Back to glossaryCyber

Penetration testing (pentest)

Security assessment exercise consisting in simulating a real attack to identify vulnerabilities before an attacker can exploit them.

Definition

A penetration test, or pentest, is a security assessment exercise in which mandated experts attempt to compromise an organization's systems by replicating the methods and tools used by real attackers. The objective is to identify exploitable vulnerabilities before a malicious actor does so. Three main modalities are distinguished by the level of information provided to testers. In black-box testing, testers only know the target's name, like an external attacker. In white-box testing, they have full architectural and source-code information. Gray-box testing, the most common intermediate situation, provides partial information. A red team is an advanced form of exercise that simulates not only technical aspects but also human and physical dimensions of a complex attack, seeking to test all of the organization's defensive capabilities including SOC and CIRT. A bug bounty is a continuous program in which security researchers are paid to report vulnerabilities. For cyber underwriting, a recent pentest report is a key document that provides a concrete image of the insured's attack surface, distinct from declarations alone. Insurers may require it for high limits or use it as a premium-reduction criterion.

Example

A pharmaceutical group commissions a red team for a 3-week gray-box exercise. The team accesses a research server containing proprietary formulas by exploiting an unpatched VPN and a service account without MFA. The report leads to urgent remediation and an 8 percent premium reduction at cyber renewal.

Related terms
Also known as

pentest, penetration test, test d'intrusion, red team, bug bounty