Let's talk about your project
01 / Knowledge hub

What is a penetration test?

A penetration test is a security assessment that looks for weaknesses in your systems using a real attacker's methods, but with your written permission and under control. The aim is not to cause damage but to expose weaknesses, with evidence, before someone else finds them.

  1. 01

    A short definition

    A penetration test (pentest for short) is an authorised attack simulation that measures how exposed a website, application or network is to unauthorised access. The tester finds weaknesses, confirms within safe limits whether they can really be exploited, and reports each finding with evidence and a recommended fix. A test is only carried out with the system owner's written permission and a written scope.

  2. 02

    How it differs from a scan

    A vulnerability scan is an automated check: it looks for known weakness signatures and produces a long list of possible issues. That list contains false alarms, while flaws in business logic never show up at all. In a penetration test, a specialist verifies findings by hand, examines how several small weaknesses could combine into a serious risk, and explains the real impact. Scanning is useful for routine upkeep; a penetration test answers the question of what an attacker could actually do.

  3. 03

    Types of test

    By target, tests are divided into web application, mobile application, API, external network and internal network tests. By the information provided, there are two approaches: in a black-box test the tester is given only the target address and starts like an outside attacker; in a grey-box test, test accounts are provided and what a signed-in user can reach is examined as well. Social engineering attempts such as phishing are a separate piece of work, and each one needs its own written approval.

  4. 04

    How a test runs

    First the scope is written: which domains, IP addresses and applications will be tested, on which dates and at what times, and with which method. A signed authorisation is obtained and a contact person reachable during the test is named. Then come reconnaissance, searching for weaknesses and verification; attempts that could interrupt the service are not made by default. If an unexpected effect appears, work stops and you are informed. Finally the findings are reported and, once fixed, retested.

  5. 05

    How often to test

    A one-off test only captures that day's picture. As a general rule, it makes sense to test at least once a year, and also after a major release, an infrastructure change or the addition of a new payment or membership flow. Customer contracts, tenders or audits may require a specific frequency; if so, write that requirement into the scope.

  6. 06

    What drives time and cost

    The main drivers of time and price are the number of targets, the size of the application and the number of user roles, whether the work is black-box or grey-box, extra components such as a mobile app or an API, and the languages the report is needed in. Typically, testing a small web application takes days while broad engagements take weeks; the exact duration is given in the quote once the scope document is written. A quote with a vague scope cannot be compared with another.

  7. 07

    Penetration testing at Doki

    In our penetration testing service, the scope is written before testing starts and only the targets you have authorised in writing are tested. Tests run on weekdays during working hours, findings are verified by hand before they go into the report, and one retest within 30 days of the report is included in the price. To see which scope fits you, look at our test packages or tell us which systems you want tested.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.