All articles

Commissioning a penetration test? Why technology is rarely the real problem

Commissioning a penetration test often starts with the expectation that the biggest surprise will be technical.

Organisations that commission a penetration test almost always gain insight into vulnerabilities, configuration errors and possible attack paths. In the hundred penetration tests we carry out each year, a completely clean environment is the exception rather than the rule.

The technology therefore almost always provides evidence. What stands out is that this rarely solves the problem.

Most organisations already have insight. Reports, dashboards and tools are in place. Yet this rarely leads to clear decisions. Where should action be taken first, and what can wait?

That is where things go wrong.

Some organisations label everything urgent, so priorities disappear. Long lists of findings are dealt with one by one, or not at all. In other cases, discussion remains at the level of technical detail, without making the impact on business operations explicit. We also regularly see environments where detection and monitoring are well configured, but no clear response follows when signals arrive.

The pattern is always the same: there is information, but no order of priority.

A good penetration test reveals this. Not by adding more vulnerabilities, but by making connections visible. Which combination of weaknesses makes an attack plausible? Which finding has a direct impact on the organisation? And what needs fixing first?

Those questions determine the value of a penetration test.

This becomes most visible when a penetration test report is discussed at board level. The main findings have been summarised and the risks explained in terms of impact and likelihood. Then almost invariably comes the same question:

“Where do we start?”

That question seems simple, but it is not. The answer forces decisions. What takes priority, and what does not? Which risk is temporarily accepted, and which is not? And who takes responsibility for that?

COMMISSIONING A PENETRATION TEST: WHAT SHOULD YOU LOOK FOR?

When commissioning a penetration test, you often compare providers on price, turnaround time or the number of testing days. Those are relevant factors, but they say little about the ultimate value of the assessment.

The first question should be: what do you want to know?

A penetration test of a web application requires a different approach from a penetration test of an internal network environment, Microsoft 365 environment or cloud platform. The right scope ultimately determines the quality of the outcome.

It is also important to consider the testing method. Are only tools and automated scans used, or does a specialist also carry out manual investigation? That is often where findings emerge that a scan does not detect.

Reporting also deserves attention. A good report contains more than technical details: it makes clear which risks are actually relevant to the organisation. Technical teams need to understand what must be fixed. Management and the board need to understand why it matters.

Finally, follow-up is important. A penetration test is not an end in itself. Its value emerges only when the outcomes lead to better decisions, targeted improvements and demonstrable risk management.

WHEN IS IT SENSIBLE TO COMMISSION A PENETRATION TEST?

A penetration test is particularly sensible when the outcome needs to support a specific decision.

For example:

  • a new web application or customer portal;
  • a cloud migration;
  • a major software release;
  • an audit process;
  • preparation for NIS2 or DORA;
  • an environment in which sensitive data is processed;
  • business-critical systems directly accessible from the internet.

For many organisations, annual testing is a logical starting point. Rapidly changing or higher-risk environments often require more frequent testing.

CONCLUSION

Commissioning a penetration test is not only about technology.

The technology is necessary. Without technical depth, there is no reliable picture.

But the real value emerges only when it becomes clear what the findings mean, which risks need attention first and who decides on that.

The question is therefore not only whether there are vulnerabilities.

The real question is whether it is clear where action must be taken first.

Discussing a penetration test report after a penetration test

FREQUENTLY ASKED QUESTIONS ABOUT PENETRATION TESTING

What is the purpose of a penetration test?

A penetration test examines whether vulnerabilities in systems, applications or infrastructure can lead to risk for the organisation in practice. Its value lies not only in finding vulnerabilities, but above all in determining which risks take priority and what follow-up is needed.

When is it sensible to commission a penetration test?

A penetration test is relevant for new applications, major changes to infrastructure or cloud environments, compliance programmes such as NIS2, DORA or ISO 27001, and when the board or IT wants greater assurance about current risks.

What does a penetration test deliver?

A penetration test provides insight into technical vulnerabilities, possible attack paths, impact on the organisation and priorities for follow-up.

What is included in a penetration test report?

A professional penetration test report contains the scope, assessment method, technical findings, impact analysis, prioritisation and practical recommendations. A good report also includes an executive summary.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan automatically flags possible weaknesses. A penetration test examines what those weaknesses mean in the organisation's context and considers their connections, impact and possible attack paths.

How often should you carry out a penetration test?

For many organisations, annual testing is a good starting point. For business-critical applications, rapid development cycles or major changes, more frequent testing may be sensible.

Is a penetration test mandatory under NIS2 or DORA?

NIS2 requires appropriate risk management and periodic evaluation of security measures. DORA includes additional requirements for financial institutions. A penetration test is a widely used means of testing measures and making risks demonstrable.

How do you choose a suitable penetration testing company?

Do not look only at price or tools. Pay particular attention to the quality of the scope, technical depth, clarity of reporting and translation into priorities and risks.

How do you define the right scope for a penetration test?

The right scope starts with the question of what you want to know. Only then do you determine which systems, applications, accounts and types of testing are needed for a worthwhile assessment.


Back to all articles