---
title: What is Penetration Testing?
description: A penetration test is a simulated cyber attack against your nonmalicious computer system to check for exploitable vulnerabilities. Learn how it works and..
image: https://www.mitnicksecurity.com/hubfs/what-is-penetration-testing-hero-image.jpeg
---

# What is Penetration Testing?

[Penetration Testing](https://www.mitnicksecurity.com/blog/tag/penetration-testing)

[ Mitnick Security| ](https://www.mitnicksecurity.com/blog/author/mitnick-security)  10.02.2020| 3 MIN READ TIME

A penetration test is a simulated cyber attack against your nonmalicious computer system to check for exploitable vulnerabilities. It’s a series of targeted nonmalicious attacks, intended to breach your cybersecurity defenses. The difference between a pentest and a real attack, however, is that penetration tests are conducted by ethical security professionals, who keep any extracted data private and ultimately help you improve your security posture. 

We simulate an external attacker attempting to exploit your internet-facing networks and applications to help you identify exploitable vulnerabilities and weaknesses in your perimeter that leave you exposed.

## Penetration Testing vs. Vulnerability Assessments

The main difference between a penetration test and vulnerability assessment is that while both start with an initial scan and investigation of identified vulnerabilities, attack vectors such as [social engineering](https://www.mitnicksecurity.com/blog/social-engineering-attacks), external/ internal network services, web application, etc. are not performed during a vulnerability assessment.

Think of vulnerability assessments and penetration tests as equally important investments in a holistic cyber security initiative. A pentest, however, takes longer and is a more extensive investigation. 

To learn more about what sets them apart, read our blog [*Penetration Testing vs. Vulnerability Assessments: The Key Differences.*](https://www.mitnicksecurity.com/blog/penetration-testing-vs-vulnerability-assessments)

## The 6 Types of Pentests

When a company says they’ll perform a pentest, it’s important to find out what kind of penetration test they’re offering.

**There are six core types:**

1. External Network
2. Internal Network
3. Social Engineering
4. Physical
5. Wireless
6. Web/Mobile Application

If a bad actor finds one shut door, it’s not to say they can’t find another that’s open. With this in mind, a savvy cyber security team should pursue all of these testing vectors, careful to take a rounded approach. This “combination of attack vectors” approach is often referred to as Red Teaming.

Learn more about the [*6 Types of Pentesting*](https://www.mitnicksecurity.com/blog/understanding-the-6-main-types-of-penetration-testing) before screening any companies for the job.

## The 4 Phases of Pentests

No matter the type of penetration test, there are usually four phases, all which deserve equal attention:

1. Planning
2. Pre-Attack
3. Attack
4. Post-Attack

While it’s easy to assume performing the attacks is all that matters, the success of any compromise often depends on what happens *before *and *after *the actual exploit. 

Social engineering attacks often work because the hacker builds a relationship and trust with the victim before planting the bait, meaning a lot of strategizing and slow-nurturing occurs before the malware-infected link is sent or the bad actor asks the recipient to perform a task.

What happens post-attack matters just as much. According to M-Trends, the median number of days [an adversary will sit inside a network undetected is an incredible 146 days](https://www.mitnicksecurity.com/blog/what-is-attack-and-how-can-it-protect-your-business-from-cyber-threats). What could a hacker find out about your company or do with 146 days of access to your internal network?

Read more about the [*4 Phases of Penetration Testing*](https://www.mitnicksecurity.com/blog/the-4-phases-of-penetration-testing) here.

The Pentesting Report

Once the cybersecurity professionals breach your systems, they’ll compile their findings into a comprehensive report. This report will breakdown what happened throughout the attack and offer recommendations for mitigating the risks. It often includes an executive summary as well, translating tech talk into an easily understood language for your C-Suite.

[Explore what’s included in a pentesting report here. ](https://www.mitnicksecurity.com/blog/whats-included-in-a-penetration-test-report)

Beyond the Compliance Checkbox

There are many reasons why a professional pentest is a wise investment beyond compliance regulations. Discover [why penetration is more important than ever in 2020](https://www.mitnicksecurity.com/blog/why-penetration-testing-is-more-important-than-ever-in-2020).

Then, read through these [*7 Real-World Findings from Penetration Tests*](https://www.mitnicksecurity.com/blog/lessons-from-penetration-testing) to start making changes to security. Continue learning by [downloading our free 5-½ Easy Steps to Avoid Cyber Attacks ebook](https://www.mitnicksecurity.com/lp-easy-steps-to-avoid-cyber-threats).

[![New call-to-action](https://no-cache.hubspot.com/cta/default/3875471/7f9b1de1-cf7c-4700-8892-cdf9402b32cf.png)](https://cta-redirect.hubspot.com/cta/redirect/3875471/7f9b1de1-cf7c-4700-8892-cdf9402b32cf)

# Related Resources

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/included-in-pentesting-report.jpeg?width=350&name=included-in-pentesting-report.jpeg)

by Mitnick Security  | 06.30.2026  | 8 min

#### What Does a Pentest Report Look Like? Inside the Results

If your last pentest report was a spreadsheet of CVE numbers with color-coded severity ratings, here is an uncomfortable truth: you did not get a penetration test. You got a vulnerability scan with a ...

 Continue Reading

Global Ghost Team, Penetration Testing 

](https://www.mitnicksecurity.com/blog/penetration-test-report)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Mitnick-Security-071-Enhanced-NR-Copy1.jpg?width=350&name=Mitnick-Security-071-Enhanced-NR-Copy1.jpg)

by Mitnick Security  | 06.08.2026  | 8 min

#### Choosing a Pentesting Company That Thinks Like an Adversary

5 Questions to Vet Any Penetration Testing Company Finding a pentesting partner that can produce a deep dive pentest is harder than knowing what one should look like. When evaluating vendors, seasoned...

 Continue Reading

Penetration Testing 

](https://www.mitnicksecurity.com/blog/best-penetration-testing-company)

[![](https://www.mitnicksecurity.com/hs-fs/hubfs/Person%20reading%20book.jpeg?width=350&name=Person%20reading%20book.jpeg)

by Mitnick Security  | 05.11.2026  | 5 min

#### 4 Essential Cybersecurity Books to Harden Your Mindset (and Your Network)

Offense is the best defense. If you want to stop a hacker, you have to read like one.

 Continue Reading

Cyber Security 

](https://www.mitnicksecurity.com/blog/best-cybersecurity-books)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Mitnick Security",
    "url" : "https://www.mitnicksecurity.com/blog/author/mitnick-security"
  },
  "dateModified" : "2020-10-02T16:49:29.406Z",
  "datePublished" : "2020-10-02T16:49:29.000Z",
  "headline" : "What is Penetration Testing?",
  "image" : [ "https://www.mitnicksecurity.com/hubfs/what-is-penetration-testing-hero-image.jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.mitnicksecurity.com/blog/what-is-penetration-testing",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.mitnicksecurity.com/hubfs/Mitnick-Security-Logo-White-H.png"
    },
    "name" : "Mitnick Security Consulting, LLC"
  }
}
```