Penetration testing (pen testing) is an authorized, simulated cyber attack in which an ethical hacker tries to breach an organization’s systems using the same tools and techniques a real attacker would. The UK National Cyber Security Centre (NCSC) describes it as a way of gaining assurance that security works, not as the main way to find vulnerabilities. A test ends with a report that ranks each weakness by risk and explains how to fix it.
Key Takeaways
- A penetration test is a permitted attack: scope, timing and off-limits systems are agreed in writing before any testing starts.
- NIST Special Publication 800-115 describes a four-phase method: planning, discovery, attack and reporting.
- Tests are white box (full internal knowledge), black box (minimal knowledge) or grey box (partial knowledge).
- According to the UK government’s Cyber Security Breaches Survey 2025/2026, only 13% of UK businesses carried out penetration testing in the previous 12 months, while 43% identified a breach or attack.
- In the UK, CREST certifications and the NCSC’s CHECK scheme are the main ways to judge a tester’s competence.
An Insight into How We Figure out Weak Points in Business Security
Data security is a hot topic amongst UK businesses and organisations – it is what keeps exploitable data secure from potential threat and keeps the business and its customers safe from potential ransomware attacks. But how do you know how secure that system is?

Most businesses have a comprehensive security system, from anti-malware software to firewalls and beyond. Defending your data is a crucial part of owning and operating a business that deals with data in any form.
This is only the first step of business security though; even businesses who have defended themselves, seemingly adequately, are only getting one side of the picture – the inside looking out.
If you built a wall but only ever saw one side of that wall, there would be no way to tell how solid it was from the other side. You may be able to push one side of the wall all day long and marvel at how strong it was, but a single shove on the other side and it would all come crumbling down. This is where penetration testing services come into the equation – your visual from the other side of the wall.
What Is Penetration Testing?
Penetration testing is designed to help businesses better defend themselves against the estimated 4,000 ransomware attacks that occur on a daily basis (an average reported in 2016 US government interagency guidance on ransomware, not a current count), and any other potential threat to a business’s sensitive information.
The basic explanation of penetration testing is to access a business’s security system from the outside, but there is a lot more to this essential service that is a vital element in any comprehensive security audit.
For example, penetration testing companies such as Fidus provide a simulated attack that mimics what a hacker would do if they were trying to gain unauthorised access into your system. A penetration test is used to locate potential weaknesses in a system and identify where exploitable data could be retrieved.
This could be personal data, credit card details, or system information – anything that could be used by hackers to ransom your business or its customers.
The other side of penetration testing is to see where your business is excelling at defence; where it is incredibly difficult or impossible for parties that are unauthorised to gain access to get into your business data.
This turns penetration testing into a comprehensive reporting service that delivers a full risk assessment of the state of your business’s defences; what more can be done and what doesn’t need immediate attention.
A Closer Look at the Inner Workings of Penetration Testing
When you’re hiring someone to essentially break into your business’s security, you want the assurance that your business is not going to be put at risk during the process; that your information will be secure and that your system is not going to be affected.

Hiring a penetration tester, or ethical hacker as they are commonly referred to, is a highly recommended protocol as part of any secure business system. Many professional ethical hackers hold industry certifications. In the UK, CREST’s penetration testing exams run from the entry-level CREST Practitioner Security Analyst (CPSA) and the CREST Registered Penetration Tester (CRT) up to the advanced CREST Certified Tester (CCT), which comes in Infrastructure (CCT INF) and Application (CCT APP) versions.
Any process involving penetration testing will start with a full scope what you hope to achieve and the setting of clear goals. This includes agreements between the business and penetration tester about times to avoid, which systems need testing, if anything is off-limits, and whether there will be forewarning that the test is occurring.
A decision will also be made as to whether the test will be a whitebox test, where the tester has knowledge of internal systems, or blackbox, where there is only the minimum internal knowledge. Everything gets documented, to make sure each party completely understands the process.
Once the process has been decided upon, the tester will choose the right tools for the job at hand. Different servers require different tools; depending on the tester, they may use existing hacking tools or develop their own tools for hacking into different systems.
Then, the tester focuses on discovering what data could be exploited on the systems. They identify where there may be a potential asset target that could be used by a hacker to exploit the company or its customers; they try to locate everything from public facing infrastructure to outdated software running on the network.
Once a target has been identified, the tester will see whether it is possible to exploit the system(s) to gain remote access, or accomplish previously discussed goals.
The purpose of the test here is to see whether it is possible to gain access to the system without authorisation. Once inside, it’s then a case of seeing what can be retrieved, what can’t be, and where there are major holes in the security system.
Depending how far the business wishes the tester to explore, they can choose whether they want the tester to gain access, or just report that there is a vulnerability in the system where access can be gained.
This is a sophisticated and difficult process but can reveal where the weak points in your business security are and provide a detailed report on how to address them. For all businesses with data to protect, both vulnerability testing and penetration testing should be used as a standard part of creating a defendable system that keeps data secure.
How Does a Penetration Test Work? The Four Phases
NIST Special Publication 800-115, the US National Institute of Standards and Technology’s Technical Guide to Information Security Testing and Assessment (September 2008, still current), splits a penetration test into four phases. NIST notes that this is one acceptable way of grouping the work, not the only one.
- Planning. Rules are identified, management approval is finalized and documented, and testing goals are set. No actual testing happens in this phase.
- Discovery. The tester gathers information about the target and scans for weaknesses such as open services and outdated software.
- Attack. The tester tries to exploit the weaknesses found to confirm whether they are real and how far access can be extended. New findings often send the tester back to the discovery phase.
- Reporting. Findings, their risk and the recommended fixes are written up for the organization.
The NCSC describes a similar engagement pattern from the client’s side: initial engagement, scoping, testing, reporting and follow-up, with a technical point of contact available throughout the test.
White Box, Black Box and Grey Box Testing
The three main test types differ in how much the tester knows before starting. The choice affects cost, depth and realism.
| Test type | What the tester knows | Best for |
|---|---|---|
| White box | Full internal knowledge, such as network diagrams, credentials or source code | Thorough coverage of custom applications and complex systems |
| Black box | Minimal or no internal knowledge | Simulating an outside attacker who starts from scratch |
| Grey box | Partial knowledge, such as a normal user account | Simulating a malicious insider or an attacker with stolen credentials |
For application testing, NIST SP 800-115 notes that white box techniques analyze the source code directly and tend to be more efficient and cost-effective for finding defects in custom applications, while black box techniques test the running program without the source code.
Penetration Testing vs Vulnerability Scanning
Penetration testing and vulnerability scanning are related but not the same. The UK Government Digital Service’s Service Manual puts the difference this way: vulnerability assessments find potential weaknesses, while penetration tests actively attack systems to show how easy those weaknesses are to exploit.
- Vulnerability scanning is usually automated, broad and repeatable, and it can run often.
- Penetration testing is led by a person, deeper and narrower, and it proves whether a weakness can actually be used to reach data or systems.
The NCSC advises treating penetration testing as a check on an organization’s own vulnerability assessment and management processes, not as the primary way of finding vulnerabilities. The GDS Service Manual recommends carrying out both frequently while a service is being built, especially after major changes such as a new dependency or integration, rather than as a one-off check.
How Common Is Penetration Testing in UK Businesses?
Penetration testing is still uncommon among UK organizations. The Cyber Security Breaches Survey 2025/2026, published by the Department for Science, Innovation and Technology on 30 April 2026, reported these figures for the previous 12 months:
| Measure (UK, 2025/2026 survey) | Businesses | Charities |
|---|---|---|
| Identified any cyber breach or attack | 43% | 28% |
| Experienced phishing attacks | 38% | 25% |
| Carried out a cyber security vulnerability audit | 18% | 10% |
| Carried out penetration testing | 13% | 7% |
The same survey found that medium (65%) and large (69%) businesses were more likely to have a breach or attack than micro (42%) and small (46%) businesses. Ransomware affected 1% of businesses, down from 3% in each of the two previous surveys. The survey estimated that UK businesses experienced approximately 5.19 million cyber crimes over the year. Our guide to phishing protection covers the most common attack type in more detail, and the common types of ransomware are explained separately.
How to Choose a Penetration Testing Provider
A penetration tester is given deliberate access to sensitive systems, so the provider’s competence and conduct matter as much as price. These checks help:
- Check certifications. Ask which CREST exams (CPSA, CRT, CCT INF or CCT APP) the testers hold, or equivalent qualifications.
- Check scheme membership for public-sector work. The NCSC’s CHECK scheme sets penetration testing standards that UK government departments, public sector bodies and critical national infrastructure organizations can trust. The GDS Service Manual recommends a CHECK certified team, or staff accredited to equivalent CHECK levels, for government services.
- Agree the scope in writing. Following the NCSC guidance, the scope should record technical boundaries, test types, timeframes, resources, compliance needs and how results will be reported.
- Ask what the report contains. The NCSC expects a report to list the security issues found, a risk rating for each, how to resolve them, and recommendations for improving the organization’s processes.
- Plan the follow-up. Fixes should be retested, and the NCSC warns that a year or more can pass between tests, leaving gaps in visibility in the meantime.
Small and medium businesses can find a practical walkthrough in Pentest 101: a guide to penetration testing for SMBs, and what’s involved in a penetration test is covered in a companion article.
Is Ethical Hacking Legal?
Ethical hacking is legal only with the system owner’s permission. In the UK, the government’s breaches survey defines cyber crime by reference to the Computer Misuse Act 1990, the law that covers unauthorized access to computers. That is why the planning phase ends with documented management approval and an agreed scope: without that written authorization, the same activity would be an attack, not a test. Anyone planning a career in the field can read the principles to keep in mind when learning ethical hacking.
Frequently Asked Questions
What is penetration testing in simple terms?
Penetration testing is a permitted, simulated cyber attack on an organization’s own systems. An ethical hacker tries to break in the way a criminal would, then reports which weaknesses worked, how serious they are and how to fix them.
What are the phases of penetration testing?
NIST Special Publication 800-115 describes four phases: planning, discovery, attack and reporting. Planning sets the rules and goals, discovery finds weaknesses, attack tries to exploit them, and reporting explains the results and fixes.
Is penetration testing the same as ethical hacking?
Penetration testing is one form of ethical hacking. Ethical hacking is the broader term for any authorized attempt to find security weaknesses, while a penetration test is a scoped engagement with agreed goals, a fixed timeframe and a written report.
What is the difference between a vulnerability scan and a penetration test?
A vulnerability scan finds potential weaknesses, usually with automated tools. A penetration test goes further by actively exploiting weaknesses to show how easily an attacker could use them, according to the UK Government Digital Service’s Service Manual.
Which certifications should a penetration tester have?
In the UK, CREST certifications are widely used: CPSA and CRT at entry and intermediate level, and CREST Certified Tester (CCT INF or CCT APP) at advanced level. UK government and critical national infrastructure bodies are directed to the NCSC’s CHECK scheme.
How often should penetration testing be done?
No single interval suits every organization. The GDS Service Manual advises testing frequently while a service is built and after major changes, and the NCSC notes that relying on tests a year or more apart leaves gaps in visibility.