Home › Resources › Penetration testing › Preparing for a penetration test

Preparing for a penetration test

Most delays and underwhelming results come down to preparation: fuzzy scope, access that was never set up, or stakeholders who learned about the test when something broke. An hour of preparation buys days of better testing.

Why it matters

You are paying for tester time. Every hour a consultant spends waiting on credentials or clarifying scope is an hour not spent finding what an attacker would find.

The preparation checklist

  • Put the scope in writing: exact systems, URLs and address ranges in, and anything specifically out
  • Name a contact who can answer questions quickly and act if something needs attention mid-test
  • Have access ready before day one: accounts for each role, VPN access, allowlisting where agreed
  • Brief the people who need to know: your IT team or provider, and whoever watches the monitoring
  • Agree in advance how urgent critical findings will be raised, and with whom
  • Snapshot or back up fragile systems if testing production cannot be avoided

Should everyone be told?

For most tests, yes: the point is to find weaknesses, not to catch your staff out. The exception is a red team exercise or phishing campaign, where a small trusted circle approves the work and everyone else responds as they would to the real thing. Your provider should help you decide who sits inside that circle.

Where Intelligence Group fits

Intelligence Group tests networks, applications, wireless and people across New Zealand and Australia, evidences every finding and retests once you have fixed it. See what we test or request a quote.