Glossary
Penetration test
Also: Pentest
A commissioned attack on your own system, to find weaknesses before somebody else does.
Scope is agreed in advance: which systems, which methods, with or without prior knowledge, with or without credentials. That determines what can be found.
The result is a report of findings by severity. The value lies in the prioritized first five, not in the total count.
How you notice it
- A customer demands evidence.
- A new application goes public.
- Basics such as permissions and patching are done.
Frequently asked
When is a test premature?
While known gaps are still open. A report listing outdated libraries and overly broad permissions costs four to five figures and says nothing a free scan would not have said. Clean up first, then have it tested.
