resources

What is a
penetration test?

A penetration test — or pentest — means deliberately attacking your system, with your written authorisation, to find what a real attacker could exploit.
The goal isn’t to scare you: it’s to fix things before someone else finds them.

definition

A simulated attack, under a strict framework

A penetration tester reproduces a real attacker’s approach — reconnaissance, finding flaws, exploitation, progression — but within a strict framework: a defined scope, agreed time windows, a signed authorisation and stop conditions. The risk is demonstrated without breaking anything, then explained so you can close it.

Accessing a computer system without authorisation is an offence (articles 323-1 et seq. of the French Criminal Code). That written authorisation is exactly what separates a legitimate penetration test from an intrusion.

scan ≠ pentest

It is not a vulnerability scan

An automated scanner lists potential flaws from signatures. It is useful, fast and cheap — but it produces a lot of noise, ignores business logic and proves nothing. A penetration test goes further: a human verifies what is actually exploitable, chains weaknesses together and measures the concrete impact on your data and your business.

  • Scan: broad, automated, indicative. Answers “where are the known flaws?”
  • Pentest: targeted, manual, demonstrative. Answers “what would an attacker actually get?”
levels of information

Black, grey or white box

Depending on what you want to put to the test, the engagement starts from a different level of information:

  • Black box: no information at the start, like an external attacker. Realistic, but part of the time goes to reconnaissance.
  • Grey box: limited access (a user account, for instance). The best coverage-to-budget ratio in most cases.
  • White box: full access (code, architecture, accounts). Maximum surface covered for a given budget.
what you receive

An actionable report, then a retest

A penetration test doesn’t stop at a list of flaws. You receive an executive summary, a technical breakdown per vulnerability (proof, severity, reproduction, fix), a debrief with your teams, then a retest once fixes are applied. It’s the retest that turns the report into security evidence — useful for your clients, insurers and auditors.

For the detail of scopes (web and API, Android, cloud, Linux, hardware, OSINT) and how an engagement runs, see the penetration testing page. To know whether you need an audit or a pentest, read audit or penetration test.

Let's discuss your needs

A system to test? Let’s talk scope. Single day rate of €1,100 (excl. VAT).

Reply within a few business days, no commitment.