What Is Penetration Testing? A Plain-English Guide

Penetration testing is a controlled, authorised attack on your systems to find real vulnerabilities before criminals do. Here's how it works and what it costs.

A penetration test (usually shortened to 'pentest') is a controlled, authorised attack on your systems, carried out by security professionals using the same techniques as real attackers. The goal is to find exploitable weaknesses, prove their real-world impact, and hand you a prioritised plan to fix them. It answers a question no automated tool can: if a capable attacker targeted us today, what would actually happen?

What happens during a penetration test

Every engagement is different, but a well-run penetration test follows a broadly similar arc:

  • Scoping. You and the testing team agree what is in scope (applications, IP ranges, cloud accounts, user roles), what is off limits, and how testing will be conducted. Good scoping is where most of the value is won or lost.
  • Reconnaissance. Testers map the target: the technologies in use, entry points, exposed services, and anything the internet already knows about your organisation.
  • Vulnerability discovery. A mix of manual testing and tooling identifies potential weaknesses, from missing patches to business logic flaws that no scanner will ever find.
  • Exploitation. This is what separates a pentest from a scan. Testers safely exploit what they find to demonstrate genuine impact: reading another customer's data, escalating privileges, or pivoting deeper into the environment.
  • Reporting. You receive a report describing each finding with evidence, business impact, and specific remediation guidance, ordered by severity.

A good report serves two audiences at once: an executive summary your board and customers can read, and technical detail your engineers can action without guesswork.

How a pentest differs from a vulnerability scan

Vulnerability scanners are automated tools that compare your systems against a database of known issues. They are fast, cheap and worth running regularly, but they only find what they have signatures for. They cannot chain findings together, and they have no concept of your business logic.

A penetration test is human-led. Testers verify every finding (so you are not chasing false positives), uncover the classes of flaw scanners are blind to — authorisation bypasses, logic abuse, chained attacks — and prove exploitability rather than guessing at it. We cover this distinction in detail in penetration test vs vulnerability scan.

Common types of penetration test

  • Web application testing. The most common engagement: testing a web app and its underlying platform for flaws like injection, broken access control and authentication weaknesses.
  • API testing. APIs power most modern applications and mobile apps, and they fail in their own distinctive ways — particularly around authorisation.
  • External network testing. An attacker's-eye view of everything your organisation exposes to the internet: services, VPNs, mail infrastructure, forgotten hosts.
  • Cloud testing. Reviewing AWS, Azure or GCP environments for misconfigurations, over-permissive identities and exposed resources.
  • Social engineering. Testing the human layer through phishing and related techniques, usually alongside a technical engagement.

Black box, grey box and white box

These terms describe how much information testers start with. In a black box test, they begin with little more than a company name or URL — realistic, but time is spent on discovery rather than depth. In a white box test, they get source code, architecture documents and full credentials — maximum depth, less realism. Grey box sits in between: testers get credentials and documentation but no source code. For most organisations, grey box offers the best value, because it spends your budget finding vulnerabilities rather than reverse-engineering how the application works.

Why organisations get penetration tests

In practice, pentests are driven by a mix of motives:

  • Compliance. ISO 27001, SOC 2 and PCI DSS all expect regular technical testing in one form or another.
  • Customer requirements. Enterprise security questionnaires almost always ask for a recent penetration test report or attestation letter.
  • Genuine assurance. You have built or significantly changed something and want to know it holds up before attackers, not auditors, find out.
  • Post-incident confidence. After a breach or near miss, testing validates that the holes are actually closed.

What does it cost, and how long does it take?

Most single-scope penetration tests involve one to two weeks of testing plus reporting. In Australia, professionally delivered tests generally start around AU$6,000 and range up to AU$18,000 or more for large, complex scopes. Price is driven almost entirely by how many days of skilled testing your scope requires — we break down real numbers in how much a penetration test costs in Australia.

Be wary of anything dramatically cheaper. A 'pentest' for a few hundred dollars is almost always an automated scan with a new label.

FAQ

Is penetration testing legal?

Yes, provided it is authorised. Before testing starts, both parties sign rules of engagement that define exactly what may be tested, when, and how. Attacking systems without the owner's permission is a crime — which is precisely why authorisation and scoping are handled so carefully.

How long does a penetration test take?

Most single-scope engagements involve 4–10 business days of hands-on testing, with the report delivered shortly after. Larger or multi-scope engagements take longer. Scheduling lead time is typically two to six weeks, so it pays to book ahead of any deadline.

Will a penetration test break our systems?

It is very unlikely. Professional testers avoid destructive actions, agree any higher-risk checks with you in advance, and can test a staging environment where the risk to production matters. Clear communication channels mean anything unexpected is flagged immediately.

If you are weighing up a penetration test, we make it easy to start: a free scoping call, a fixed quote within one business day, and a free retest of fixed issues within 90 days. Get in touch and we will scope it with you.

Need cybersecurity expertise?

Drop your email and we'll be in touch within one business day.