Penetration test scoping, coordination with specialist testers, and — the part that matters — remediation of what the report finds.
Do you need one?
This is worth asking before spending the money, because a large share of businesses requesting a penetration test are trying to answer a question a test does not answer.
If nobody has ever scanned your environment, start there. A vulnerability assessment finds missing patches, exposed services and weak configurations quickly and cheaply. Paying a skilled tester to spend a week discovering that your firewall firmware is three years old is a very expensive way to learn something a scan reports in an hour.
If a customer or insurer has asked for a penetration test by name, you need the real thing, and the scope should be whatever satisfies their requirement.
If you have done the basics and want to know whether they hold, that is exactly what a test is for, and it will produce useful findings.
If you want to know your overall security maturity, an Essential Eight assessment answers that question better and costs less.
Scope determines everything
An unscoped test produces a report nobody can act on. The engagement needs to specify what is being tested and from what position:
External — what an attacker on the internet can reach and do, with no credentials.
Internal — what someone who is already inside can reach, whether that is a compromised workstation, a guest network connection or a contractor.
Microsoft 365 tenant — configuration, identity, conditional access and privilege paths. For a cloud-first business this is frequently the highest-value scope and the least often tested.
Application — a specific web application, its authentication and its authorisation logic.
Each answers a different question and they price differently. Choosing on the basis of what you actually need to know is the difference between a useful engagement and an expensive one.
Why we do not test our own work
We scope, coordinate and remediate. The testing is performed by specialist penetration testing providers.
This is deliberate. Offensive security is its own discipline and the people who are good at it do it full time. More importantly, a provider assessing infrastructure it configured itself is not conducting an independent test — the blind spots in the build are the blind spots in the assessment.
That does cost you the convenience of a single vendor, and it is worth knowing that is the trade we have chosen.
The report is the beginning
The most common failure in penetration testing has nothing to do with the test. It is that the report arrives, gets circulated, and nothing happens. Twelve months later the same engagement produces largely the same findings.
The remediation is the value. We take the findings, triage them by actual exploitability and business impact rather than by the severity label, work through them, and arrange a retest to verify closure — which is also what a customer asking for evidence actually wants to see.