09-10-2026
Hugo Ploeg
Reports of companies falling victim to cyberattacks appear in the news with increasing regularity. But how do you actually know if your systems can withstand such an attack? That is precisely where penetration testing comes in. In this blog, we explain what a pentest is, what its objective is, and which variants exist.
A pentest, short for penetration test, is a "manual assessment where testers attempt to penetrate as deeply as possible into a digital system to identify vulnerabilities and determine their impact. The discovered vulnerabilities are then used to gain even deeper access into the system," according to the Cybersecurity Dictionary of Cyberveilig Nederland.
This exercise is not meant to cause damage, but to identify security flaws before malicious actors do. Another crucial detail: a pentest is not an entirely automated process. It is carried out by real security specialists who think critically and adapt dynamically, exactly as an attacker would.
The objective of a pentest is "not necessarily to find as many vulnerabilities as possible. The primary goal is to examine whether a system contains vulnerabilities," the Cybersecurity Dictionary of Cyberveilig Nederland notes further. Discovered vulnerabilities are deliberately leveraged to see how far an attacker could penetrate. From that newly gained foothold, subsequent attack paths are investigated.
A frequently asked question is the difference between a penetration test and a vulnerability scan or assessment. The distinction lies in depth. A vulnerability scan broadly identifies potential weaknesses or configuration flaws across systems, but these are not actively exploited. A pentest goes a step further: discovered vulnerabilities are actively exploited to gain unauthorized access, and the investigation continues from that position. That makes a pentest significantly more thorough.
Not every pentest follows the same approach. Depending on the level of information provided to the testers in advance, three main variants are distinguished:
Black box penetration test. In a black box test, security experts receive zero prior knowledge of the target systems. They simulate an external attacker operating completely from the outside, providing a realistic perspective of an unknown threat actor's methodology.
Gray box penetration test. A hybrid of black box and white box testing. Testers receive limited information, such as high-level architecture diagrams or partial source code access. This enables more targeted testing and simulates risks associated with internal leaks or partial privilege abuse.
White box penetration test. Experts are granted full visibility: source code, system architecture blueprints, and infrastructure documentation. This allows for exhaustive analysis, uncovering vulnerabilities that would be difficult or impossible to identify from an external vantage point alone.
The costs of a pentest depend primarily on the scope and complexity of the target environment. A standalone web application requires a fundamentally different approach than a sprawling enterprise IT infrastructure.
Interested in knowing what a penetration test would entail for your organization? Feel free to reach out to us, and we will gladly assess your requirements together.
Curious about how we approach projects and security challenges?
Contact us for an obligation-free conversation.