If you've been quoted for a penetration test and aren't entirely sure what you're paying for, you're not alone. It's one of the least understood line items in a cybersecurity budget, partly because the popular image of "hacking" doesn't match what a professional test actually looks like. Here's what actually happens.

It Starts With Scoping, Not Hacking

Before anything technical happens, a proper test starts with agreeing exactly what's in scope: which systems, which networks, what's explicitly off-limits, and getting formal written authorisation to proceed.

This isn't paperwork for its own sake. It's what separates a legitimate, professional test from something that could land the tester, and by extension you, in legal trouble. Testing a system without clear authorisation is, technically, the same action as attacking it. The scoping stage is what turns it into a service rather than an incident. A good tester will also agree things like testing windows, what happens if they find something critical mid-test, and how sensitive data discovered along the way is handled.

Reconnaissance and Vulnerability Discovery

With scope agreed, the tester starts mapping out what's actually exposed: open ports, outdated software versions, misconfigurations, weak or reused credentials, anything an attacker could realistically use as a way in.

Much of this overlaps with a standard vulnerability assessment. A scanner can flag the same missing patches and open ports a human tester would notice. The difference starts in what happens next.

The Actual Exploitation Phase

This is the part that distinguishes a penetration test from a vulnerability scan, and it's the part you're actually paying for. Rather than simply listing weaknesses, the tester attempts to exploit them, in a controlled and agreed way, to prove real-world impact rather than theoretical risk.

Could they actually get into a system using that weak credential? Once in, could they access real data, or was the exposure more limited than it looked on paper? Could they move further into the network from that initial foothold, escalating privileges or reaching systems that weren't the original target? This is where a "medium severity" finding on a scanner report either turns out to be a genuine path to your most sensitive data, or a dead end that isn't worth losing sleep over. Only actual exploitation tells you which.

The Report Is the Actual Deliverable

Everything above exists to produce one thing: a report your business can actually act on. A good penetration test report doesn't just list findings. It prioritises them by real risk rather than raw technical severity, explains them in language your team can understand without a security background, and sets out a clear remediation path for each one.

If the report you receive reads like raw scanner output with a company logo on the front page, you didn't get what you paid for. The value of a penetration test isn't the list of vulnerabilities. It's the judgement applied to that list: which ones actually matter, why, and what to do about them first.

Choosing Between a Vulnerability Assessment and a Full Test

Not every business needs a full penetration test as a starting point, and not every budget needs to go there immediately. A vulnerability assessment is faster and cheaper, and it's a reasonable place to start if you've never had one done at all. A full penetration test earns its cost once you need to know whether those vulnerabilities are actually exploitable in practice, which matters more the more sensitive your data is and the more scrutiny your business is under.

If you're weighing up which one is the right starting point for where your business actually is, that's exactly the kind of question a free review can help answer.