Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Knowledge hub / Penetration test

Knowledge hub

Penetration test

A time-boxed engagement where skilled people attack your systems by hand.

What it means

A penetration test is a time-boxed engagement. Experienced people attack an agreed part of your systems by hand, inside rules you both sign, and write up what they found along with the steps to repeat it.

People do the work, and that is the point. A tester follows a hunch, chains three small oddities into one serious finding, and understands that a discount code which can be applied twice matters even though nothing technically broke.

Why it matters

It is the best evidence about your security that money buys, and enterprise customers, insurers and investors ask for the report by name. A skilled tester finds things nothing else will.

The limitation is time rather than quality. The report describes the application as it stood during one week, and you ship changes every week afterwards. So the sensible shape is a deep annual look, with something automated covering the other eleven months. Cyberlop sits beside the annual test rather than in place of it.

How it shows up

Four things decide whether the money is well spent. A scope covering the parts you actually worry about. Credentials for every role. An environment with realistic data. And a retest, because an untested fix is a hope. NIST's testing guide treats planning and reporting as part of the work rather than paperwork around it.

Read the methodology section as carefully as the findings. It tells you what the testers covered and, just as usefully, what they never reached. A report listing scanner output under a logo is a different product from one where a person spent the week thinking about your application.

Questions people ask

Penetration test, answered

How often do we need one?

Once a year is the common floor, and most frameworks and enterprise contracts also ask for a test after any significant change.

Check the exact wording of whichever standard applies to you, because the requirements differ and some name internal and external testing separately.

How much does a penetration test cost?

It varies enormously, because you are buying days of a skilled person's time. The honest way to compare quotes is by scope and days, not by headline price.

Ask how many days, who is doing the work, and whether a retest is included. Two quotes that look similar often differ by a factor of two in effort.

Is a penetration test the same as a vulnerability scan?

No. A scan matches known patterns and reports what it recognises. A test has somebody reasoning about your application, chaining findings and deciding what matters in your business.

Some reports sold as tests are scans with a cover page, which is why the methodology section is worth reading first.

What should the report contain?

Findings with the exact request, the response, the account used and the steps to reproduce, plus a methodology section saying what was in scope and what was not.

An executive summary matters too, because somebody who is not an engineer has to act on it.

Can it be done without credentials?

It can, and for a product with a login it tells you very little. Most of your risk sits behind the sign-in page, in what one role can reach that belongs to another.

Give the tester an account for every role you have, and realistic data to work against.

What covers the other eleven months?

Keep the annual test. Cyberlop runs beside it on one application for $699 a year at the founding price, with evidence on every finding. Start with a $199 pilot for 30 days and see.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.