Skip to content
ShadowSee
← All articles

Pentesting

What to Expect From Your First Penetration Test

· 2 min read · ShadowSee Team

Commissioning a penetration test for the first time can feel like inviting a stranger to break into your house. It doesn't have to. A well-run engagement is structured, predictable and collaborative. Here is what actually happens, step by step.

1. Scoping: deciding what gets tested

Everything starts with a scoping conversation. Together we identify what's in scope (for example a customer-facing web app, its API and the cloud account behind it), what's out of scope, and what you most want to learn. Good scoping questions include:

  • Which systems hold your most sensitive data or keep the business running?

  • Should testing be black-box (no prior knowledge), grey-box (test accounts provided) or white-box (source code and architecture shared)?

  • Are there compliance drivers, such as PCI-DSS, ISO 27001 or a customer security questionnaire?

  • Are there fragile systems or busy periods we should avoid?

2. Rules of engagement

Before any testing begins, both sides sign off on the rules: testing windows, source IP addresses, emergency contacts, what to do if a critical issue is found, and whether techniques like denial of service or social engineering are allowed. This protects you and gives us clear authorization to test.

3. Testing

Our testers combine automated tooling with manual techniques to map your attack surface and look for weaknesses: broken access control, injection flaws, authentication bypasses, misconfigurations and business-logic abuse. The goal isn't a long list of theoretical issues. It's to prove what an attacker could realistically achieve.

If we find something critical mid-engagement, we don't wait for the final report. We notify your team immediately so you can start fixing it.

4. Reporting

You receive a report with two audiences in mind. The executive summary explains overall risk in business terms. The technical section details each finding with severity, evidence, reproduction steps and specific remediation guidance. We then walk your team through the results so nothing is lost in translation.

5. Remediation and retest

Once your team has applied fixes, we retest the affected findings to confirm they're resolved. That verified result is what you can confidently share with customers, auditors and leadership.

How to prepare

  • Nominate a technical point of contact who can answer questions quickly.

  • Prepare test accounts for each user role if doing grey-box testing.

  • Tell your hosting provider or SOC so alerts aren't mistaken for a real attack.

  • Take backups of anything critical, as good practice.

A first pentest is less about passing or failing and more about establishing a baseline. Knowing where you stand is the first step to getting measurably more secure.

Ready to see what an attacker sees?

Tell us what you're building. We'll scope a test that fits your stack, timeline and budget.