Precursor Security
Intelligence Library
Article

What Is Penetration Testing? A Complete UK Guide (2026)

7 July 2026
·
8 min read
·Precursor Security

What Is Penetration Testing?

Penetration testing (or pen testing) is a controlled cyber attack against your own systems, carried out by an ethical hacker to find and safely exploit security weaknesses before a real attacker does. The tester thinks and acts like an adversary, then reports exactly what they could reach, how, and how to fix it.

Automated scanners tell you where a door might be unlocked. A penetration test proves whether someone can actually walk through it, get into the building, and reach the safe. That difference, between a theoretical weakness and a demonstrated, exploitable path, is the whole point of a pen test.

This guide explains what penetration testing is, what a penetration tester actually does, the main types, how a test works step by step, how it differs from vulnerability scanning, and what it costs in the UK.

What Does a Penetration Tester Do?

A penetration tester (also called an ethical hacker) is a security professional paid to break into systems with the owner's permission. Their job is to simulate a real attacker using the same tools and techniques, but to document findings and help fix them rather than cause harm.

In practice a penetration tester will:

  • Reconnaissance: gather information about the target, from public sources (OSINT), exposed services, and the application itself.
  • Find weaknesses: identify misconfigurations, missing patches, weak authentication, and logic flaws.
  • Exploit them: safely prove a weakness is real by chaining it into actual access, privilege escalation, or data exposure.
  • Report: write up each finding with a severity rating, business impact, evidence, and clear remediation steps.

The exploitation step is what separates a real pen test from a scan. Anyone can run a tool that lists potential issues. A tester demonstrates which of those issues an attacker could actually use, and how far they could get.

How Does Penetration Testing Work?

Most professional penetration tests follow a recognised methodology (such as PTES, OWASP, or the NCSC and CREST frameworks) and move through the same phases:

  1. Scoping: you and the provider agree what is tested, the rules of engagement, and the goals. This defines the boundaries so testing is safe and legal.
  2. Reconnaissance and enumeration: the tester maps the attack surface, discovering hosts, services, endpoints, and users.
  3. Vulnerability analysis: potential weaknesses are identified across the in-scope systems.
  4. Exploitation: the tester attempts to exploit those weaknesses to gain access, escalate privileges, and move laterally, exactly as an attacker would.
  5. Post-exploitation: they assess how much damage is possible from the access gained, such as reaching sensitive data or domain administrator rights.
  6. Reporting: findings are documented with severity, evidence, business impact, and prioritised remediation guidance.
  7. Retest: after you fix the issues, the tester verifies the fixes actually worked.

A good report is written for two audiences at once: an executive summary the board can act on, and technical detail your engineers can remediate against.

What Are the Types of Penetration Testing?

"Penetration testing" is an umbrella term. Which test you need depends on what you are trying to protect:

TypeWhat it tests
Web application penetration testingWebsites, portals, and SaaS apps: injection, broken access control, business logic flaws, OWASP Top 10
External network penetration testingYour internet-facing perimeter, as an outside attacker would see it
Internal network penetration testingAn attacker already inside: Active Directory, lateral movement, privilege escalation
Cloud penetration testingAWS, Azure, GCP, and Microsoft 365 configuration and identity
Mobile application penetration testingiOS and Android apps: data storage, traffic, platform-specific flaws
API security testingAuthentication, authorisation, and data exposure in your APIs

Most organisations start with the surface most likely to be attacked, usually a web application or the external network, and expand from there.

Penetration Testing vs Vulnerability Scanning

This is the most common point of confusion, and it matters commercially because the two are priced very differently.

Penetration testVulnerability scan
Who runs itA human ethical hackerAn automated tool
What it doesFinds and exploits weaknessesLists potential weaknesses
Finds business logic flawsYesNo
False positivesManually verified outCommon
OutputProven attack paths, prioritised by real riskA raw list of possible issues
FrequencyPoint-in-time (often annual) or continuousContinuous / on demand

A vulnerability scan is a useful, low-cost hygiene tool you run often. A penetration test is a deeper, human-led assessment that proves what an attacker could actually achieve. They complement each other. If a provider sells you an automated scan as a "penetration test", that is a red flag. See our fuller breakdown of penetration testing vs vulnerability scanning.

Black Box, White Box, and Grey Box Testing

These terms describe how much information the tester is given up front:

  • Black box: the tester starts with no inside knowledge, simulating an external attacker. Realistic, but slower.
  • White box: the tester is given full access, source code, and documentation. Most thorough coverage for the time.
  • Grey box: a middle ground, for example a standard user account. Usually the best value, reflecting a realistic "credentialed attacker" scenario.

Grey box is the most common choice for web application and internal testing because it balances realism against how much of the attack surface gets covered in the testing window.

What Methodologies Do Penetration Testers Use?

Credible testing follows an established methodology rather than an ad-hoc poke around. The main ones are:

  • OWASP (Web Security Testing Guide) for web applications.
  • PTES (Penetration Testing Execution Standard) for engagement structure.
  • NIST SP 800-115 for technical assessment guidance.
  • MITRE ATT&CK for mapping real adversary tactics and techniques.
  • CREST and NCSC CHECK for UK accreditation and quality assurance.

In the UK, CREST accreditation is the benchmark that matters most: it is required for government, NHS, and most regulated-sector contracts, and it independently validates the provider's people, process, and methodology.

How Much Does Penetration Testing Cost?

UK penetration testing is typically priced per consultant day, at roughly £1,000 to £1,500 per day. Typical engagement costs:

  • Web application or external network test: £3,750 to £6,250 (3 to 5 days).
  • Internal network test: £6,250 to £10,000+ (5 to 8 days).
  • Full security assessment: £12,500 to £25,000+ (10 to 20 days).

Day rates far below £500 usually indicate an automated scan rather than manual testing. For a full breakdown by test type and what drives the price, see our penetration testing cost guide.

Do You Need a Penetration Test?

A penetration test is worth commissioning if any of the following apply:

  • A compliance framework or auditor requires one (PCI DSS, ISO 27001, SOC 2, NHS DSPT).
  • Your cyber insurer asks for evidence of independent testing.
  • A customer or prospect has sent you a security questionnaire or requires proof of testing.
  • You have launched a new application, or made major changes to an existing one.
  • You handle sensitive or regulated data and want assurance before an attacker finds the gaps first.

Many organisations test annually as a baseline, and after any significant change to their systems.

How to Choose a Penetration Testing Provider

Not all "penetration testing" is equal. Before you buy, ask:

  • Is it manual testing, or an automated scan dressed up as a pen test? Ask how many days of hands-on testing you are paying for.
  • Are they CREST-accredited? This independently validates the provider and their testers, and is required for many UK contracts.
  • Are the testers UK-based and vetted? This matters for regulated data and response times.
  • Do you get a retest? Fixing findings is the point; a good provider verifies your remediation.
  • Is the report actionable? You want prioritised, business-focused remediation, not a raw scanner dump.

Precursor Security delivers CREST-accredited penetration testing services from £2,500, with fixed pricing, DBS-checked UK testers, and a free retest.

Frequently Asked Questions

What is penetration testing in simple terms? Penetration testing is a controlled, authorised cyber attack on your own systems by an ethical hacker, to find and safely exploit weaknesses before a real attacker does, then report how to fix them.

What is a penetration tester? A penetration tester, or ethical hacker, is a security professional who is paid to break into systems with permission, using real attacker techniques, in order to identify and help fix security weaknesses.

What does "pen testing" mean? "Pen testing" is short for penetration testing. The two terms mean exactly the same thing.

How long does a penetration test take? Most engagements run 3 to 10 days of testing depending on scope, plus a few days for reporting. A single web application is often 3 to 5 days.

Is penetration testing legal? Yes, when it is authorised. A pen test is always carried out with the system owner's written permission and an agreed scope. Testing systems without permission is illegal under the Computer Misuse Act.

How often should you run a penetration test? At least annually, and after any significant change to your systems, such as a new application, major release, or infrastructure change.

Ready to scope a test? See our penetration testing services, the cost guide, or get in touch for a fixed-price quote.

Expert Guidance

Put this guide into practice

Our CREST-accredited penetration testers can validate your configuration, identify gaps, and provide an independent audit report.

The Intelligence Brief

Get the security intelligence brief

Practical UK security guidance, new research, and threat breakdowns, straight to your inbox.

No spam. Unsubscribe any time. Covered by our Privacy Policy.