What Is Penetration Testing? How It Works
What a penetration test is, the phases of the process, black-box, white-box and grey-box types, and when it's worth doing for your business.

A penetration test (or pentest) is a controlled simulation of a cyberattack, carried out by security specialists to uncover real vulnerabilities in a system, application or company network before an attacker can find them first. Unlike an automated scan, a pentest actually verifies whether a flaw is exploitable, what impact it would have, and how to fix it.
It's one of the most requested services among businesses that need to meet regulatory requirements (NIS2, ISO/IEC 27001) or that simply want to know their real level of exposure before finding out the hard way.
How a penetration test works
A professional pentest follows a structured method, not a random attempt:
- Information gathering (reconnaissance) — a preliminary analysis of the scope to be tested: domains, public IPs, exposed applications.
- Vulnerability analysis — identifying weak points, often starting from a preliminary vulnerability assessment.
- Exploitation — a controlled attempt to exploit the flaws found, to demonstrate their real impact.
- Escalation and post-exploitation — checking what an attacker could gain once inside (access, data, lateral movement).
- Reporting — a technical, actionable document detailing evidence, risk level and priority of remediation.
Every phase is carried out in a controlled way and agreed in writing beforehand: an unauthorised pentest isn't a service — it's a crime.
The three types: black-box, white-box, grey-box
- Black-box — the tester has no prior information, just like a real external attacker. This is the test closest to an authentic attack scenario.
- White-box — the tester has access to source code, architecture and credentials. This allows for a much deeper, more targeted analysis.
- Grey-box — a middle ground, useful for simulating an attack carried out by someone with partial knowledge of the environment (e.g. an employee or a compromised supplier).
The choice depends on the goal: testing the external attack surface or stress-testing internal resilience.
When to do it
A penetration test makes sense, in particular:
- before releasing a new application or service exposed to the internet;
- after a significant change to infrastructure or network;
- ahead of an audit, a certification, or a regulatory obligation (NIS2, or clients requiring it contractually);
- on a regular basis, not as a one-off event: infrastructure changes, and new vulnerabilities are discovered every week.
It should be kept distinct from a vulnerability assessment, which is broader but less in-depth: the two tools are complementary, not interchangeable — the practical difference between the two is explained here. For businesses subject to NIS2, it's also worth understanding what actually changes in terms of obligations.
A penetration test carried out by an external partner, using a recognised methodology and a report that's readable even by non-technical staff, is the most concrete way to find out where you're really exposed — and act before someone else finds out for you. TN Solutions supports SMBs through every stage, from planning the test to remediating the vulnerabilities found: you can talk to one of our security specialists for an assessment of your attack surface.
Frequently asked questions
Who can interpret a penetration test report?
The report is a technical but structured document: it describes the vulnerabilities found, how they were exploited, the associated risk and the recommended remediation actions. A reputable provider always includes an "executive" summary that's understandable even to non-technical readers, so management can prioritise interventions together with IT.
Can a penetration test be run on cloud environments like Azure or AWS?
Yes, and it's increasingly common. The major cloud providers allow penetration testing activities on their environments, provided their pre-authorisation policies are respected. Cloud tests typically focus on misconfigurations, poorly protected access, exposed storage and vulnerable APIs.
Does a penetration test include social engineering?
Only if explicitly requested and agreed in advance. Phishing simulations or telephone social engineering are used to assess staff responsiveness, not just technology. They must always be defined in writing within the scope of the test, for legal as well as organisational reasons.
What's the difference between a penetration test and red teaming?
A penetration test has a defined scope and a specific objective — for example, an application or a network. Red teaming is a broader exercise, often not announced internally, where a team simulates a real attack across people, processes and technology together. The former is a targeted technical analysis, the latter a scenario-based simulation.
How long does a penetration test take?
It depends on the scope: a test on a single web application may take a few days, while one on a larger network infrastructure can take one to two weeks. A reliable provider always defines a timeline before starting, together with the exact scope of the test.
Is written authorisation required to carry out a penetration test?
Always. Without a written agreement defining the scope, limits, timeline and responsibilities, the activity isn't legal and risks being treated as a real attack. It's a document that protects both the client company and whoever carries out the test.
Technology partners
Want to discuss it with our team?
We analyse your infrastructure for free and propose the most suitable solution.







