Five Signs Your Business Needs a Penetration Test
Five practical signs that changes to your business, systems or customer expectations mean it may be time for a penetration test.
Many businesses arrange a penetration test only when a customer, insurer or regulator asks for one.
By that point, the test is often urgent. There may be a tender deadline approaching, a contract waiting to be signed or a customer asking for evidence before supplier onboarding can continue.
That leaves limited time to define the right scope, complete the testing, address any findings and arrange independent retesting.
Penetration testing is more valuable when it is planned around meaningful changes in the business, its technology and the threats it faces. It should not be treated simply as an annual compliance task that can be repeated without considering what has changed.
So, how do you know when it might be time to arrange a penetration test?
Here are five practical warning signs.
1. Your business or IT environment has grown quickly
Business growth is generally good news, but rapid growth can make an IT environment more difficult to understand and control.
Growth may result in:
- More employees and user accounts
- New offices and remote workers
- Additional cloud services
- New servers, laptops and mobile devices
- More suppliers with access to systems
- Additional applications and integrations
- Permissions accumulating without review
- Inconsistent security configurations
Systems introduced quickly may not receive the same level of security review as established infrastructure.
A temporary account created for a supplier may remain active long after the work has finished. A new cloud platform might be deployed using default settings. Employees who change roles may retain access that is no longer required.
Individually, these issues may appear relatively minor. Together, they can create routes through which an attacker could move from one system to another.
For example, a compromised employee account might provide access to a shared system. That system could reveal credentials or information that helps the attacker reach a more sensitive part of the environment.
A penetration test can examine whether growth has created:
- Unnecessary internet exposure
- Excessive user privileges
- Weak authentication
- Inconsistent security controls
- Poor separation between systems
- Forgotten accounts or services
- Opportunities for an attacker to move through the network
The objective is not simply to identify individual vulnerabilities. It is to understand how the environment behaves as a whole and whether one weakness could provide a route to important systems or information.
If your business has expanded significantly since its last security assessment, the risk may have changed even if no major incident has occurred.
2. You have launched or significantly changed an application
Launching a new application is one of the clearest reasons to arrange penetration testing.
A customer portal, web application, API or mobile application may expose business functions and sensitive information directly to the internet. Functional testing can confirm that the application behaves as intended, but it may not identify how the application behaves when somebody deliberately misuses it.
Potential security weaknesses include:
- Broken access controls
- Account takeover
- Insecure file uploads
- Exposure of sensitive information
- Injection vulnerabilities
- Weak session management
- Users accessing another customer’s records
- Flaws in password-reset processes
- Abuse of business workflows
- Missing restrictions on sensitive actions
Some of the most serious application weaknesses are not obvious technical errors.
An application might correctly process every request but fail to verify that the user is authorised to perform the requested action. This could allow one customer to view another customer’s records by changing an identifier in a request.
A business process may also work exactly as designed but still be open to abuse. An attacker might be able to bypass an approval step, manipulate a price, reuse a discount or perform an action in an unintended order.
These are problems that automated vulnerability scanners and ordinary functional testing can easily miss.
Penetration testing should not be limited to the application’s first launch. It may also be appropriate following:
- A major software update
- A platform migration
- The introduction of a new API
- A change to authentication
- Integration with a third-party service
- A redesigned customer journey
- Changes to payment or file-upload functionality
- Significant changes to user roles and permissions
Testing early gives developers time to understand and resolve findings before the application is exposed to customers and attackers.
Where pre-launch testing is not practical, the test should be arranged as soon as possible after deployment, with appropriate controls in place to minimise the risk to live data and services.
3. You provide remote access to business systems
Remote access is now essential for many organisations.
Employees may work from home, suppliers may provide remote support and administrators may need to manage systems from different locations. However, remote access also places important services within reach of internet-based attackers.
Examples include:
- VPN gateways
- Remote desktop services
- Cloud administration portals
- Microsoft 365
- Virtual desktop platforms
- Supplier support connections
- Remote monitoring and management tools
- Web-based administration interfaces
Attackers continuously scan the internet looking for exposed services. They may attempt to exploit known vulnerabilities, use passwords exposed in previous data breaches or repeatedly try common credentials across multiple accounts.
Multi-factor authentication provides an important additional layer of protection, but the wider configuration still matters.
A penetration test can assess whether remote-access services:
- Expose unnecessary information
- Use supported and updated software
- Permit insecure authentication methods
- Enforce multi-factor authentication appropriately
- Reveal valid usernames
- Apply suitable account-lockout controls
- Use securely configured encryption
- Expose administrative interfaces unnecessarily
- Provide more access than users require
Testing can also look beyond the initial login.
A valuable question is not simply, “Can an attacker access this service?” It is also, “What could an attacker do if a remote account or employee device were compromised?”
If a standard remote user can access management systems, sensitive data or large parts of the internal network, the consequences of a single compromised account could be considerable.
An internal penetration test can simulate this situation in a controlled way. It can investigate whether an attacker starting with limited access could escalate privileges, access sensitive information or compromise other systems.
4. Your infrastructure contains older or inherited technology
Legacy technology is not automatically insecure. Some older systems remain well supported, properly configured and isolated from unnecessary access.
The difficulty is that ageing and inherited systems can be harder to understand, update and manage.
Warning signs may include:
- Unsupported operating systems
- End-of-life applications
- Old network devices
- Systems inherited through a merger or acquisition
- Services that nobody fully understands
- Default or shared credentials
- Applications that cannot be patched easily
- Weaknesses accepted years ago but never reviewed
- Systems maintained by former employees or suppliers
- Incomplete documentation
A vulnerability scan may identify outdated software and known vulnerabilities. This is useful, but it does not always show whether those weaknesses can be exploited or combined.
A penetration tester may discover that a low-profile legacy service exposes credentials that can be reused elsewhere. An outdated application might provide access to a server that contains connections to more sensitive systems. A shared administrator password could allow one compromised device to affect several others.
The risk often lies in the relationship between the weaknesses rather than any single finding.
Penetration testing can help answer questions such as:
- Can the legacy system be reached by ordinary users?
- Could it provide a route into more sensitive systems?
- Are old credentials still valid elsewhere?
- Can the system be isolated more effectively?
- What is the realistic business impact if it is compromised?
- Are existing compensating controls effective?
Concerns about fragile systems should not prevent testing.
A professional penetration test can be carefully scoped to account for operational risk. Potentially disruptive techniques can be excluded, testing windows can be agreed and particularly sensitive systems can be assessed using a more cautious approach.
The purpose is not to recklessly attack critical infrastructure. It is to provide useful assurance without creating unacceptable risk to the business.
5. Customers keep asking security questions
Repeated security questionnaires, tender requirements and supplier assessments are a strong indication that customers expect evidence of effective cybersecurity.
Customers may ask:
- When was your last penetration test?
- Who performed the testing?
- Was the tester independent?
- Which systems were included?
- Were high-risk findings resolved?
- Was independent retesting completed?
- Can you provide an executive summary?
- Can you provide a confirmation letter?
These questions are particularly common when a supplier will handle sensitive information, access customer systems or provide a business-critical service.
A recent independent penetration test can support:
- Tender responses
- Supplier onboarding
- Contract renewals
- Customer due diligence
- Cyber insurance applications
- Internal risk reporting
- Board-level assurance
- Partnership and investment discussions
A penetration test does not guarantee that the business will win a contract. It also does not prove that every system is secure.
However, being unable to provide evidence of recent testing may delay the customer’s decision or result in the business being removed from consideration.
Planning ahead makes a significant difference.
If testing reveals a high-risk vulnerability two days before a tender deadline, there may not be enough time to resolve it and complete retesting. Arranging the work in advance gives the business time to address findings properly and provide stronger evidence to prospective customers.
Where appropriate and subject to confidentiality, the business may be able to share an executive summary or confirmation letter rather than the complete technical report.
Penetration testing should be driven by risk
There is no single testing schedule that is suitable for every organisation.
Annual penetration testing can provide a useful baseline and may satisfy contractual or regulatory expectations. However, testing once a year does not automatically provide adequate assurance if the environment changes significantly between assessments.
Additional testing may be appropriate following:
- A major infrastructure change
- A new application release
- A cloud migration
- A merger or acquisition
- A significant security incident
- The introduction of remote access
- A major change to authentication
- The adoption of a new supplier platform
- A new contractual requirement
- Significant business growth
The scope should reflect the systems that matter most to the organisation and the realistic threats they face.
Repeating the same narrow test every year may provide limited value if the organisation’s critical services have moved elsewhere. Equally, testing everything may be unnecessary, expensive and difficult to manage.
A focused assessment of the most important risks is usually more valuable than a broad test with an unclear objective.
What should a penetration test cover?
The appropriate type of testing depends on what the organisation needs to understand.
External infrastructure testing
An external infrastructure penetration test examines systems and services that are accessible from the internet.
This may include:
- Firewalls
- VPN gateways
- Email services
- Remote-access platforms
- Web servers
- Cloud-hosted infrastructure
- Internet-facing administration services
The test looks for opportunities an external attacker could use to gain access, expose information or compromise systems.
Internal infrastructure testing
An internal penetration test considers what could happen after an attacker gains access to the organisation’s network.
The starting point might represent:
- A compromised employee laptop
- A malicious insider
- An attacker connected to an office network
- A compromised remote-access account
- A supplier with limited access
Testing can investigate whether the attacker could escalate privileges, access sensitive information, compromise additional systems or take control of the wider environment.
Web application testing
A web application penetration test assesses websites, customer portals, APIs and other online applications.
It examines both technical weaknesses and business-logic flaws, including whether users can access information or perform actions that should not be available to them.
Testing should take account of different user roles, authentication processes, sensitive workflows and the types of information handled by the application.
Cloud and Microsoft 365 testing
Cloud environments introduce risks relating to identities, permissions, administrative access and configuration.
Testing and security reviews may examine:
- Authentication controls
- Privileged accounts
- External sharing
- Dormant users
- Application permissions
- Access policies
- Cloud resources
- Opportunities for privilege escalation
The precise approach will depend on the cloud platform and the level of access available for the assessment.
An initial scoping conversation can help determine which type of testing is appropriate, which systems should be included and what questions the organisation needs the test to answer.
What should you expect from the test?
A well-scoped penetration test should provide more than a list of scanner results.
It should:
- Identify credible weaknesses
- Explain how they could be exploited
- Demonstrate realistic attack paths
- Describe the potential business impact
- Prioritise findings clearly
- Provide practical remediation advice
- Distinguish confirmed issues from theoretical concerns
- Support retesting after remediation
The final report should be understandable to the people responsible for fixing the findings, while also providing management with a clear view of the risks.
Where several weaknesses can be combined, the report should explain the complete attack path. This helps the business understand why apparently minor issues may become more significant when used together.
Has your risk changed?
If one or more of these five signs apply, it does not necessarily mean your business is insecure.
It does mean that your systems, services or customer expectations may have changed since the last independent assessment.
A penetration test can provide evidence about whether those changes have introduced unnecessary exposure and what should be done to reduce the risk.
The most useful testing is planned around a clear business objective. That might be protecting a new application, assessing remote access, understanding the impact of legacy infrastructure or providing customers with independent assurance.
Has your business grown, launched a new service or started receiving more security questions from customers?
Arrange an initial scoping conversation with Plainsight Security to identify the most appropriate type and scope of penetration testing for your organisation.
Put this into practice.
Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.