Penetration Testing
An authorised simulated attack against systems to find exploitable weaknesses before a real attacker does.
Definition
Penetration testing, often shortened to pentest, is an authorised and scoped simulated attack against systems, applications or people, carried out to identify weaknesses that a real attacker could exploit.
The defining features are authorisation and scope. A pentest is agreed in advance, bounded to named targets and time windows, and documented. Without written authorisation the same activity is simply an intrusion, which is why the engagement letter matters as much as the technical work.
Tests are usually described by how much the tester is told. Black box means minimal information, closest to an external attacker. White box means full access to source and architecture, which finds more issues per hour. Grey box sits between and is the most common in practice.
The most important thing to understand is what a pentest does not tell you. It is a point-in-time assessment of a defined scope, so it says nothing about systems outside that scope, changes made afterwards, or human susceptibility unless social engineering was explicitly included. Passing a pentest is not evidence that an organisation is secure.
At a glance
- Type
- Assessment activity
- Also known as
- Pentest, ethical hacking, uji penetrasi
How it works
- 1
Scoping and authorisation: targets, methods, timing and limits are agreed and documented in writing
- 2
Reconnaissance: information about the target is gathered from public and permitted sources
- 3
Discovery: services, versions and potential weaknesses are enumerated
- 4
Exploitation: the tester attempts to use those weaknesses, then escalates to see how far access reaches
- 5
Reporting and retest: findings are documented with severity and remediation advice, then verified after fixes
Key points
- Authorisation and scope are what separate a pentest from an intrusion
- It is a point-in-time result, valid for the scope tested on the date tested
- A pentest and a vulnerability assessment answer different questions
- Social engineering is usually out of scope, so human risk stays unmeasured
- The value is in remediation and retest, not in the certificate of completion
Best practices
- Put authorisation, scope and emergency contacts in writing before any testing starts
- Retest after remediation, since an unverified fix is not a fix
- Test after significant change, not only on an annual cycle
- Include social engineering explicitly, or cover it with a continuous programme instead
- Read the scope statement before drawing conclusions about what the result actually proves
Real-world example
An Indonesian fintech commissions an annual pentest covering its customer application and passes with two medium findings. Its call centre, staff email and third-party admin portal were out of scope. Three months later an attacker reaches customer data by phoning a call centre agent, an avenue the test was never asked to examine.
How Claro helps
Most penetration tests exclude social engineering, or sample it with a handful of phishing emails on one day. Claro covers that gap continuously rather than annually, measuring workforce susceptibility across email, WhatsApp, SMS and voice, with per-user trends rather than a single snapshot.
Frequently asked questions
What is penetration testing?
Penetration testing is an authorised, scoped simulated attack against systems, applications or people, carried out to find weaknesses a real attacker could exploit. Authorisation and defined scope are what distinguish it from an actual intrusion.
What is the difference between a vulnerability assessment and a penetration test?
A vulnerability assessment identifies and prioritises known weaknesses broadly, usually with automated scanning, and answers what might be wrong. A penetration test attempts to exploit weaknesses to prove real impact and chain them together, answering what an attacker could actually achieve. Assessments are broad and frequent; tests are deep and periodic.
How often should we run a penetration test?
At least annually for most regulated organisations, and additionally after any significant change to architecture, authentication or exposure. Annual-only testing leaves long windows where changes go unexamined.
Does a penetration test cover phishing and social engineering?
Usually not, unless explicitly included in scope. Where it is included it is typically a one-day sample rather than sustained measurement, so human susceptibility is generally better addressed through a continuous awareness programme.
Related terms
Vulnerability Assessment
A systematic review that identifies, classifies and prioritises known weaknesses across systems.
Attack Surface
The total set of points, technical and human, where an attacker could attempt to gain entry to a system or extract data, including every account, endpoint, application, exposed service, and employee.
Zero-Day
A software vulnerability that is unknown to the vendor and has no available patch, leaving no time (zero days) to prepare a defense before it is exploited.
Social Engineering
The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo