What is the difference between a penetration test and a vulnerability scan?
A vulnerability scan uses automated tooling to identify known vulnerabilities and configuration weaknesses. A penetration test adds manual analysis, exploitation and attack-path validation. It determines whether a weakness can be used in practice, how separate findings can be chained and what level of access or impact an attacker could achieve.
Which systems can be included in a penetration test?
The scope can include web applications, APIs, mobile applications, external infrastructure, internal networks, Active Directory, Microsoft Entra ID, cloud environments, wireless networks, endpoints and OT environments. Combined scopes can be used to examine attack paths across applications, identities, infrastructure and network boundaries.
What is the difference between black box, grey box and white box testing?
A black box test starts without credentials or internal documentation. A grey box test uses limited access or technical context to test authenticated functionality and internal attack paths in greater depth. A white box test includes extensive information such as source code, architecture and configurations. Grey box testing provides the strongest balance between realistic attacker behaviour and technical coverage for most assessments.
Can a penetration test be performed safely in production?
Yes, provided that the scope, rules of engagement, stop conditions and escalation procedures are defined in advance. Techniques that could affect availability are restricted or coordinated separately. OT, healthcare and other safety-critical environments require additional controls and may rely on passive analysis or carefully selected active tests.
How long does a penetration test take?
Duration depends on the size, complexity and required depth of the scope. A limited application or infrastructure assessment may require one or a few test days. Complex environments with multiple roles, networks, cloud platforms or OT systems may require several days up to one or more weeks. The required effort is established during technical scoping during the intake call.
What does a penetration test report contain?
The report contains the agreed scope, methodology, validated findings, affected assets, technical evidence, attack paths, impact analysis and remediation guidance. Findings are scored using CVSS v4 and interpreted within the operational context of the environment. Critical findings are communicated during the test rather than held until final reporting.