RED TEAM / PENTEST2026-09-0211 min

Penetration testing: scope, method and deliverables that drive change

A useful pentest answers a risk question, protects production and ends with retested remediation.

Direct answer

Penetration testing is an authorized security assessment that simulates attack techniques to demonstrate exploitable paths and impact. Its value depends on scope, rules of engagement, evidence depth and remediation follow-through.

31%

of breaches start with a vulnerability

The 2026 DBIR identifies vulnerability exploitation as the leading initial access vector. Testing should therefore connect discovery, real exposure and remediation time.

Verizon — 2026 Data Breach Investigations Report

Start with the decision you need

“Test the application” is too broad. Are you validating new authentication, tenant isolation, Internet exposure or access to critical data? That decision determines the profiles, accounts, environments and scenarios.

A vulnerability scan identifies weaknesses broadly; a penetration test attempts to validate and chain them within explicit limits.

Write operational rules of engagement

Define targets, exclusions, timing, prohibited techniques, load thresholds, data handling, emergency contacts and stop procedure. Include third parties and cloud services whose authorization must be confirmed.

Agree on the minimum evidence needed to prove impact so testers do not escalate unnecessarily in production.

A penetration test becomes actionable when it connects controlled exploitation, impact and retesting.
Key takeaway:A penetration test becomes actionable when it connects controlled exploitation, impact and retesting.

Require attack-path reporting

A CVE list is not enough. Each finding should explain the starting condition, reproducible steps, reached asset or data, bypassed controls and architecture-aware remediation.

The executive summary should present scenarios, distinguish demonstrated from hypothetical impact and show common dependencies across findings.

Use retesting as the closure decision

A symptom fix may leave the path open. Retesting confirms the control, tries a reasonable variant and checks for regression. Feed lessons into engineering standards, architecture and SOC detection.

  • Fix applied
  • Original path blocked
  • Relevant variants checked
  • Telemetry verified
  • Residual risk owned

Operational decision matrix

StageQuestion to resolveExpected outcome
ScopeDefine assets, exclusions and rules of engagement.Prevent out-of-scope action
TestValidate exploitable paths without harm.Preserve evidence
PrioritizeConnect likelihood, impact and exposure.Order remediation

Expected value

A scanner list is not a penetration test. Value comes from controlled proof of a realistic path and verified closure.

The right control level depends on context, exposed assets and business impact: document assumptions, measure the outcome and reassess after every material change.

Frequently asked questions

Are a pentest and security audit the same?

No. A pentest demonstrates exploit paths; an audit may cover governance, configuration, process and compliance more broadly.

Can production be tested?

Only with authorization, scope and safeguards proportionate to the risk. Pre-production may be preferable for some objectives.

What should the report include?

An executive view, attack paths, controlled evidence, priorities, remediation and retest conditions.

Official sources

Achraf Hachimi

CISSP-certified Senior SOC / CSIRT Engineer specializing in Incident Response, Threat Hunting and Detection Engineering. Eight years of experience in critical environments with Splunk ES, Microsoft Defender XDR, SentinelOne and Cybereason.