How a penetration test engagement actually works
If you've never bought a penetration test, the process can feel opaque. It shouldn't. A good engagement is a disciplined, predictable loop — and knowing the phases helps you judge whether you're getting real testing or an automated scan with a logo on it.
1. Scoping
Everything starts with scope. You and the testing team agree what's in bounds (which apps, APIs, ranges, or people), what's explicitly out, the rules of engagement, and the outcomes that matter to you. This is also where timing, test accounts, and a safe contact path for anything urgent get settled.
A vendor that quotes a price before understanding your environment is guessing. Scoping first is what makes a fixed, honest quote possible.
2. Testing
This is the work. Manual-led testing means a human is reasoning about your system — abusing business logic, chaining minor issues into real impact, and finding the things automated tools structurally cannot. Tools still play a role for coverage and speed, but they assist the tester rather than replace them.
The difference shows up in the findings. A scan reports that a library is outdated. A tester demonstrates that the outdated library, combined with a permissive CORS policy and a predictable token, lets them read another user's data.
3. Reporting
A report should serve two audiences at once: engineers who need exact reproduction steps and a fix, and leadership who need to understand business risk without a security degree. Each finding should carry a severity, evidence, and clear remediation guidance — not just a CVSS number.
4. Re-test
The engagement isn't done when the report lands. After you remediate, the team re-tests to confirm each fix actually holds and didn't quietly introduce a new gap. A test without a re-test leaves you trusting that the fix worked — re-testing proves it.
Red flags to watch for
- A quote with no scoping conversation first
- Reports that are raw scanner output with no manual validation
- No re-test included, or it costs extra as a separate engagement
- Findings with no reproduction steps or remediation guidance
Want this applied to your stack?
Every engagement starts with a no-obligation conversation about what you run and what worries you — the scoping is on us.
Talk to our team