Syntra Systems
Cases Services Products About Blog IT Caravan
+998 70 010 68 44 +7 999 900 22 12
RusEngUzb
A dark funnel of concentric rings with blue and magenta light streaks, an image of searching for a way into a system
Security

Penetration Testing for Business: Types, Stages and Report

By Nikita Zhulin · · 8 min read · updated

A penetration test, or pentest, is a controlled attack on a company's infrastructure carried out under contract by a team of security specialists. They use the same methods as criminals, but the outcome is a report listing the ways in, not damage. A pentest answers the question "can we be broken into in practice", not "is everything described correctly in the policies".

Key takeaways

  • A penetration test is a controlled attack under contract: it shows whether vulnerabilities can be exploited in practice and how far an attacker gets.
  • A security audit, vulnerability scanning and a penetration test answer different questions and do not replace one another.
  • Without the system owner's written permission such testing falls under Article 278-2 of the Criminal Code of Uzbekistan.
  • The value of a report lies in reproduction steps, complete attack scenarios and an honest list of what could not be tested.
  • Syntra Systems does not sell penetration testing as a separate service: we run a security audit from $1,200 and build data and access protection from $4,000.

Pentest, security audit and vulnerability scanning: the difference

These are three different jobs that are often confused. An audit examines how protection is built; a scanner looks for known vulnerabilities in a database; a pentest checks whether those vulnerabilities can be used and how far an attacker can go afterwards.

WorkQuestion it answersHow it is doneWhat you get
Information security auditIs protection built correctlyReview of settings, access rights, processes and documentsA prioritised list of risks and a plan of work
Vulnerability scanningAre there known vulnerabilitiesAutomated checks against a database, run regularly without human inputA list of vulnerabilities with severity ratings
Penetration testCan they be exploited and how farManual work by a specialist who exploits what was foundAttack scenarios: which entry point was used and which data was reached
Red TeamWill the security team notice usA long covert operation the IT team is not warned aboutAn assessment of how detection and response actually work

One does not replace another: an audit may show exemplary policies while a pentest finds a forgotten test server with a default password. What an infrastructure review covers and when it is worth ordering is explained in our article on the IT infrastructure audit.

Types of penetration testing

The type is chosen by which scenario is realistic for the company. There is no point in ordering everything at once: each type takes its own time and its own specialists.

TypeWhat it simulatesWhat is testedWhen you need it
ExternalAn attack from the internet with no access insideWebsites, mail, VPN, admin panels — everything exposed to the outsideThe baseline: this is how any attacker sees the company
InternalAn intruder already inside: an employee or an infected workstationNetwork segmentation, account privileges, access to file shares and databasesWhen the network has many workstations and shared resources
Web applicationAn attack on a website, customer portal or APIAccess rights, input handling, file uploads, order and payment logicBefore a product launch and after major updates
Social engineeringEmails and calls supposedly from colleagues, a bank or a contractorHow employees react: will they click, enter a password or send moneyWhen people, not technology, are the main risk

Web application testing relies on the common weaknesses listed in OWASP Top 10:2025: in this edition broken access control ranks first and a new category, software supply chain failures, ranks third. Phishing simulations only pay off together with training — how to build it is covered in our article on security awareness training for employees.

Black box, gray box and white box: what the tester knows

The model defines how much information the team receives before the start, and that determines what can realistically be covered in the allotted time.

If the goal is to see the company through the eyes of a random attacker, black box is the choice. If the goal is to find as many problems as possible before someone else does, white box works better: that is the usual option before launching a new product.

How a penetration test runs: the stages

The sequence is described in open methodologies — for example in the NIST SP 800-115 guide to technical security testing — and looks much the same across teams.

  1. Agreeing the scope: which addresses, applications and accounts are included, which methods are forbidden, which hours are allowed.
  2. Written permission from the system owner, notice to the hosting provider or data centre and a contact for stopping the work immediately.
  3. Reconnaissance: open data collection, hunting for subdomains, services, software versions and accounts exposed in other companies' breaches.
  4. Finding vulnerabilities: automated scanning plus mandatory manual verification of what the scanner reported.
  5. Exploitation: an attempt to use a vulnerability, escalate privileges and reach critical data.
  6. The report and a walkthrough of the findings — separately with the technical team and with management.
  7. Retesting after the findings are fixed: it confirms that the closed holes are really closed.

What the report must contain

The report is the main deliverable and the only thing the company keeps after the work. It shows how thoroughly the testing was done.

The last item is what separates an honest report. A straight "the firewall blocked us here, that system was excluded from the scope" is more useful to you than a smooth conclusion that no critical vulnerabilities were found.

What is legal in Uzbekistan

Testing without the system owner's written permission is not a pentest but a crime. The Criminal Code has a dedicated chapter on information technology offences, and within it Article 278-2, "Unauthorised access to computer information".

Important Permission is signed by whoever owns the systems. If the website or servers are rented, the provider's consent is needed separately: from its side scanning and load testing look like an attack and can end in a block.

Government bodies cannot choose a contractor freely. Decree UP-38 of 10 March 2026, which approved the Cybersecurity Strategy for 2026–2030, allows bodies without their own cybersecurity unit to use only those organisations that are included in a dedicated register. The register is maintained by the State Security Service.

Data is a separate question. If the system holds customers' personal data, agree in advance whether the team works on a copy of the database with anonymised records or on the live system, and put that in the contract together with an obligation to destroy every extract after the work.

How to prepare for the testing

Preparation strongly affects the result: without it part of the paid time goes into finding out whose server this is and whether it may be touched.

How to choose a contractor and what to put in the contract

The market is uneven: the word "pentest" covers both a month of manual work and a single scanner run with an automatic report. The difference shows in the contract and in a sample report.

Findings should be turned into a prioritised plan straight away — how to weigh likelihood and impact is covered in our article on information security risks. And the cheapest way to avoid a long report is to build protection in at the IT system design stage.

What it costs and where to start

The price follows the volume of work: how many external addresses and applications are in scope, how many user roles must be covered, which model was chosen and whether retesting is included. Compare it not with the price of a scanner but with the price of an incident.

Syntra Systems does not offer penetration testing as a separate service and does not sell it under another name. We start with an information security audit — from $1,200: we map what needs protecting, check servers, networks, mail, websites and workstations for known vulnerabilities, review access rights and the handling of personal data, and deliver a report where every risk has a likelihood, a consequence and a place in the queue.

If the audit shows there is something to close, the next step is data and access protection from $4,000: roles and two-factor authentication, encryption, protection of mail against spoofing, backups with verified restore, firewall and VPN, incident procedures and staff training. The full scope is on our cybersecurity for business page. The audit report is also useful if you decide to order a pentest from a specialised team: it already describes the systems, the access rights and the known weak spots.

Let’s discuss your project

Tell us what you need, and we will estimate the timeline and cost and suggest a solution.

Discuss a security audit

Frequently asked questions

How does a penetration test differ from vulnerability scanning?

A scanner compares software versions and settings against a database of known vulnerabilities and returns a list of findings. A pentest starts where the scanner stops: a specialist manually checks whether a vulnerability can be used and shows which data was reached.

How often is a penetration test needed?

After every significant change: a new product launch, an infrastructure move, a major web application update, a change of contractor. The report shows the state as of the testing date, so automated vulnerability scanning runs regularly between pentests to fill the gaps.

Can testing break production systems?

The risk is managed by rules. Scope and forbidden actions are fixed before the start, risky checks are agreed separately, critical systems are tested outside business hours. Destructive methods are never used without written approval, and the contract describes how to stop the work immediately.

How much does a penetration test cost?

We don't sell a standalone "pentest" service, under that name or any other. The price is set by the number of addresses and applications, the number of user roles, and how much the team already knows in advance — from a single website address to a network diagram and source code. We start with an information security audit, from $1,200.

Does a small company need a penetration test?

A small company is usually better off starting with an information security audit and regular scanning: they cost less and catch most of the common problems. A pentest pays off once the basics are covered and an online service earns money or holds customer data.

What should be done with the report afterwards?

The report becomes a plan of work: vulnerabilities are fixed in order of severity, each one gets an owner and a deadline, and then retesting is ordered. A report that simply goes into a folder does not make the company any safer.

Can we run a penetration test ourselves?

In-house it makes sense to run regular vulnerability scanning and keep software updated. Full testing needs separate qualifications and an outside view: your own team checks the system it configured itself and repeats its own blind spots.

Read also