What Happens During a Penetration Test? A Step-by-Step Overview
If you consider yourself to be a complete newcomer to the idea of penetration testing, don’t panic – it’s a complicated field, but understanding why it’s important and what happens during a penetration test are arguably two of the most important things you can wrap your head around.
Penetration testing is the process of testing a computer system for its weak points. As we know, objects are only ever as strong as their weakest points, and any vulnerabilities in your company’s infrastructure are all too easily exploited by bad actors – rendering any strong points effectively null.
Think of it like a stress test. If your computer system were a physical item, a pentest is the equivalent of roughly handling it – maybe dropping it a few times – or getting someone strong to try to crack it open.
But enough with the metaphors. Here’s what actually happens.
-
Data Gathering
In order to think like a potential or would-be hacker, you’ve got to act like a potential hacker, which means starting at the very beginning: figuring things out from the outside, gathering intel and information on the company and its systems, looking for any sign of a weak spot.
Think of a burglar staking out a house for a few weeks, figuring out the comings and goings of its occupants – noting patterns, observing windows that might be left on the latch or periods when the garage offers an entrance into the house.
-
Getting in
It sounds so simple, and sometimes it is – sometimes it takes a more nuanced approach – but a good pentest will exhaust a huge range of options in trying to identify those points of entry into your private systems.
Sometimes, this involves brute force attack methods – in other words, simply trying potential passwords through cryptography until the right one clicks. Similarly, they may try human vulnerabilities by sending phishing emails to employees in an attempt to physically take the information from them.
Port scanners, SQL injections, web proxy servers and network ‘sniffers’ are some of the other tools utilised to obtain access to a system.
-
Reporting
Following the test itself, it’s time for the pentesting team to write a comprehensive report on the system’s vulnerabilities. While this used to take considerable time, cybersecurity companies and internal teams are utilising pentest tooling from Cyyver to make the process far more efficient.
This part can be a little unnerving, since it effectively tells you which of your doors you left wide open to criminals, but it’s part of the process.
-
Remediation and Retesting
With the information from the report, it’s time to make any necessary changes to the state of your systems and, eventually, retest following the same methodologies to see if you are watertight against hackers.
It’s important to remember that, even if you’re given the all clear following the retesting phase, the process isn’t over. Most companies will get a pentest report generated at least once a year, since the cybersecurity landscape is constantly changing. What worked before may not work any longer, so don’t get complacent about your security.