A penetration test is an authorized, simulated attack on your own systems, run by people whose job is to get in the way a criminal would and then hand you the map. It is the difference between believing your defenses work and having watched somebody try to break them.
This page answers the questions businesses actually ask before they buy one: what the stages are, what the types mean, how a test differs from a scan, what you get at the end, how often to run one, and what moves the price. If you already know all that and just want a test scoped, our penetration testing service page is the shorter road.
What is meant by penetration testing is straightforward: it is an authorized, simulated cyberattack on your own systems, run to find and prove real weaknesses before a criminal finds them. That is the whole definition, and ethical hacking is the same activity under a friendlier name.
Basic penetration testing, the kind most businesses start with, is simply the external network flavor of exactly this. The two most common vulnerabilities a test turns up are unpatched or misconfigured internet-facing services and credentials that work in more places than anyone intended. Neither is exotic, and both are how most real breaches actually start.
A professional penetration test runs in seven stages, and the first and last matter as much as the hacking in the middle.
If a proposal you are reading does not describe stage one or stage seven, you are being sold a scan with a nicer cover page.
The three types describe how much the tester is told before they start, and that single variable changes what the test can find and what it costs.
Cutting across all three is where the test is launched from. An external penetration test attacks your internet-facing perimeter the way a stranger would. An internal penetration test starts from inside the network and answers a different and increasingly relevant question: what happens after somebody clicks the wrong link, or after a contractor plugs into your network.
Organizations get the most value from the white box internal test, because that is the scenario modern ransomware actually follows, and it comprehensively includes searching for black box and grey box vulnerabilities.
Anything with an attack surface can be tested, and the scope you pick decides which questions the test is able to answer.
Third-party testing simply means the work is done by somebody other than the team that built and runs the systems, which is the point: you cannot meaningfully grade your own homework.
A scan finds known weaknesses automatically; a test puts a human using AI against them. Said plainly, no hedging. A vulnerability assessment (VA) is the scanning half; a penetration test (PT) is the proving half.
That human layer is also where the job has changed most. Testers now use automation and AI to cover ground faster and to try combinations that would have been impractical by hand, which means a good test today reaches further than the same budget bought three years ago. The scan is still the floor. The test is the proof.
Both belong in a serious security program, which is why our own penetration test service pairs them rather than treating them as alternatives.
A penetration test is legal because you authorize it in writing, and that same document is what keeps it safe.
A real penetration test report is a remediation plan with evidence attached, not a vulnerability list with a logo on it.
The timeline of a penetration test is shorter than most people expect. Most engagements run one to three weeks end to end, depending on scope, and the report lands within a week or two of testing finishing. In our experience the findings fall into two buckets. The first is projects, the ones already on your list that stalled on budget or on needing a specialist. The second is the mundane work: training people, turning on verbose logging, and turning all that telemetry into alerts somebody actually reads. Knowing which bucket each finding sits in is what makes the report usable.
Annually is the working baseline, and any material change to your environment resets the clock. How regular penetration testing benefits a company is simple: each test is only true on the day it ran, so a cadence is what turns a snapshot into a trend you can manage.
If a compliance framework applies to you, it will usually set the interval for you, which is the subject of the next section.
Several do, and where a framework applies it usually decides your schedule for you.
If you sell to the Department of Defense or sit anywhere in a defense supply chain, testing sits inside a much larger set of obligations. Our CMMC compliance page covers what that involves, and CMMC Demystified explains the framework itself.
If you are in a regulated supply chain
There is no single price, because a penetration test is priced on scope and skill rather than on a per-seat rate, and the scope is set by you.
At Pegasus Technologies, a full penetration test covering internal and external across all three types runs $3,600 to $5,400 for a single site, and that includes one retest within the year so you can prove your fixes actually worked. Additional sites, or networks above 250 devices, cost more.
Getting started is less involved than most people expect. To test your perimeter, all we need is your public IP range, and it tends to be eye-opening to see exactly what a criminal can see. If you want to know what happens when somebody who means no harm plugs into your internal network, we can show you that too.
A penetration test is not a purchase that ends in a certificate. It ends in a list of things to do, in priority order, with evidence for each one. That list is the point.
If you want to know where you actually stand, talk to the Pegasus team or call 610-444-8256. We will scope a test honestly, tell you if a scan is all you need, and hand you a plan you can execute with us or without us.