Guest Article | Penetration Test Scoping | What to Test First and Why?

Guest article from Fortifi Cyber Security

Kieran Roberts, Founder and Director at one of our partners, Fortifi Cyber Security, provides tips on getting the scope of a Penetration Test right, specifically how to plan ahead with what to test, in what order, and why. Read on to find out how to genuinely improve your security.

Most organisations know they should run a penetration test, but far fewer stop to ask what the test is actually meant to achieve.

Each year, a renewal date appears, last year's scope gets dusted off, the same systems get tested again, and a near-identical report lands in someone's inbox. A box is ticked, and nobody is much safer than they were twelve months ago.

That is the problem we want to talk about.

Not whether you should test, but what you should test, in what order, and why, because if you get the scope right, a penetration test becomes a genuine improvement to your security. Get it wrong, and you have bought yourself a very expensive piece of paper.

Why does the scope of a penetration test matter?

The scope is simply the agreement on what gets tested and what gets left out. While it sounds a lot like admin, it is much closer to a cybersecurity strategy, and its importance cannot be understated.

Much like a telescope can only see what it’s aiming at, a test can only find weaknesses in the things in scope. So, if your scope ignores the part of your attack surface that an attacker would actually target, the report can come back clean while the real risk remains untouched.We have seen organisations test a well-hardened public website year after year, while the cloud environment quietly grew into the largest part of their attack surface. The website kept passing, the exposure kept growing, and they had no idea that each year, their business was becoming less secure.

Ultimately, the scope decides where your money goes, and, as with anything, if you spend it in the wrong place, it’s wasted because you are paying to confirm what you already knew.

What does tick-box testing actually cost you?

Compliance-driven testing has a habit of freezing scope in time because, while the business changes, the scope does not.

In the gap between two annual tests, most organisations will have added new applications, moved services to the cloud, onboarded suppliers with access to internal systems, and changed who can reach what. None of those changes are reflected if you simply repeat last year's test.

So the cost is not really the fee, but rather the false comfort that comes with each completed test. A pass against an out-of-date scope tells your board that things are fine, right up until the moment they are not, making it practically useless.

There is also an opportunity cost because the budget you spent retesting a stable, low-risk system is the budget you did not spend on something newer and more dangerous.

How do you decide what to test first?

The honest answer is that it depends on your business, which is exactly why a conversation beats a template. Ask yourself these few questions, and you should be well on your way to knowing where best to start.

What has changed since the last test? New systems, new integrations and recent migrations carry the most unknown risk, so they usually earn a place near the top.

What would hurt most if it were breached? Map the data and systems that matter to the people who would have to explain the incident. Think of it like this: your crown jewels deserve attention before anything else.

Where would an attacker realistically start? Internet-facing services, remote access, and anything holding customer or payment data are common entry points. As AI software and chatbots become more common and companies race to implement them, it is likely that the answer to this question will be the same as the answer to the first question.

What did the last test flag that never got fixed? Re-testing closed issues has value, but only if they were closed.

Work through those, and a priority order tends to emerge on its own. The job of a good provider is to ask questions and challenge easy answers, not to hand you a fixed shopping list. So go into your scoping call with an open mind, and don’t be afraid to lean on the expert's experience.

Automated vs. manual penetration testing: what is the difference?

This is where we want to be fair, because automation has earned its place.

Automated scanning is fast, cheap and tireless. It is very good at sweeping a large estate for known vulnerabilities, missing patches and obvious misconfigurations, and running scans regularly between manual tests is sensible. In fact, we recommend it.

What a scanner cannot do is think like an attacker. It will not chain three low-rated findings into one serious compromise, just like it will not reason about your business logic, spot that a discount field can be abused to commit fraud, or notice that a harmless-looking page leaks just enough information to make access easier.

With the correct scope, a tester does all of that.

The value of manual penetration testing lies in judgment: understanding context, following a hunch, and pursuing the path a real intruder would take rather than the path a checklist prescribes.

Ultimately, automated tools cast a wider net and keep you honest between engagements, while manual testing goes deep where it matters. Treating a vulnerability scan as a penetration test is the mistake to avoid, and plenty of vendors are happy to let buyers believe the two are the same.

Should you test the same thing every year?

Sometimes, yes. A system that handles your most sensitive data and faces the internet probably warrants annual attention regardless.

The point is that repetition should be a decision, not a default.

So, if you are testing something for the third year running, you should be able to say why it still deserves the slot ahead of everything that has changed around it.

A healthier pattern is a rolling programme where you cover the highest-risk areas often, rotate through the rest over a longer cycle, and revisit the scope whenever the business shifts in a meaningful way.

That approach keeps coverage broad over time without pretending you can test everything at once.

How to work with your penetration testing provider

The best results come from treating your provider as a partner throughout the entire process, rather than just someone you rely on once a year to carry out last year’s scope.

The better their contextual understanding of your business, the more valuable the results of your test are likely to be. Tell them about the cloud migration, the acquisition, the new customer portal and the supplier you just gave access to, because the more they understand your business, the better.

Better business decisions usually come from people pushing back and forth, not from everyone agreeing. A provider who simply agrees to repeat last year's work is doing you no favours and clearly values easy work over actually helping you to become more secure. You want them to ask awkward questions that get you to think meaningfully about how this test can deliver the most value.

Read the report with the next test in mind because findings are not just a to-do list. They are evidence about where your weaknesses cluster, which should inform what you prioritise next.

Remember, a single test is a snapshot, which means you should create a plan over several years. A programme, shaped by someone who knows your environment, is a strategy that will leave you much better situated than repeat tests.

If you approach your penetration testing this way, penetration testing stops being an annual formality and starts doing what you are paying for: making you genuinely harder to attack.

Fortifi Cyber Security works with organisations to scope, prioritise and run penetration testing that reflects real-world risk.

To get a quote for your next penetration test, contact your OX IT Solutions Account Manager today.


Next
Next

Case Study | msolv | Engineering | Cybersecurity, Backup & Recovery