Most business leaders who commission a penetration test do not really know what they will receive. They expect a vulnerability scan with a security score. What they get is a document showing, with screenshots as evidence, how an attacker could have accessed their customer data, bypassed authentication or taken their application offline.
This guide explains what a penetration test is, what it actually uncovers and how to use it to fix what matters.
Definition
What a penetration test actually tests
73%
Of web applications tested
Contain at least one critical or high-severity vulnerability
3 hours
Median time to initial access
On an application with no WAF or rate limiting
80%
Of critical vulnerabilities
Come from configuration errors, not zero-days
An automated vulnerability scan lists potential weaknesses. It does not verify whether they can actually be exploited in your environment. A penetration test goes further: the tester actively tries to exploit what they find, documents every step and shows you how far they can go.
The distinction matters. A CVE rated 9.8 may be impossible to exploit on your infrastructure because of another control. Conversely, three vulnerabilities rated 4 may be chained together to gain access to your database. Only a penetration test reveals these attack chains.
Methodology
Black box, grey box, white box: choosing the right level
Black box
No information
- The tester knows only the URL or domain name
- Simulates an external attacker with no prior access
- Also tests your detection capabilities
- Takes longer and therefore costs more
- Recommended for assessing your internet exposure
Grey box
Standard user access
- The tester has a non-privileged account
- Simulates a malicious employee or compromised account
- Offers the best coverage-to-cost ratio
- Recommended for most SMEs and SaaS applications
- Reveals authorisation and segregation weaknesses
White-box testing adds access to the source code and complete architecture. It is useful for a code audit or certification preparation, but not for simulating a realistic attack.
For an SME commissioning its first penetration test, grey box is almost always the right choice. It covers what matters most: weaknesses that become accessible after a successful phishing attack or credential leak.
Process
The 5 phases of a penetration test
Phase 1
Scoping and authorisation
Define the scope, testing hours, excluded systems and emergency contacts. Sign a letter of authorisation. Without this document, the penetration test is illegal.
Phase 2
Reconnaissance
Map exposed assets: subdomains, open ports, technologies in use and public information (OSINT). The tester seeks to understand the architecture before attacking.
Phase 3
Vulnerability identification
Combine automated scans with manual analysis. The tester looks for known vulnerabilities, configuration errors and unprotected entry points.
Phase 4
Exploitation
Attempt to exploit the identified vulnerabilities. Every access gained is documented with screenshots. The tester assesses how far they can go: privilege escalation, lateral movement and exfiltration.
Phase 5
Report and debrief
Produce a structured report with an executive summary, technical details for each vulnerability, evidence of exploitation and prioritised recommendations. Follow up with an oral debrief for the team.
Anonymised real-world case
What we actually find: inside a B2B SaaS penetration test
Here is what Cyber Expert found during a recent penetration test of a B2B sales management SaaS application. Names, domains and identifiable technical data have been removed. The findings are real.
Context: an internet-facing web application used to manage customers and contracts by a 40-person team. Scope: a black-box phase (external attacker), followed by a grey-box phase (standard user account).
Black-box phase: what an external attacker sees
The tester has only the application's URL. Within 2 hours of reconnaissance:
Grey-box phase: what a compromised account enables
The tester now has standard user access. What they find in 4 hours:
What worked well. Account segregation was robust: no data leaked from one profile to another. No exploitable SQL injection was found despite varied payloads. The authentication mechanism resisted cookie and token manipulation. These were sound foundations weakened by gaps in back-end validation.
The deliverable
What a good penetration test report contains
A good penetration test report is not an unreadable 80-page PDF. It is a two-part document: an executive summary for leadership and technical detail for the teams.
- Executive summary: overall risk rating, 3 to 5 priority findings and a budget recommendation. Readable by a non-technical leader in 10 minutes.
- Scope and methodology: what was tested, how and with which tools. This makes clear what was not covered.
- Details of each vulnerability: description, evidence of exploitation (screenshot), severity rating, concrete business impact and remediation recommendation.
- Prioritised remediation plan: critical (fix within 7 days), high (fix within a month), medium (schedule), low (continuous improvement).
- Oral debrief included: reading a report does not replace a question-and-answer session with the penetration tester. Insist that it is included.
Choosing a provider
What sets a good penetration testing provider apart
There are several hundred penetration testing providers in France. These are the criteria that genuinely matter:
- PASSI certification (ANSSI): the French benchmark for security audit providers. It guarantees a defined methodology, verified expertise and professional ethics.
- Individual tester certifications: OSCP (Offensive Security), CEH (EC-Council), GPEN (GIAC). Ask who will conduct the test, not just who signs the report.
- References for a scope similar to yours: testing a SaaS web application is not the same exercise as testing Active Directory infrastructure.
- A real anonymised penetration test report: a reputable provider can show you a sample report. If no one can provide one, that is a bad sign.
- Responsiveness to critical findings: ask what happens if a critical vulnerability is discovered during the engagement. You must be alerted immediately.
Budget
How much penetration testing costs in 2026
€3,000
Simple web application
Limited scope, 3 to 5 days, grey box
€8,000
B2B SaaS application
Black box + grey box, API included, 7 to 10 days
€15,000
Complete infrastructure
Internal network, Active Directory, applications, 15 days
These ranges are indicative. The real cost drivers are the size of the scope and the length of the test. A provider that gives you a fixed price without analysing your scope is applying a generic package, not conducting a serious assessment.
When comparing providers, look at the number of days included, whether retesting and an oral debrief are covered, and whether the report is delivered in English with a clear executive summary.
Want to know what a penetration test would reveal about your application or infrastructure? Request a free assessment: 30 minutes to define the scope, estimate the budget and identify the most urgent risks.
Let's talk for 30 minutes — no commitment
A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.
Book a call