Skip to content

Blog

What Is Pentesting? Types and How It Works

September 9, 2026 · Pentesting · Cybersecurity · Ethical Hacking · Enterprise Security

What Is Pentesting and What Is It For?

Pentesting (short for penetration testing) is a controlled, authorized attack against a company's systems, applications, or network, aimed at finding real vulnerabilities before an actual attacker does. Unlike an automated scan, a pentest is carried out by a person — an ethical hacker — who tries to exploit whatever flaws they find, the same way a real attacker would, to measure the true impact of each vulnerability instead of just listing it.

For any business handling customer data, payments, or critical infrastructure, understanding what pentesting is and how one gets planned is the first step toward knowing whether your security actually holds up against a real attack, or just looks good on paper.

Pentesting vs. Vulnerability Scanning vs. Security Audit

These three terms get mixed up constantly, but they're not the same thing:

  • Vulnerability scanning: an automated tool compares your systems against a database of known flaws and produces a list. It's fast and inexpensive, but it doesn't confirm whether those flaws can actually be exploited or how bad the damage would be.
  • Security audit: checks whether your company follows policies, controls, and standards (passwords, permissions, backups, documentation). It's a compliance exercise, not an attack.
  • Pentesting: combines automated tools with manual work from a specialist who genuinely tries to break in, chains minor flaws together to achieve something serious (like access to a database), and documents the exact path they took.

Pentesting is the only one of the three that answers the question that actually matters: if someone with the same tools a real attacker uses tried today, would they succeed?

Black Box, Grey Box, and White Box: The Three Types of Pentesting

The most common way to classify a pentest is by how much information the ethical hacker receives before starting:

  • Black box: the pentester gets no internal data — no diagrams, no credentials, no source code. They start exactly the way a real external attacker would, working only from what's publicly visible. It simulates an outside attack with no help from anyone inside the company.
  • White box: the pentester gets full access — source code, architecture, credentials, technical documentation. It's the deepest and most detailed type of test, useful for reviewing an application thoroughly before launch or for a security-focused code audit.
  • Grey box: a middle ground. The pentester receives partial information, such as a regular user account or a general map of the network, similar to what an employee with limited access would have, or an attacker who already gained some foothold. It's the most common approach in practice because it balances realism with depth, without spending weeks rebuilding information the company already has documented.

None of the three types is "the best" in general — the right choice depends on which risk scenario worries you most: an external one, an internal one, or an exhaustive technical review.

Types of Pentesting by Target

Beyond black, grey, and white box, a pentest is also classified by what's being tested:

  • Network pentesting (internal and external): reviews servers, firewalls, routers, and segmentation between network zones.
  • Web application pentesting: looks for issues like SQL injection, broken access control, or improper session handling on sites and portals.
  • Mobile application pentesting: checks how the app stores data locally, how it communicates with the server, and whether it exposes sensitive information on the device.
  • Wireless network pentesting: evaluates whether the company's wifi network can be compromised from the parking lot or the street outside.
  • Social engineering: measures how easily an employee would hand over a password over the phone or click a simulated phishing email; it's a common complement to a technical pentest, not a replacement for one.

A business running e-commerce, for example, usually prioritizes web and network pentesting; a business with its own app adds the mobile component to the scope.

How Pentest Scope Gets Defined

Before any test begins, the provider and the company need to agree in writing on the scope: which systems, domains, IP ranges, or applications are included in the test, which are explicitly excluded, what time window the test runs in, and which techniques are allowed or forbidden (for example, whether denial-of-service attacks are authorized, or only tests that won't affect the availability of a production system).

This scope document also sets the contact rules: who gets notified if the pentester finds something critical mid-test, and what happens if real customer data gets touched by accident. Without a clear, signed scope, a pentest stops being an authorized security test and becomes, legally, unauthorized access to a system.

What Deliverables You Get at the End of a Pentest

A serious pentest doesn't end with an email saying "everything's fine" or "we found a few things." Typical deliverables include:

  • A detailed technical report, covering each vulnerability found, exactly how it was exploited step by step, and supporting evidence (screenshots, logs).
  • A severity rating for each finding (critical, high, medium, low), usually based on the real impact if an attacker exploited it.
  • Specific remediation recommendations for each flaw, not just generic advice like "update your software."
  • An executive summary in non-technical language, meant so leadership or the business team can understand the risk without a cybersecurity background.
  • A retest, a follow-up check (after the internal team fixes the findings) to confirm the flaws are actually gone.

If a provider only hands over a list of vulnerabilities with no exploitation evidence and no prioritized remediation plan, what they actually sold you was an automated scan dressed up as a pentest.

How Often You Should Run a Pentest

There's no single rule that applies to every industry, but the most widely accepted practice is to run one at least once a year, plus any time there's a significant change: a new application, an infrastructure migration, a major shift in network architecture, or a new integration with an outside vendor. A pentest done two years ago says nothing about the vulnerabilities introduced by the system you launched last month.

Some standards make it mandatory: PCI DSS 4.0, the standard that governs any business processing card payments, requires external and internal penetration testing at least every 12 months and after any significant change to the infrastructure, plus network segmentation testing. Outside of that kind of regulatory obligation, the practical rule of thumb is simple: the more sensitive the data you handle and the faster your infrastructure changes, the more often you need to repeat the test.

Frequently Asked Questions

What Is Pentesting Compared to Ethical Hacking?

Ethical hacking is the broader discipline: using attack techniques with authorization and defensive intent. Pentesting is one concrete application of it, focused on testing a specific system within a defined scope and timeframe.

How long does a typical pentest take?

It depends on the scope: a web application might take one to two weeks, while a full network with several systems can stretch several weeks longer. The provider should define the exact duration when the scope is set, not as a generic estimate.

Can a pentest affect my production systems?

It can, especially in aggressive tests against live systems. That's why the scope document specifies testing windows, allowed techniques, and an immediate contact protocol in case something critical happens during the test.

Do I need a pentest if I already have a firewall and antivirus?

Yes. A firewall and antivirus are preventive controls, but they don't confirm whether those controls actually stop a determined attacker. Pentesting is the only way to verify, with a real attack, that your defenses work the way you think they do.

What happens after I get the pentest report?

The internal team prioritizes and fixes the findings based on severity, and it's a good idea to schedule a retest to confirm the fixes actually closed the vulnerabilities, not just that they no longer show up in a shallow scan.


If your business wants to know for certain how exposed it is to a real attack, at AISDC we design pentesting and enterprise security strategies tailored to your infrastructure, with scope, deliverables, and a retest defined from day one, and we connect them with continuous threat detection so security doesn't depend on a single yearly test. If you also want the bigger picture before hiring a pentest, check out our guide to what cybersecurity is, or the specific risks of phishing and social engineering that a well-planned pentest should also cover.

Need help with this at your company? AISDC builds the custom solution for you.

Talk to AISDC