Penetration testingSecurity auditSMEs

Penetration testing: what it really reveals about your security

A penetration test is not just a list of CVEs. It is a simulated real-world attack, with a report showing exactly how an attacker gets in, how far they can go and what they can take. Here is what that looks like in practice.

Hakim Djelili12 min read

Most business leaders who commission a penetration test do not really know what they will receive. They expect a vulnerability scan with a security score. What they get is a document showing, with screenshots as evidence, how an attacker could have accessed their customer data, bypassed authentication or taken their application offline.

This guide explains what a penetration test is, what it actually uncovers and how to use it to fix what matters.

Definition

What a penetration test actually tests

73%

Of web applications tested

Contain at least one critical or high-severity vulnerability

3 hours

Median time to initial access

On an application with no WAF or rate limiting

80%

Of critical vulnerabilities

Come from configuration errors, not zero-days

An automated vulnerability scan lists potential weaknesses. It does not verify whether they can actually be exploited in your environment. A penetration test goes further: the tester actively tries to exploit what they find, documents every step and shows you how far they can go.

The distinction matters. A CVE rated 9.8 may be impossible to exploit on your infrastructure because of another control. Conversely, three vulnerabilities rated 4 may be chained together to gain access to your database. Only a penetration test reveals these attack chains.

Methodology

Black box, grey box, white box: choosing the right level

Black box

No information

  • The tester knows only the URL or domain name
  • Simulates an external attacker with no prior access
  • Also tests your detection capabilities
  • Takes longer and therefore costs more
  • Recommended for assessing your internet exposure

Grey box

Standard user access

  • The tester has a non-privileged account
  • Simulates a malicious employee or compromised account
  • Offers the best coverage-to-cost ratio
  • Recommended for most SMEs and SaaS applications
  • Reveals authorisation and segregation weaknesses

White-box testing adds access to the source code and complete architecture. It is useful for a code audit or certification preparation, but not for simulating a realistic attack.

For an SME commissioning its first penetration test, grey box is almost always the right choice. It covers what matters most: weaknesses that become accessible after a successful phishing attack or credential leak.

Process

The 5 phases of a penetration test

  1. Phase 1

    Scoping and authorisation

    Define the scope, testing hours, excluded systems and emergency contacts. Sign a letter of authorisation. Without this document, the penetration test is illegal.

  2. Phase 2

    Reconnaissance

    Map exposed assets: subdomains, open ports, technologies in use and public information (OSINT). The tester seeks to understand the architecture before attacking.

  3. Phase 3

    Vulnerability identification

    Combine automated scans with manual analysis. The tester looks for known vulnerabilities, configuration errors and unprotected entry points.

  4. Phase 4

    Exploitation

    Attempt to exploit the identified vulnerabilities. Every access gained is documented with screenshots. The tester assesses how far they can go: privilege escalation, lateral movement and exfiltration.

  5. Phase 5

    Report and debrief

    Produce a structured report with an executive summary, technical details for each vulnerability, evidence of exploitation and prioritised recommendations. Follow up with an oral debrief for the team.

Anonymised real-world case

What we actually find: inside a B2B SaaS penetration test

Here is what Cyber Expert found during a recent penetration test of a B2B sales management SaaS application. Names, domains and identifiable technical data have been removed. The findings are real.

Context: an internet-facing web application used to manage customers and contracts by a 40-person team. Scope: a black-box phase (external attacker), followed by a grey-box phase (standard user account).

Black-box phase: what an external attacker sees

The tester has only the application's URL. Within 2 hours of reconnaissance:

Grey-box phase: what a compromised account enables

The tester now has standard user access. What they find in 4 hours:

What worked well. Account segregation was robust: no data leaked from one profile to another. No exploitable SQL injection was found despite varied payloads. The authentication mechanism resisted cookie and token manipulation. These were sound foundations weakened by gaps in back-end validation.

The deliverable

What a good penetration test report contains

A good penetration test report is not an unreadable 80-page PDF. It is a two-part document: an executive summary for leadership and technical detail for the teams.

  • Executive summary: overall risk rating, 3 to 5 priority findings and a budget recommendation. Readable by a non-technical leader in 10 minutes.
  • Scope and methodology: what was tested, how and with which tools. This makes clear what was not covered.
  • Details of each vulnerability: description, evidence of exploitation (screenshot), severity rating, concrete business impact and remediation recommendation.
  • Prioritised remediation plan: critical (fix within 7 days), high (fix within a month), medium (schedule), low (continuous improvement).
  • Oral debrief included: reading a report does not replace a question-and-answer session with the penetration tester. Insist that it is included.

Choosing a provider

What sets a good penetration testing provider apart

There are several hundred penetration testing providers in France. These are the criteria that genuinely matter:

  • PASSI certification (ANSSI): the French benchmark for security audit providers. It guarantees a defined methodology, verified expertise and professional ethics.
  • Individual tester certifications: OSCP (Offensive Security), CEH (EC-Council), GPEN (GIAC). Ask who will conduct the test, not just who signs the report.
  • References for a scope similar to yours: testing a SaaS web application is not the same exercise as testing Active Directory infrastructure.
  • A real anonymised penetration test report: a reputable provider can show you a sample report. If no one can provide one, that is a bad sign.
  • Responsiveness to critical findings: ask what happens if a critical vulnerability is discovered during the engagement. You must be alerted immediately.

Budget

How much penetration testing costs in 2026

€3,000

Simple web application

Limited scope, 3 to 5 days, grey box

€8,000

B2B SaaS application

Black box + grey box, API included, 7 to 10 days

€15,000

Complete infrastructure

Internal network, Active Directory, applications, 15 days

These ranges are indicative. The real cost drivers are the size of the scope and the length of the test. A provider that gives you a fixed price without analysing your scope is applying a generic package, not conducting a serious assessment.

When comparing providers, look at the number of days included, whether retesting and an oral debrief are covered, and whether the report is delivered in English with a clear executive summary.

Want to know what a penetration test would reveal about your application or infrastructure? Request a free assessment: 30 minutes to define the scope, estimate the budget and identify the most urgent risks.

Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call