Pentesting
What to Expect From Your First Penetration Test
· 2 min read · ShadowSee Team
Commissioning a penetration test for the first time can feel like inviting a stranger to break into your house. It doesn't have to. A well-run engagement is structured, predictable and collaborative. Here is what actually happens, step by step.
1. Scoping: deciding what gets tested
Everything starts with a scoping conversation. Together we identify what's in scope (for example a customer-facing web app, its API and the cloud account behind it), what's out of scope, and what you most want to learn. Good scoping questions include:
Which systems hold your most sensitive data or keep the business running?
Should testing be black-box (no prior knowledge), grey-box (test accounts provided) or white-box (source code and architecture shared)?
Are there compliance drivers, such as PCI-DSS, ISO 27001 or a customer security questionnaire?
Are there fragile systems or busy periods we should avoid?
2. Rules of engagement
Before any testing begins, both sides sign off on the rules: testing windows, source IP addresses, emergency contacts, what to do if a critical issue is found, and whether techniques like denial of service or social engineering are allowed. This protects you and gives us clear authorization to test.
3. Testing
Our testers combine automated tooling with manual techniques to map your attack surface and look for weaknesses: broken access control, injection flaws, authentication bypasses, misconfigurations and business-logic abuse. The goal isn't a long list of theoretical issues. It's to prove what an attacker could realistically achieve.
If we find something critical mid-engagement, we don't wait for the final report. We notify your team immediately so you can start fixing it.
4. Reporting
You receive a report with two audiences in mind. The executive summary explains overall risk in business terms. The technical section details each finding with severity, evidence, reproduction steps and specific remediation guidance. We then walk your team through the results so nothing is lost in translation.
5. Remediation and retest
Once your team has applied fixes, we retest the affected findings to confirm they're resolved. That verified result is what you can confidently share with customers, auditors and leadership.
How to prepare
Nominate a technical point of contact who can answer questions quickly.
Prepare test accounts for each user role if doing grey-box testing.
Tell your hosting provider or SOC so alerts aren't mistaken for a real attack.
Take backups of anything critical, as good practice.
A first pentest is less about passing or failing and more about establishing a baseline. Knowing where you stand is the first step to getting measurably more secure.
