How to prepare for a penetration test

How to prepare for a penetration test: scope, type of test, rules of engagement, your internal team and what to do with the report.

A penetration test gives useful results only when it is well prepared. Most problems during testing come from an unclear scope, not from the testing itself.

Define the scope

Write down exactly what will be tested: which applications, addresses and environments. It is just as important to write down what will not be touched, for example third-party systems you have no permission to test.

Choose the type of test

  • Black box: the tester has no prior information, like an outside attacker.
  • Grey box: the tester has limited access, for example a user account.
  • White box: the tester has the documentation and, where it makes sense, the source code.

The more information you provide, the deeper the test goes in the same amount of time.

Agree the rules

  • Testing hours and periods when no testing should happen.
  • Contacts on both sides and how a critical finding is reported.
  • Whether tests that could affect availability are allowed.
  • How any data the tester may see will be handled.

Prepare your team

Tell the team that monitors your systems, so they do not treat the test as a real attack. Take backups and make sure someone with technical knowledge is available during testing.

After the report

The report is the start of the work. Assign an owner and a deadline to each finding, fix the high-risk ones first, and ask for a retest to confirm the weaknesses are closed.

Related servicePenetration Testing and Red TeamingTesting of infrastructure, web, mobile and cloud, with technical and executive reports.Learn more

Let's talk about your next engagement.

Tell us about your engagement — we typically respond within one business day.

WhatsApp +355 69 522 4573