← All terms

Penetration Testing

Penetration testing is an authorized simulated attack that finds exploitable weaknesses — in systems, and increasingly in people and processes.

Penetration testing (pen testing) is an authorized, controlled attack against your own organization, performed to find exploitable weaknesses before a real adversary does. A pen test is scoped and time-boxed — a defined set of systems, applications, facilities, or people, tested within agreed rules of engagement — and it ends in a report: what was tried, what broke, how far the tester got, and what to fix first. It differs from a vulnerability scan, which only lists potential weaknesses, and from a red team engagement, which is broader, goal-driven, and usually run without defenders' knowledge.

How it works

Testers follow the same kill chain as attackers: reconnaissance, gaining access, escalating privileges, and demonstrating impact. The scope determines the flavor — network and infrastructure tests probe exposed services and misconfigurations; application tests attack code and business logic; physical tests attempt entry to buildings and server rooms; and social engineering tests target the workforce itself, using pretexting calls, phishing campaigns, or a dropped USB drive to measure whether people and processes hold. Many compliance frameworks expect regular testing, and mature security programs treat the human-layer findings as seriously as the technical ones — a domain administrator's password captured by one phone call outweighs a dozen medium-severity CVEs.

How to defend against it (and learn from it)

The point of a pen test is the fixing, not the finding. Prioritize remediation by demonstrated impact rather than raw severity scores, retest to confirm the fix, and feed every human-layer result into your awareness program: if the tester's pretext worked on the help desk, that exact scenario belongs in training and rehearsal. Annual tests also leave an eleven-month blind spot — which is why continuous, automated phishing and vishing simulation has become the standing complement to periodic professional testing, and why discussion-based rehearsals like a social engineering tabletop exercise turn findings into practiced response.

Related terms

Red TeamA red team is a group authorized to simulate real attackers against an organization, including social engineering, to test defenses end to end.Blue TeamA blue team is the defensive side of security — the people who detect, respond to and harden against attacks, including social engineering.Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo