Every penetration test turns up something new. But after testing networks at many different organizations, we keep running into the same handful of problems, at companies of every size and in every industry. None of them are exotic. Most of them have been sitting in plain sight for years.
Here are six things we find again and again, why they matter, and what to do about each one.
1. A forgotten Windows 10 computer, still plugged in
It’s usually under someone’s desk or in a back closet, powered on and connected to the network, running one legacy application that was never migrated. Nobody thinks of it as a computer anymore. It’s just “the machine that runs the old software.”
Windows 10 reached end of support in October 2025, so unless that machine is enrolled in Microsoft’s paid Extended Security Updates, it no longer gets security patches. Every vulnerability discovered since then stays open, on a device with access to the rest of your network.
What to do: keep a complete inventory of every device on your network, including the ones nobody uses day to day. Move the legacy application to a supported system, or isolate that machine so it can’t reach anything it doesn’t need to.
2. A lookalike domain someone else registered
We regularly find a domain that looks almost exactly like the company’s own, registered by an unknown party. Swap one letter, add a hyphen, change .com to .co, and most people won’t notice. That lookalike can host a fake login page or send phishing emails that appear to come from your company, to your employees, your clients and your vendors.
What to do: watch for new registrations that resemble your domain, consider registering the most obvious variations yourself, and set up email authentication (SPF, DKIM and DMARC) so it’s harder for anyone to send mail that pretends to be you. Train your team to check the full sender address along with the display name.
3. IPv6 turned on and never configured
The IP addresses most people know follow a format called IPv4. The world ran out of IPv4 addresses years ago and began using a newer format, IPv6. For compatibility, most computers now run both at the same time.
The problem is that many IT teams configure and monitor IPv4 carefully and leave IPv6 at its default settings. And most operating systems, Windows included, prefer IPv6 over IPv4 when both are available. That gives an attacker a lane on your network that nobody is watching.
What to do: apply the same firewall rules, monitoring and access controls to IPv6 that you apply to IPv4, or turn IPv6 off on devices and networks that don’t need it.
4. Default passwords on routers, switches and printers
Network equipment ships with a default administrator password, and it’s often printed in the manual and posted online. When it’s never changed, anyone who reaches that device gets full control of it. From there, a compromised printer or switch becomes a launchpad for attacks on the computers around it.
What to do: change the default password on every network device when it’s installed, store the new credentials in a password manager, and include printers, cameras and other “non-computer” devices in your inventory.
5. Firewalls and switches running end-of-life firmware
Firewalls and switches need updates just like computers do, and once a device reaches end of life, the updates stop. The vulnerabilities in old firmware are usually well documented, which makes them easy for attackers to look up and exploit to take control of network access, traffic and data.
What to do: keep firmware current, track the support status of every network device, and budget to replace equipment before it reaches end of life.
6. Administrator passwords on sticky notes
It happens more than anyone wants to admit. Admin credentials written on a sticky note on a monitor, or pinned to a bulletin board in the IT closet. Physical access is part of a thorough test, and a password on paper is a password anyone walking by can use.
What to do: use a password manager for shared and administrator credentials, turn on multifactor authentication for administrator accounts, and make “no passwords on paper” part of your security training.
Why these problems slip past everyday IT
None of these show up on a normal dashboard. A forgotten computer doesn’t generate a help desk ticket, and a lookalike domain doesn’t trigger an alert on your network. They surface when someone deliberately looks for them from an attacker’s point of view, from the internet and from inside your network. That’s the job of a penetration test. Our complete guide to penetration testing walks through how a test works, from scoping to the final report.
Choose a testing partner you trust
A penetration test hands someone a detailed map of every weak spot in your network. That’s exactly what a good test should produce, and it’s exactly why the partner you choose matters. The findings are only useful if the team that delivers them explains them in plain language, helps you fix what they found, and comes back to confirm the fixes worked.
Look for a partner who understands how your business runs, earns your trust before they ever touch your systems, and will still be there when next year’s test comes around. Our Right Fit IT Resource Center walks through how to find an IT partner that fits your business.
What it costs to find them
A full Pegasus penetration test covering internal and external testing typically runs $3,600 to $5,400 for one site, including a retest within the year to confirm the fixes worked. Additional sites, or networks with more than 250 devices, cost more. Learn more about our penetration testing service, or contact us and call 610-444-8256 to find out what’s hiding on your network.