts Flaw

In 2017 the credit agency Equifax exposed the personal data of roughly 147 million people. The way in was a known flaw in Apache Struts, a web framework component. Apache had released a patch on 7 March 2017 and US authorities alerted affected firms the next day.

Equifax’s own scan failed to find the vulnerable, internet-facing system so it stayed unpatched. Attackers reached it and moved through the network from mid-May until the activity was spotted in late July. The breach was disclosed to the public on 7 September 2017.

A thorough external test of internet-facing systems is built to catch exactly what an automated scan misses. Finding and confirming that one exposed component would have closed the door.

Capital One and a Cloud Misconfiguration

In 2019 Capital One lost data on around 106 million people across the US and Canada. A former cloud engineer exploited a misconfigured web application firewall using a server-side request forgery attack.

That single request tricked the firewall into fetching temporary cloud credentials from an internal metadata service. Those credentials unlocked storage holding customer records including roughly 140,000 US social security numbers. A US regulator later fined the bank 80 million dollars.

Server-side request forgery is a standard check in web application penetration testing. A test aimed at the firewall and its access to cloud metadata would have exposed the flaw before an outsider did.

Colonial Pipeline and a Forgotten VPN Account

In May 2021 a ransomware crew shut down Colonial Pipeline which carries close to half of the fuel used on the US East Coast. The pipeline was down for about five days and set off panic buying across several states.

Investigators traced the entry to a single leaked password for an old VPN account that was still enabled and had no multi-factor authentication. Colonial paid about 4.4 million dollars in ransom though US authorities later clawed back most of the bitcoin.

No exotic exploit was involved. An external test of remote access would have flagged the dormant account and the missing second factor, the sort of basic gap these engagements are built to find.

Penetration Testing and Compliance

Testing is increasingly not optional. Several regimes that apply in Sweden and the EU expect organisations to test their defences and prove the results.

NIS2 and Cybersäkerhetslagen: Sweden’s NIS2 law, Cybersäkerhetslagen (SFS 2025:1506), came into force on 15 January 2026. The NIS2 Directive’s Article 21 requires risk-management measures that include testing and vulnerability handling and its Article 20 makes the management body personally accountable. Cybersäkerhetslagen transposes both into Swedish law.

Since 1 July 2026 the national single point of contact and incident-reporting body has been the National
Cyber Security Centre (NCSC) at Försvarets radioanstalt (FRA) which took these functions over from
MCF (formerly MSB). Supervision itself is handled by sector-specific authorities such as
Finansinspektionen and PTS.

DORA: The EU’s Digital Operational Resilience Act has applied to financial entities since 17 January 2025. Under Articles 26 and 27, the significant firms identified by regulators must run threat-led penetration testing at least every three years. See our DORA guide for who is in scope.

GDPR: Article 32 of the GDPR requires a process for regularly testing, assessing and evaluating the effectiveness of security measures. Penetration testing is the accepted way to evidence that duty for systems that process personal data. In Sweden the data protection authority is IMY.

ISO 27001 and PCI DSS: ISO 27001, the information security management standard, expects organisations to manage technical vulnerabilities and test that controls work. PCI DSS which governs card data is more prescriptive still and requires internal and external penetration tests at least every twelve months and after any significant change.

Meeting these duties is not about a single report. It is about testing on a sensible cycle, fixing what is found and being able to show the evidence which is what a managed penetration testing service is built to deliver.

How to Choose a Penetration Testing Provider

Not all tests are equal. The difference between a report that lowers your risk and one that gathers dust is in how the work is scoped and who does it.

  • Qualified and independent testers: The people testing should be skilled and organisationally separate from the team that built the systems.
  • A clear methodology: Ask which standard the test follows such as OSSTMM or the OWASP guide, and how coverage is recorded.
  • Scope that matches your risk: The test should target your most valuable systems and data, agreed before work starts.
  • Safe execution: Rules of engagement, safeguards and an agreed way to pause protect production.
  • Reporting you can act on: Findings ranked by severity with evidence and plain remediation steps plus a summary a board can read.
  • A retest included: The provider should confirm that your fixes actually closed the gaps.

One caveat matters. A penetration test is a point-in-time snapshot rather than a guarantee that you are secure tomorrow. New systems and newly disclosed flaws appear constantly so testing works best alongside continuous vulnerability scanning and monitoring, not instead of them.

How to Get Started with Penetration Testing

You do not need a mature security programme to begin. A focused first test on your most exposed systems is more useful than waiting for the perfect moment.

Get Started with Penetration Testing
  • Identify what matters most. List the systems and data that would hurt the business if breached and start there.
  • Set the scope and rules in writing. Agree what will be tested, what is off limits and how findings are handled.
  • Choose the right type. Match the test to the risk, whether that is network, web application or cloud.
  • Fix the cadence to reality. Test at least once a year and again after any major change to systems, applications or infrastructure.
  • Plan for remediation. Book time to fix findings and require a retest to confirm they are closed.
  • Layer in continuous checks. Pair periodic tests with ongoing vulnerability scanning so new gaps are caught between engagements.

Handled this way, penetration testing becomes a steady supply of the specific fixes that keep attackers out rather than a yearly compliance chore.

Myths & Facts

Myth

A vulnerability scan and a penetration test are the same thing.

We passed our last penetration test, so we are secure.

Only large companies need penetration testing.

Penetration testing will break our production systems.

Penetration testing is just running automated tools.

A penetration test is a one-off compliance tick.

Fact

They are not. A scan is automated and flags possible weaknesses, while a penetration test adds a skilled human who confirms which weaknesses are truly exploitable and how far an attacker could get.

A penetration test is a snapshot of one moment. New code, new systems and newly disclosed vulnerabilities can reopen risk the day after the report is signed.

Attackers scan the whole internet and exploit weak, internet-facing systems whatever the company size. Smaller organisations are often hit precisely because their defences are thinner.

A professional test runs to an agreed scope and rules of engagement, with safeguards and an agreed way to pause, so serious disruption is controlled and rare.

Tools help with discovery, but the real value comes from a human chaining flaws, testing business logic and judging true impact, which automated tools cannot do.

Rules such as GDPR and PCI DSS expect regular, repeated testing. The payoff is fixing what is found and retesting to confirm the gap is closed.

Test Yourself

Four real-world scenarios, then six knowledge questions. See how prepared you would be under pressure.

Scenario Simulation

  1. A supplier warns that a critical flaw has been found in a web framework your public website uses, and a patch is out. Your last penetration test was three months ago.

    What is the right response?

    • Apply the patch now and confirm the fix, then check whether other systems use the same component
    • Wait for the next scheduled penetration test to check it
    • Rely on your last clean scan, which did not flag it
  2. You are commissioning your first penetration test. The provider asks you to agree the scope and rules of engagement in writing before starting.

    How should you treat this step?

    • As essential, defining what is in scope, what is off limits and how findings are handled
    • As unnecessary paperwork that slows the test down
    • As the provider's job alone, with no input from you
  3. A test of your remote access finds an old VPN account that is still enabled, belongs to a former employee and has no multi-factor authentication.

    What do you do first?

    • Disable the account and add multi-factor authentication to remote access
    • Leave it, since the password looks complex
    • Note it for the annual review next year
  4. Your penetration test report lists several high-severity findings. Your team fixes them over the next month.

    What is the final step?

    • Ask the tester to retest and confirm the fixes actually closed the gaps
    • Close the project once the tickets are marked resolved
    • File the report and wait a year for the next test

Knowledge Test

  1. What mainly separates a penetration test from a vulnerability scan?

    • A human confirms which weaknesses are truly exploitable
    • It is fully automated
    • It only checks for viruses
    • It needs no scoping

    A scan lists possible weaknesses, while a pentest adds a human who proves which ones can actually be exploited.

  2. In ENISA's 2024 to 2025 data, exploited vulnerabilities were the second most common way into EU organisations after which vector?

    • Phishing
    • Insider theft
    • Physical break-in
    • Denial-of-service

    ENISA found vulnerability exploitation behind 21.3 percent of intrusions, second only to phishing.

  3. Which methodology is the reference guide for web application testing?

    • The OWASP Web Security Testing Guide
    • OSSTMM
    • NIST SP 800-115
    • PTES

    OWASP's WSTG, organised into twelve test categories, is the standard method for web application testing.

  4. Under DORA, how often must significant financial entities run threat-led penetration testing?

    • At least every three years
    • Every month
    • Once, at launch
    • Only after a breach

    DORA Articles 26 and 27 require identified significant entities to run threat-led penetration testing at least every three years.

  5. What caused the 2017 Equifax breach?

    • An unpatched, known flaw in a web component
    • A stolen laptop
    • A malicious insider
    • A denial-of-service attack

    Equifax left a known Apache Struts flaw unpatched on an internet-facing system, and attackers exploited it.

  6. Why should a penetration test be repeated regularly?

    • It is a point-in-time snapshot that new systems and flaws can undo
    • Tools expire after one use
    • The law bans testing twice
    • One test covers all future risk

    A pentest reflects one moment, so new code and newly disclosed vulnerabilities mean testing must be ongoing.

Take It with You

Share the Summary PDF with Your Team

A short distilled brief in PDF: key findings, red flags and action steps.

Download summary PDF

Why Training Matters

Even the best penetration test has one limit. It shows you where you were exposed on the day it ran, and keeping those gaps closed depends on the people who build and run your systems.

Social engineering tests exist because staff are a genuine attack surface. Developers who understand common flaws write fewer of them, and colleagues who can spot a phishing email close a door that many attacks rely on. Regular security awareness training is what turns a one-off finding into a lasting fix.

Frequently Asked Questions

What is penetration testing?

Penetration testing is a controlled and simulated cyberattack in which a skilled tester tries to break into your systems the way a real attacker would. The aim is to find weaknesses in networks, applications and people, prove safely which ones can be exploited and report exactly how to fix them before criminals get there first.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment is an automated scan that lists possible weaknesses, while a penetration test adds a human who confirms which of those weaknesses can actually be exploited and how far they lead. The two are often combined as vulnerability assessment and penetration testing, or VAPT, giving both broad coverage and proven impact.

How often should you perform penetration testing?

Most organisations should run a penetration test at least once a year and again after any significant change to their systems, applications or infrastructure. Regulations reinforce this. PCI DSS requires annual internal and external tests, and GDPR Article 32 expects regular testing of security measures. Higher-risk systems benefit from more frequent testing.

What is network penetration testing?

Network penetration testing assesses the security of your servers, firewalls and network devices. External network penetration testing targets internet-facing systems the way an outside attacker would, while internal testing examines what an intruder or insider could reach once inside. It finds exposed services, weak configurations and paths an attacker could use to move around.

What is web application penetration testing?

Web application penetration testing probes your websites, portals and APIs for security flaws. Testers look for issues such as injection, broken authentication, access-control gaps and server-side request forgery, the kind of flaw behind the 2019 Capital One breach. It is usually guided by the OWASP Web Security Testing Guide, the reference method for web application security.

Is penetration testing required for NIS2, DORA or ISO 27001?

Yes, in effect. NIS2 and Sweden's Cybersäkerhetslagen require risk-management measures that include testing and vulnerability handling. DORA mandates threat-led penetration testing at least every three years for significant financial entities. ISO 27001 expects organisations to manage technical vulnerabilities and test that controls work, so a regular pentest supports all three.

How long does a penetration test take?

There is no single answer because it depends on scope. A small web application test may take a few days and a large network test a couple of weeks, while a full red team exercise runs longer still. Scoping, reporting and a retest to confirm fixes add time on either side of the active testing.

You Understand the Risk.
Now See Where You Stand.

Book a 30-minute briefing with one of our analysts, or run the free breach check first to find out what attackers already know about your organisation.

Book a 30-Min Briefing
No sales pitch, just a straight assessment

How eBuilder Security Can Help

Awareness is the first layer. These are the services that turn it into measurable protection.