IT Glossary
What is a penetration test?
The attack under contract: specialists you pay try to break into your systems, so you learn the gaps from them rather than from real attackers.
There are two routes to learning where your defences fail: from attackers, with the invoice attached, or from people you pay to attack first. A penetration test is the second one. Security specialists attempt, with your written authorisation and inside agreed limits, to actually compromise your systems — not to scan them theoretically but to get in, exploiting vulnerabilities, chaining small weaknesses into a serious path, and demonstrating concretely that from here, with what we found, we reached the customer database. The distinction from vulnerability scanning is the classic source of confusion when comparing quotes. Scanning is automated and cheap and produces a theoretical list of weak points, useful as recurring hygiene. A penetration test is creative human work proving real exploitability and business impact; its report does not say that a port runs an old version, it says that combining two findings produced administrator access, here is the evidence, and here are the fixes in order of risk. The usual varieties test web applications and their programming interfaces, which is the most requested; infrastructure covering network, servers and remote access; and social engineering with physical access, the category that produces the most humbling results. And the part many buyers miss when budgeting: money for afterwards, because a test not followed by prioritised remediation and a retest is an expensive document.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247
Why it matters for your business
Real gaps found under contract
Demonstrated attack paths rather than theorised ones show exactly what an intruder would find: the same information, with the invoice pointing the other way.
Fixes ordered by real risk
A report prioritised on demonstrated impact puts the security budget on the holes that matter instead of on an alphabetical list of theoretical alerts.
A requirement ticked for larger contracts
Periodic testing answers the vendor questionnaires used by corporate buyers and cyber insurers, opening doors that would otherwise stay politely shut.
Frequently asked questions
What does a penetration test cost, and why do prices vary so much?
By human effort and scope: a mid-sized company’s web application starts from a few thousand euros for a serious test of several days to a week, while infrastructure and combined engagements cost more. Suspiciously cheap offers usually buy an automated scan under a better name, and the difference shows in the report — demonstrated exploitation and concrete fixes versus a tool export listing theoretical severities. Compare on days of manual work and on anonymised sample reports.
Can testing break something in our live systems?
The risk exists and is managed contractually: agreed limits exclude destructive techniques and denial-of-service attempts, aggressive testing ideally runs against a staging environment, windows are scheduled, and an emergency channel to your team stays open throughout. Professionals treat this as basic care and genuine incidents are rare. Even so, a verified backup before the engagement is standard hygiene, and the liability clauses are read rather than assumed.
The report came back with thirty findings — where do we start?
From the matrix of severity against effort: externally exploitable critical issues are fixed now, and serious providers announce those during the test rather than saving them for the document. Then the high-severity wave on exposed systems, then the rest on a plan. Two closing disciplines: a retest on the fixes, negotiated at the outset because an unverified claim of repair is only a hope; and treating process causes, since three findings in one category point at a development practice to correct at source.
Let’s talk about your project
Message us on WhatsApp or send an email — you talk directly to a developer.
office@northdan.com · +40 752 070 247