What Is Penetration Testing?

Penetration testing is an authorized, simulated attack on your systems, carried out by security specialists who try to break in the way a real attacker would. The goal is not a list of theoretical weaknesses but proof: which flaws can actually be exploited, what an attacker would reach through them, and what to fix first.
Who penetration testing is for
Teams shipping software continuously, where the code tested last quarter is no longer the code running in production today.
Organizations facing a SOC 2, ISO 27001 or PCI DSS audit that need evidence a real person attempted exploitation — not a scanner export.
Security leaders who have to translate technical findings into an answer to the board's question: which of these could actually cost us money?

[ FUNDAMENTALS ]
Penetration test, vulnerability scan, continuous pentesting
All three get sold as security testing, and the difference matters the moment an auditor, an enterprise customer or your board asks what you actually did. A scanner lists what might be vulnerable. A penetration test proves what is. Continuous penetration testing keeps that proof current as your systems change.
Most mature programs run all three: scanning for hygiene, human-led testing for depth, and continuous validation so neither goes stale.
[ TYPES AND PROCESS ]
The main types of penetration test
Scope is what separates one penetration test from another. These are the engagements most organizations actually buy, and what each one is looking for.
External network penetration testing
Everything reachable from the internet: perimeter services, VPN and remote access endpoints, mail and DNS, and forgotten subdomains. The objective is to find the way in before someone else maps it.
Internal network penetration testing
Starts from a foothold already inside the network and asks how far it goes: lateral movement, credential reuse, and the Active Directory paths that end in domain administrator.
Web application penetration testing
Authentication and session handling, access control between users and tenants, injection, and business logic that can be abused without breaking a single technical rule.
API penetration testing
Undocumented endpoints, broken object-level authorization, and the assumption that only your own mobile app will ever call the API. APIs now carry most of the traffic and get a fraction of the testing.
Cloud penetration testing
IAM roles that grant far more than intended, exposed storage, instance metadata services, and misconfigured managed services across AWS, Azure and GCP.
Social engineering and red teaming
Phishing, pretexting and physical access, usually as part of a broader red team exercise that tests detection and response rather than a single technical target.
Strike runs these as a continuous program rather than isolated projects. See penetration testing services, web application penetration testing, and the full testing methodology.
How a penetration test works, step by step
1. Scoping and rules of engagement. What is in scope, what is explicitly off limits, when testing may run, and who to call if something breaks. The written authorization produced here is what makes the test lawful.
2. Reconnaissance. Mapping the real attack surface: domains, IP ranges, services, technologies, leaked credentials and third-party assets. Most engagements surface assets the client did not know were exposed.
3. Vulnerability discovery. Automated and manual identification of weaknesses across the mapped surface, prioritized by how likely each one is to actually lead somewhere.
4. Exploitation. The step that separates a penetration test from a scan. Testers attempt real exploitation, under the agreed rules, to confirm the weakness exists and is reachable in practice.
5. Post-exploitation and lateral movement. From a confirmed foothold, how much further can an attacker go: privilege escalation, pivoting between systems, and access to the data that would actually matter.
6. Reporting and retesting. Findings with evidence, business impact and remediation guidance, followed by a retest that confirms the attack path is closed rather than assuming it.
[ DELIVERABLES ]
What a penetration testing report should contain
The report is the product you are actually buying. If it reads like a scanner export with a logo on the cover, you paid for a scan. Four things separate a useful report from a compliance artifact.
Executive summary
What was tested, what an attacker was able to achieve, and what that would mean for the business — written so a non-technical executive can make a decision from it.
Reproducible evidence
For every finding: the affected asset, the exact steps to reproduce it, requests, responses or screenshots, and the preconditions required. If your engineers cannot reproduce it, they cannot fix it.
Risk rating with context
Severity that accounts for real exploitability and business impact in your environment, not a raw CVSS number copied from a database and applied without context.
Remediation and retest
A specific fix for each finding rather than generic advice, plus confirmation after remediation that the attack path is genuinely closed.
How much does a penetration test cost?
Price is driven by scope and depth, not by a rate card. The variables that move it most are the number and type of targets, whether testing is authenticated, how much manual exploitation the scope demands, and whether you need a single report or coverage that stays current.
A narrow unauthenticated external test of a handful of hosts sits at the low end of the market. A full authenticated web application and API assessment with manual business-logic testing sits at the high end. One-off engagements are priced per project; continuous penetration testing is normally priced as a subscription tied to the size of your attack surface, which is what makes retesting after every fix economically viable instead of a change order.
The more useful comparison is cost per unit of assurance. An annual report that is already out of date six weeks after delivery can cost less and buy considerably less than continuous testing that keeps the answer current — the model behind penetration testing as a service.
[ FAQ ]
Penetration testing FAQ
Is penetration testing legal?
Yes, when it is authorized. What makes a penetration test legal is written permission from the owner of the systems in scope, defining exactly what may be tested, how, and during which windows. Testing without that authorization is a criminal offence in most jurisdictions, which is why every legitimate engagement starts with a signed rules-of-engagement document.
How long does a penetration test take?
A focused external test or a single web application typically takes one to two weeks of active testing plus reporting. Broad scopes, authenticated testing and complex business logic push that out. Continuous penetration testing changes the shape of the question: testing runs permanently and each finding arrives once it has been validated, instead of arriving all at once weeks later.
How often should we run a penetration test?
At minimum once a year, and again after any significant change to architecture, authentication or exposed infrastructure. For teams deploying weekly, that rule effectively means continuously — an annual test verifies the version of your product that existed on the week it ran, not the one your customers are using now.
Does penetration testing satisfy SOC 2, ISO 27001 or PCI DSS?
Penetration testing supports all three. SOC 2 auditors and ISO 27001 assessors expect evidence that technical testing happens and that findings are remediated, and PCI DSS requires penetration testing explicitly. No single test certifies compliance on its own — it is one control among many, and what auditors look for is evidence of a repeatable process rather than a one-off PDF.
What is the difference between penetration testing and ethical hacking?
Ethical hacking is the broader practice of using attacker techniques with permission to improve security. A penetration test is one scoped, time-bound engagement inside that practice, with a defined target, an agreed methodology and a deliverable. Read more on ethical hacking.
Is retesting after remediation included?
It should be, and it is worth asking before you sign. A fix is unverified until somebody re-attempts the original attack path — patches get applied to the wrong environment, and configuration changes get reverted. Ask any provider whether retesting is included, how many times, and for how long after delivery.
PENETRATION TESTING
More than a test. A strategic layer for real security.
Our AI is powered by a proprietary data layer built from thousands of hours of pentesting and real-world validations. Strike combines autonomous execution and expert human validation to uncover complex risks, reduce noise, and prioritize actionable findings.
In-depth continuous testing
Strikers uncover high-impact vulnerabilities across multi-technology environments (web apps, APIs, mobile, cloud, and more).
AI-led retesting on-demand
Validate fixes instantly, without waiting for the next testing cycle.
Real-time fixing
AI agents guide your team step-by-step through remediation to accelerate resolution.
Step-by-step Threat emulation creation
Easily scope, launch, and track your Threat emulation with full transparency.
Human triaging & peer review
Every finding is validated by security experts to ensure accuracy and impact.
Full visibility
Track every finding with complete transparency through security expert work logs and real-time notifications.
Seamless integrations
Connect directly with Slack, Teams and Jira to streamline collaboration with your security and development teams.
Vulnerability Manager
Visualize, manage, and retest vulnerabilities in one platform, with full context on severity, sources, and remediation.
Compliance-ready reporting
Automatically generate up-to-date reports aligned with PCI DSS, HIPAA, ISO 27001, SOC 2, and more.
Ongoing partnership
Weekly check-ins with a dedicated Customer Success Manager, plus personalized onboarding and strategic planning.
A penetration test answers the question a scanner cannot: not what looks vulnerable, but what an attacker can actually reach, chain together and turn into a breach.
Trusted by security teams that lead
Human expertise.
AI power.
Superior security.
Whether you’re scaling fast, closing enterprise deals, or just tired of noisy reports, we’ll help you build a security stack that moves faster than your threats.






