How does a penetration test work? Think of it as a fire drill for your IT systems. A tester agrees the rules with you. They study your systems the way an attacker would. They try to break in through whatever weaknesses they find. Then they tell you exactly what worked, what didn’t, and what to fix first. It’s controlled, it’s documented, and nothing happens without your sign-off.
If you’ve never bought one before, that can still sound abstract. Here’s what actually happens, stage by stage, so you know what you’re paying for.
Table of Contents
How does a penetration test work? Stage one: agreeing the scope
Nothing gets tested until the scope is nailed down. Which systems are in play? Which are off limits? What days and hours can testing happen? The NCSC’s own guidance says this needs risk owners, technical staff and the testing team all in the room. The resulting scope document has to cover technical boundaries, test types, timing, resources and compliance needs. Get that precise enough and nobody gets a nasty surprise later.
You’ll also sign written authorisation at this point. That paperwork is what turns “someone trying to break into our systems” from a crime into a legitimate, contracted test.

Stage two: reconnaissance
Once scope is set, the tester starts building a picture of your business from the outside in: domains, exposed services, software versions, even how your staff email addresses are structured. Some of this comes from public information. Some involves lightly probing systems that are in scope, without touching anything that isn’t.
Nothing is broken at this stage. The tester is simply working out where the doors and windows are before deciding which ones to try.
Stage three: finding the weaknesses
Automated tools scan for known issues quickly, but a good tester doesn’t stop there. They dig manually for the things scanners miss: logic flaws, weak configurations specific to your setup, or several small issues on their own. Chained together, those small issues can become serious. This mix of speed and manual judgement is what separates a proper test from an automated scan with a report attached.
Different targets need different tools. A network test relies heavily on scanners and manual configuration checks. A web application test adds tools for probing the inputs a normal visitor would never touch, such as login forms and file uploads.
Stage four: exploitation
This is the part most people imagine when they hear “penetration test”. The tester actually attempts to use the weaknesses found, carefully and under agreed rules, to prove they’re real rather than theoretical. A scan might say a door could be unlocked. Exploitation is where someone actually tries the handle, so you know for certain rather than guessing.
A skilled tester also knows when to stop. If pushing further would risk crashing a live system, they’ll document the danger instead of causing it.
Stage five: working out the damage
Breaking in is rarely where a real attacker would stop, so testers keep going too. Could they reach other systems from here? Grab higher-level access? Get to sensitive data? This stage is often what makes a report land with people outside IT, because it shows business impact, not just a technical flaw with a score attached.
Stage six: the report, and the retest
Everything gets written up clearly: what was tried, what worked, how serious each issue is, and what your team should do about it, in order. A report that’s just a wall of scanner output with no priorities isn’t worth much, however long it is. It’s worth reading up on why a well-written penetration testing report matters before you judge one you’ve been handed.
Once you’ve fixed the issues, book a retest. Skipping it is one of the most common reasons a business pays for a test and fixes what it thinks is the problem. A year later, the same weakness is often still sitting open.
The standards behind the process
Different testing firms may quote different frameworks, but they’re usually describing the same six stages above. OWASP’s testing guide points to the Penetration Testing Execution Standard, which splits the work into seven phases. NIST’s SP 800-115 condenses it into four: planning, discovery, attack and reporting. The labels differ. The questions being answered don’t.
Signs you’re getting a rushed test
Not every test that runs through these six stages does so properly. A few warning signs are worth knowing before you sign a contract. If a supplier can’t explain what happens during scoping beyond “we’ll agree a start date”, that’s a gap. If the report arrives as a raw list of scanner findings with no ranking by real risk, the analysis and exploitation stages likely got skipped. And if nobody mentions a retest at all, assume one isn’t included, because it usually needs asking for.
None of these signs mean fraud. More often they mean a supplier is running an automated scan with a human sign-off, rather than the full process described above. Both have a place, but they aren’t the same product, and they shouldn’t cost the same either.
What to ask before you commission one
A few direct questions tell you a lot about a supplier before you sign anything. Does the quote include a retest, or is that extra? Will they call you immediately if they find something critical, rather than waiting for the final report? Can they explain what happens at each of the six stages above, in their own words? A supplier who answers clearly is usually one who actually runs this process. One who can’t is often selling a scan dressed up as a test.
Getting a properly scoped test done
That’s how a penetration test works from start to finish, and it’s the exact process we run end to end, retest included, on our penetration testing engagements. Aardwolf Security is a UK penetration-testing firm. If you’d like a straightforward conversation about scope before you commit to anything, you’re welcome to get in touch.
Frequently asked questions
How long does a penetration test take?
It varies with scope. A single application might need only a few days of active testing. A full network and application estate can take several weeks once scoping and reporting are added on either side.
Is penetration testing legal?
Yes, provided it’s authorised. That’s exactly why the scoping stage exists: to produce written permission covering which systems and techniques are allowed. Without it, the same activity is simply unauthorised access.
What’s the difference between a penetration test and a vulnerability scan?
A scan lists known weaknesses and stops there. A penetration test goes further, with someone actually trying to exploit those weaknesses and see how far they lead. That’s exactly what stages four and five above cover; our guide on penetration testing vs vulnerability scanning goes into the difference in more depth.
Who should run the test?
An independent tester, not your own IT team, since fresh eyes catch what day-to-day familiarity tends to miss. For UK government-related systems, the NCSC recommends using testers accredited under its CHECK scheme.
What happens once we get the report?
Work through the findings in priority order, fix what you can, then book a retest to confirm the fixes hold. A test that stops at the report only proves what was wrong on the day it ran, not what’s wrong now.
Does passing a penetration test mean we’re safe now?
No. It means the systems in scope had no exploitable weaknesses that this tester found on that particular day. New flaws get disclosed all the time, and your own systems change too, through updates, new staff and new software. That’s why the frameworks behind this process treat testing as something you repeat on a schedule, not a one-off certificate to file away.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.