Defense

Penetration Testing

An authorised simulated attack against systems to find exploitable weaknesses before a real attacker does.

Definition

Penetration testing, often shortened to pentest, is an authorised and scoped simulated attack against systems, applications or people, carried out to identify weaknesses that a real attacker could exploit.

The defining features are authorisation and scope. A pentest is agreed in advance, bounded to named targets and time windows, and documented. Without written authorisation the same activity is simply an intrusion, which is why the engagement letter matters as much as the technical work.

Tests are usually described by how much the tester is told. Black box means minimal information, closest to an external attacker. White box means full access to source and architecture, which finds more issues per hour. Grey box sits between and is the most common in practice.

The most important thing to understand is what a pentest does not tell you. It is a point-in-time assessment of a defined scope, so it says nothing about systems outside that scope, changes made afterwards, or human susceptibility unless social engineering was explicitly included. Passing a pentest is not evidence that an organisation is secure.

At a glance

Type
Assessment activity
Also known as
Pentest, ethical hacking, uji penetrasi

How it works

  1. 1

    Scoping and authorisation: targets, methods, timing and limits are agreed and documented in writing

  2. 2

    Reconnaissance: information about the target is gathered from public and permitted sources

  3. 3

    Discovery: services, versions and potential weaknesses are enumerated

  4. 4

    Exploitation: the tester attempts to use those weaknesses, then escalates to see how far access reaches

  5. 5

    Reporting and retest: findings are documented with severity and remediation advice, then verified after fixes

Key points

  • Authorisation and scope are what separate a pentest from an intrusion
  • It is a point-in-time result, valid for the scope tested on the date tested
  • A pentest and a vulnerability assessment answer different questions
  • Social engineering is usually out of scope, so human risk stays unmeasured
  • The value is in remediation and retest, not in the certificate of completion

Best practices

  • Put authorisation, scope and emergency contacts in writing before any testing starts
  • Retest after remediation, since an unverified fix is not a fix
  • Test after significant change, not only on an annual cycle
  • Include social engineering explicitly, or cover it with a continuous programme instead
  • Read the scope statement before drawing conclusions about what the result actually proves

Real-world example

An Indonesian fintech commissions an annual pentest covering its customer application and passes with two medium findings. Its call centre, staff email and third-party admin portal were out of scope. Three months later an attacker reaches customer data by phoning a call centre agent, an avenue the test was never asked to examine.

How Claro helps

Most penetration tests exclude social engineering, or sample it with a handful of phishing emails on one day. Claro covers that gap continuously rather than annually, measuring workforce susceptibility across email, WhatsApp, SMS and voice, with per-user trends rather than a single snapshot.

Frequently asked questions

What is penetration testing?

Penetration testing is an authorised, scoped simulated attack against systems, applications or people, carried out to find weaknesses a real attacker could exploit. Authorisation and defined scope are what distinguish it from an actual intrusion.

What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment identifies and prioritises known weaknesses broadly, usually with automated scanning, and answers what might be wrong. A penetration test attempts to exploit weaknesses to prove real impact and chain them together, answering what an attacker could actually achieve. Assessments are broad and frequent; tests are deep and periodic.

How often should we run a penetration test?

At least annually for most regulated organisations, and additionally after any significant change to architecture, authentication or exposure. Annual-only testing leaves long windows where changes go unexamined.

Does a penetration test cover phishing and social engineering?

Usually not, unless explicitly included in scope. Where it is included it is typically a one-day sample rather than sustained measurement, so human susceptibility is generally better addressed through a continuous awareness programme.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo