A penetration test, or pentest, is a controlled attack on a company's infrastructure carried out under contract by a team of security specialists. They use the same methods as criminals, but the outcome is a report listing the ways in, not damage. A pentest answers the question "can we be broken into in practice", not "is everything described correctly in the policies".
Key takeaways
These are three different jobs that are often confused. An audit examines how protection is built; a scanner looks for known vulnerabilities in a database; a pentest checks whether those vulnerabilities can be used and how far an attacker can go afterwards.
| Work | Question it answers | How it is done | What you get |
|---|---|---|---|
| Information security audit | Is protection built correctly | Review of settings, access rights, processes and documents | A prioritised list of risks and a plan of work |
| Vulnerability scanning | Are there known vulnerabilities | Automated checks against a database, run regularly without human input | A list of vulnerabilities with severity ratings |
| Penetration test | Can they be exploited and how far | Manual work by a specialist who exploits what was found | Attack scenarios: which entry point was used and which data was reached |
| Red Team | Will the security team notice us | A long covert operation the IT team is not warned about | An assessment of how detection and response actually work |
One does not replace another: an audit may show exemplary policies while a pentest finds a forgotten test server with a default password. What an infrastructure review covers and when it is worth ordering is explained in our article on the IT infrastructure audit.
The type is chosen by which scenario is realistic for the company. There is no point in ordering everything at once: each type takes its own time and its own specialists.
| Type | What it simulates | What is tested | When you need it |
|---|---|---|---|
| External | An attack from the internet with no access inside | Websites, mail, VPN, admin panels — everything exposed to the outside | The baseline: this is how any attacker sees the company |
| Internal | An intruder already inside: an employee or an infected workstation | Network segmentation, account privileges, access to file shares and databases | When the network has many workstations and shared resources |
| Web application | An attack on a website, customer portal or API | Access rights, input handling, file uploads, order and payment logic | Before a product launch and after major updates |
| Social engineering | Emails and calls supposedly from colleagues, a bank or a contractor | How employees react: will they click, enter a password or send money | When people, not technology, are the main risk |
Web application testing relies on the common weaknesses listed in OWASP Top 10:2025: in this edition broken access control ranks first and a new category, software supply chain failures, ranks third. Phishing simulations only pay off together with training — how to build it is covered in our article on security awareness training for employees.
The model defines how much information the team receives before the start, and that determines what can realistically be covered in the allotted time.
If the goal is to see the company through the eyes of a random attacker, black box is the choice. If the goal is to find as many problems as possible before someone else does, white box works better: that is the usual option before launching a new product.
The sequence is described in open methodologies — for example in the NIST SP 800-115 guide to technical security testing — and looks much the same across teams.
The report is the main deliverable and the only thing the company keeps after the work. It shows how thoroughly the testing was done.
The last item is what separates an honest report. A straight "the firewall blocked us here, that system was excluded from the scope" is more useful to you than a smooth conclusion that no critical vulnerabilities were found.
Testing without the system owner's written permission is not a pentest but a crime. The Criminal Code has a dedicated chapter on information technology offences, and within it Article 278-2, "Unauthorised access to computer information".
Important Permission is signed by whoever owns the systems. If the website or servers are rented, the provider's consent is needed separately: from its side scanning and load testing look like an attack and can end in a block.
Government bodies cannot choose a contractor freely. Decree UP-38 of 10 March 2026, which approved the Cybersecurity Strategy for 2026–2030, allows bodies without their own cybersecurity unit to use only those organisations that are included in a dedicated register. The register is maintained by the State Security Service.
Data is a separate question. If the system holds customers' personal data, agree in advance whether the team works on a copy of the database with anonymised records or on the live system, and put that in the contract together with an obligation to destroy every extract after the work.
Preparation strongly affects the result: without it part of the paid time goes into finding out whose server this is and whether it may be touched.
The market is uneven: the word "pentest" covers both a month of manual work and a single scanner run with an automatic report. The difference shows in the contract and in a sample report.
Findings should be turned into a prioritised plan straight away — how to weigh likelihood and impact is covered in our article on information security risks. And the cheapest way to avoid a long report is to build protection in at the IT system design stage.
The price follows the volume of work: how many external addresses and applications are in scope, how many user roles must be covered, which model was chosen and whether retesting is included. Compare it not with the price of a scanner but with the price of an incident.
Syntra Systems does not offer penetration testing as a separate service and does not sell it under another name. We start with an information security audit — from $1,200: we map what needs protecting, check servers, networks, mail, websites and workstations for known vulnerabilities, review access rights and the handling of personal data, and deliver a report where every risk has a likelihood, a consequence and a place in the queue.
If the audit shows there is something to close, the next step is data and access protection from $4,000: roles and two-factor authentication, encryption, protection of mail against spoofing, backups with verified restore, firewall and VPN, incident procedures and staff training. The full scope is on our cybersecurity for business page. The audit report is also useful if you decide to order a pentest from a specialised team: it already describes the systems, the access rights and the known weak spots.
Let’s discuss your project
Tell us what you need, and we will estimate the timeline and cost and suggest a solution.
A scanner compares software versions and settings against a database of known vulnerabilities and returns a list of findings. A pentest starts where the scanner stops: a specialist manually checks whether a vulnerability can be used and shows which data was reached.
After every significant change: a new product launch, an infrastructure move, a major web application update, a change of contractor. The report shows the state as of the testing date, so automated vulnerability scanning runs regularly between pentests to fill the gaps.
The risk is managed by rules. Scope and forbidden actions are fixed before the start, risky checks are agreed separately, critical systems are tested outside business hours. Destructive methods are never used without written approval, and the contract describes how to stop the work immediately.
We don't sell a standalone "pentest" service, under that name or any other. The price is set by the number of addresses and applications, the number of user roles, and how much the team already knows in advance — from a single website address to a network diagram and source code. We start with an information security audit, from $1,200.
A small company is usually better off starting with an information security audit and regular scanning: they cost less and catch most of the common problems. A pentest pays off once the basics are covered and an online service earns money or holds customer data.
The report becomes a plan of work: vulnerabilities are fixed in order of severity, each one gets an owner and a deadline, and then retesting is ordered. A report that simply goes into a folder does not make the company any safer.
In-house it makes sense to run regular vulnerability scanning and keep software updated. Full testing needs separate qualifications and an outside view: your own team checks the system it configured itself and repeats its own blind spots.
Sources