What is a pentest?
A pentest (penetration test) is an authorised, controlled simulation of a real attack, in which an expert tries to break into your systems to find exploitable vulnerabilities.
Unlike an automated scan, here a person thinks like an attacker: chains flaws, tries paths and shows how far someone could actually get.
Types of pentest
- Web and applications: your site, portal, app.
- External (perimeter) network: what's visible from the internet.
- Internal network: what would happen if an attacker is already inside.
- Wi-Fi and social engineering, depending on scope.
When and why do one?
A pentest gives you a real picture of your exposure. It makes sense:
- Before launching a product or service.
- Because a client or standard requires it (ISO 27001, ENS, contracts).
- After major changes to your systems.
- On a regular basis, so you don't get comfortable.
How we work
- Scope and rules. What's tested and what isn't, with written permission.
- Reconnaissance. Information gathering.
- Controlled exploitation. A real break-in attempt, without breaking anything.
- Executive + technical report. What we found, its risk and how to fix it.
- Retest. We confirm the fixes actually close the gaps.
A pentest is a snapshot; risk changes every week. With Plan Tria you close the gaps and keep them closed, instead of starting from scratch at every test.
Frequently asked questions
Is a pentest dangerous for my systems?
No, it's done in a controlled way, with rules and written permission. The goal is to find flaws, not cause damage.
How often should I do one?
At least once a year, and always after major changes or before launching something new.
Pentest or vulnerability scan?
A vulnerability scan is automated and broad; a pentest is manual and deep, with an expert actually exploiting flaws. They complement each other.
Does it help with ISO 27001 or the ENS?
Yes: the pentest report is common evidence to show you assess your technical security.