Home › Resources › Penetration testing › What a penetration test actually involves

What a penetration test actually involves

A professional penetration test is a structured engagement with clearly defined stages. Understanding how it unfolds helps you scope it well and get the most from the work.

Why it matters

Knowing the process shows you where your own effort counts (scoping and preparation), what the deliverable should contain, and which questions to ask when something is unclear, so you get the full value of the engagement.

The stages of an engagement

  • Scoping: targets, exclusions, timing and rules of engagement agreed with the provider in writing
  • Reconnaissance: the testers map what is exposed, just as a real attacker would begin
  • Active testing: consultants probe, exploit and chain weaknesses within the agreed rules
  • Reporting: each finding written up with evidence, severity, business impact and a specific fix
  • Debrief: a walkthrough of the results with your technical team and, if you want it, your leadership
  • Retest: once you have remediated, the fixes are verified and the report updated

Could it break something?

The rules of engagement exist to manage exactly that. Destructive techniques are excluded by default, fragile systems are flagged during scoping, and anything genuinely risky happens only with your approval at an agreed time. A critical finding uncovered mid-test is raised straight away through the channel you chose, not held back for the report.

Where Intelligence Group fits

Intelligence Group tests networks, applications, wireless and people across New Zealand and Australia, evidences every finding and retests once you have fixed it. See what we test or request a quote.