Security

What Is Penetration Testing and Does Your Business Need It?

OrasecMay 13, 20264 min read

Written by the OraSec security research team — offensive security engineers and penetration testers.

What Is Penetration Testing and Does Your Business Need It?

<span style="white-space: pre-wrap;">Penetration testing finds the weaknesses an attacker would use, proves what they could reach, and shows you which ones to fix first.</span>

Most companies find out how good their security is at the worst possible moment. A penetration test moves that discovery forward, to a week you picked, run by people on your side.

The idea is simple. You hire skilled testers to break into your own systems, then they hand you the map they used. What you do with that map is the whole point.

What Is Penetration Testing?

Penetration testing, sometimes called ethical hacking, is an authorised attack on your own systems. Same techniques a criminal would use, but with a signed contract and an agreed scope.

People often confuse it with vulnerability scanning. A scanner tells you a door might be unlocked. A tester walks through it, checks what's in the room, and tries the next door along the corridor. That second part is where the real answers live. Attackers don't stop at the first finding either.

How a Penetration Test Actually Runs

Engagements vary, but the shape is consistent. It starts with scoping, where you agree what's in, what's off limits, and who to call if something breaks. Then the tester maps your exposure. You'd be surprised how often this turns up a staging server nobody remembered.

Next comes the hunting. Some is automated, most of the interesting parts aren't. When a tester finds something promising, they exploit it to prove it's real, then see how far it carries them.

Then you get a report, and this is where firms differ most. A good one explains the attack path, ranks findings by what they'd cost you, and gives engineers something specific to fix.

Then you fix things and the tester checks again. If a proposal doesn't include that retest, ask why.

The Main Types of Penetration Testing

Which type you need depends on what you're protecting:

  • Web application testing, for logic flaws, injection, and broken access control
  • API testing, which usually surfaces authorisation gaps
  • Network testing, covering your perimeter and internal movement
  • Cloud testing, for open storage, over-wide IAM roles, exposed metadata
  • Mobile testing, covering local storage and hardcoded keys
  • Active Directory testing, where the goal is domain admin
  • Social engineering, aimed at your people rather than your servers

There's also how much the tester knows going in. Black box means nothing. Grey box means a login. White box means source code, which tends to find the most because nobody wastes time guessing.

Why It Matters to the Business

Security teams usually suspect where the weak spots are. What they lack is proof the board will act on.

A test provides that. It replaces "this could be risky" with "here is the exact path from our login page to customer records, and here is how long it took."

There's a compliance angle too, though it's often overstated. PCI DSS Requirement 11.4 does mandate internal and external testing at least every 12 months, plus another after any significant change. ISO 27001, GDPR, and HIPAA ask for security testing and risk assessment without naming a pentest specifically. Treat anyone who claims all four require one as a sales pitch.

Enterprise clients and cyber insurers increasingly ask for a recent report too. That alone pays for a lot of tests.

How Small Findings Turn Into Big Problems

Breaches rarely come from one dramatic flaw. They come from ordinary ones stacking up.

Say your website exposes staff email formats. Your login page confirms which addresses exist. Your password policy still allows Summer2026. Each is a low or medium finding that would sit in a backlog for months.

Chain them and a tester has working credentials. If your VPN doesn't enforce MFA, they're inside.

A scanner reports three minor issues here. A penetration test reports one critical attack path. Same underlying facts, completely different conversation with your CFO.

What to Demand Before You Sign

Ask any prospective providerx to confirm, in writing:

  • How much of the work is manual versus automated
  • Whether they test business logic, which scanners cannot reach
  • Whether they test permissions between user roles
  • That every critical finding comes with proof it was exploited
  • That a retest is included, not billed separately
  • That you get a technical report and a summary a director can read

Vague answers usually mean you're buying a scan with a nicer cover.

Where Pentests Get Wasted

The most common failure isn't a bad tester. It's a good test nobody acts on.

Narrow scoping comes a close second. Excluding the system you're most nervous about saves money and tells you nothing. Booking the week before launch does the same, because there's no time left to fix anything.

How OraSec Can Help

OraSec runs manual penetration testing across web, API, network, cloud, mobile, and Active Directory. Every critical finding arrives with a proven attack path, a specific fix, and a retest to confirm it's closed. You get evidence, not a tool export with your logo on it.

Conclusion

Penetration testing turns assumptions into evidence. It shows which weaknesses an attacker could actually use, how far they'd get, and what deserves your attention first.

Test after significant changes, at least once a year, and verify the fixes landed. Security nobody has tested is a hopeful guess.

FAQs

What is penetration testing in plain terms? An authorised, simulated attack. Testers break in the way a real attacker would, then show you exactly how they managed it.

How is it different from a vulnerability assessment? An assessment lists what might be wrong. A test proves what genuinely is, and shows where it leads.

How often should we run one? Once a year as a baseline, plus after any major change. PCI DSS uses the same 12-month rule.

How long does it take? Most web or network engagements run one to three weeks, plus a few days for reporting.

Is it legal? Yes, provided you have written permission from whoever owns the systems and a defined scope. Without that, it's just hacking.

Explore related services

Need hands-on help? Our security testing services put this research into practice.

bgp-hijack-virtualizor-update

BGP Hijack Delivered a Backdoored Virtualizor Update

The update came from the right domain over valid TLS. The route to the vendor had been stolen, so the traffic reached an attacker-controlled server instead. What Happened? Between 28 and 30 August 2026, attackers announced a BGP route they had no authority over, pulling Softaculous update traffic to a server they controlled. Any Virtualizor installation that checked for updates during one of the diverted routing intervals could have received the backdoored package. AlbaHost, a hosting provid

·4 min read
jfrog-artifactory-vulnerability

JFrog Artifactory Vulnerability: Exploited in Three Days

JFrog released patches on 28 August 2026. By 1 September, watchTowr was publicly reporting active exploitation — roughly three and a half days after disclosure. What Is the Vulnerability? CVE-2026-82329 is an authentication bypass in JFrog Artifactory, rated CVSS 9.8. In default configurations, an unauthenticated attacker with network access can obtain administrative privileges, with no user interaction required. Self-hosted deployments require customer action. JFrog says affected cloud envi

·3 min read
dll-sideloading-signed-software

DLL Sideloading: How ValleyRAT Hides Behind Signed Software

The malicious code was not signed. The program that loaded it was. What Is DLL Sideloading? When an application loads a DLL by name rather than a fully qualified path, Windows searches a defined set of locations. If an attacker can place a malicious DLL in a directory searched before the legitimate copy, the application may load it. Microsoft documents this as DLL preloading/binary planting behavior. (Microsoft Learn) The signed executable runs. The signature checks out. The malicious DLL ex

·3 min read