Services on Heelr

Penetration testing

A penetration test is a controlled, hands-on attempt to find and exploit weaknesses in a defined system, the way an attacker might, so that the organisation understands what could realistically be reached. Companies commission them before a launch, alongside an assurance or compliance programme, in response to a customer requirement, or simply to understand where a particular system stands.

Heelr connects you with penetration testing providers who must meet Heelr's identity and provider verification requirements. You agree the scope, the targets and the price with the provider before any testing begins.

What a penetration test covers

A penetration test covers the specific systems and attack surface agreed in scope, tested manually by a professional rather than only scanned automatically. The scope is agreed before testing starts, and it determines what is examined, how deeply, and what the engagement can and cannot tell you.

For an adversarial, objective-based exercise involving people, process and multiple attack paths rather than exhaustive testing of one defined target, see red teaming. For broader, largely automated identification of known weaknesses across many systems, see vulnerability assessment.

When might you need a penetration test?

A penetration test is usually commissioned when an organisation needs hands-on assurance about a specific system, and the reason varies with the organisation, the system and the requirement involved.

Common situations include:

  • before launching or materially changing an internet-facing product or service
  • when a customer or contract requests independent security testing
  • as part of a wider assurance or compliance programme
  • after significant changes to an application, API or infrastructure
  • when an organisation wants a deeper manual assessment than vulnerability scanning alone provides

There is no universal rule that every company needs a penetration test, or that tests should happen at the same interval everywhere. Need and frequency depend on factors such as system risk, how often the environment changes, customer and contractual requirements, regulatory or compliance context, previous findings, and the nature of the environment itself. Where the underlying question is broader than technical testing of a defined target, a security audit or audit-readiness exercise may be a better fit.

What type of penetration test do I need?

The type of test should reflect the system or attack surface you actually need assessed, rather than a generic package. Most requests fall into one of the areas below, and a provider can advise on what fits the scope you describe.

Web application penetration testing

Hands-on testing of a web application and the functionality it exposes, including authentication, session handling, business logic and other application behaviour reachable within the agreed scope.

API penetration testing

Testing of the interfaces an application exposes, including authentication, authorisation, input handling and the functionality available through the API to different roles or callers.

Network or infrastructure penetration testing

Assessment of internal or external network and infrastructure attack surfaces in scope, such as exposed services, hosts and configuration reachable by an attacker.

Some questions are better answered by an adjacent service. If the question concerns how securely software is designed, built and reviewed rather than a single test, see application security. If it concerns how a cloud environment is configured and architected, see cloud security. A broader adversarial exercise spanning people, process and multiple attack paths is red teaming, which is a different kind of engagement rather than a larger penetration test. And if you mainly need broad, largely automated coverage of known weaknesses, a vulnerability assessment is a related but different activity: scanning identifies known issues at breadth, while a penetration test involves a professional working hands-on within a defined scope.

What should you prepare before requesting a penetration testing quote?

A provider generally needs enough information to understand the proposed scope before they can suggest an approach or a price. Requirements vary between providers, but the following is often useful:

  • what application, API, infrastructure or environment needs testing
  • what is explicitly in scope and out of scope
  • whether the target is production, staging or another environment
  • whether authenticated access or test accounts can be provided
  • the relevant user roles or permission levels
  • the reason for the test, such as internal assurance, a customer request or a contractual requirement
  • any deadline, and what is driving it
  • whether a formal report is required for a customer or third party
  • any important operational or testing constraints

Clearer scope generally makes it easier for providers to propose appropriate work and pricing, though the approach and cost still depend on the provider and what you agree together.

What should you look for in a penetration testing provider?

Once you know roughly what needs testing, the choice of provider is mostly about fit with that scope. Points worth considering:

  • experience with the relevant type of system or technology
  • their proposed testing approach and how they define scope
  • how findings are communicated during and after the engagement
  • report format, and who the report is intended to be read by
  • whether remediation guidance or retesting forms part of the agreed scope
  • relevant credentials or accreditations, where these matter to the requirement you are meeting
  • ability to work within your operational constraints and timelines

Heelr's identity and provider verification requirements are a starting point for your own due diligence, not an assessment of technical expertise or suitability for a particular engagement.

What happens after a penetration test?

Most engagements conclude with the findings documented in a report, though the exact deliverables depend on what you agreed in scope.

A report may include:

  • the vulnerabilities or findings identified
  • severity ratings or prioritisation
  • the affected systems or components
  • evidence supporting each finding
  • remediation guidance
  • an executive or customer-facing summary, where agreed

Responsibility for remediation stays with your organisation unless remediation work is separately included in the scope. Some engagements also include retesting after fixes are made, if that is agreed with the provider.

It is worth being clear about what the result represents. A penetration test reflects the system and the scope that were tested, at the point in time they were tested. It does not certify that a product, company or environment is secure, and a report with few findings is not a guarantee about future security or about how any customer will respond.

A customer has asked us for a penetration test

Customer requests are one of the most common triggers, and they are worth unpacking before commissioning anything. Clarify exactly what the customer requires, confirm which system or product they expect to be tested, and establish whether they need a report or some other form of evidence. Understand any deadline attached to the commercial process, and check whether testing or evidence you already hold may be relevant to what they are asking for. Where new testing is genuinely required, commission it against a scope that matches the request.

Not every request means a new test is automatically necessary. For wider context on security requirements in an enterprise deal, see our guide for startups selling to larger customers.

Common questions

What is the difference between a penetration test and a vulnerability assessment?

A vulnerability assessment is largely automated and lists known weaknesses across many systems. A penetration test is hands-on: a professional works within a defined scope and attempts to exploit weaknesses to show what could be reached. Assessment gives breadth; testing gives depth.

How much does a penetration test cost?

It depends on scope: the number of targets, their complexity, and the depth of testing. On Heelr you agree the scope and price with the provider before work begins. A focused web app test generally costs less than a broad engagement across a whole estate.

How long does a penetration test take?

Most engagements run from a few days to a couple of weeks, plus time for the report. Scope drives the timeline.

How often should a penetration test be carried out?

There is no universal testing interval. Frequency depends on factors such as system risk, major changes, customer or contractual requirements, previous findings and the environment being tested. Some organisations test on a recurring basis, while others commission tests around defined changes or requirements.

Can a penetration test help with SOC 2 or ISO 27001?

It can form part of the evidence supporting a wider security or assurance programme. Neither SOC 2 nor ISO/IEC 27001 should be treated as universally requiring the same penetration testing activity in every case: what is appropriate depends on the scope, the controls in question and how the programme is defined. See SOC 2 preparation and ISO 27001 preparation.

Can we use an existing penetration-test report for a customer?

It depends on what the customer requires: how recent the test is, whether the relevant product or environment was in scope, and what evidence they are willing to accept. Ask the customer what they need before assuming an existing report will or will not be sufficient.

A customer has asked for a penetration test we have not done. What should we do?

Clarify what scope and evidence the customer requires, identify the deadline, and determine which system actually needs testing. If new testing is required, find a provider whose experience suits that scope. Our guide to security requirements in an enterprise deal covers the wider context.

What is the difference between penetration testing and red teaming?

A pen test aims to find as many exploitable weaknesses as possible within a defined scope. A red team exercise is objective-based and adversarial, testing whether a determined attacker could achieve a specific goal, often across people and process, and frequently testing detection and response too.

Need a penetration test?

Heelr can help you find penetration testing providers with experience relevant to your environment and scope. You agree the scope and price with the provider before work begins.

Related