What to do before your first penetration test
A practical preparation checklist for your first penetration test: how to scope it, prepare access, set rules of engagement, and plan for the fixes.
Booking your first penetration test can feel like inviting someone to break into your house and take notes. It's a lot less stressful when you know how to prepare. Here's a practical checklist to get the most from your first engagement.
1. Define your goal and scope
Start with why. Compliance? A customer requirement? Pre-launch assurance? Your goal shapes the scope. Then decide exactly what's in scope (which applications, environments, IP ranges, or cloud accounts) and, just as importantly, what's out.
2. Pick the right test type
Web app, API, cloud, network, mobile, and social engineering are different disciplines. If you're not sure which you need, a good vendor will help you choose during scoping. (Our services overview is a starting point.)
3. Prepare access and environments
Testers work faster and find more when they can actually reach the target. Decide whether you'll test staging or production, and prepare test accounts for each user role, API credentials, and any documentation. Grey-box testing, where testers have credentials and docs, usually delivers more value than black-box guessing.
4. Set clear rules of engagement
Agree the testing window, what's off-limits, how disruptive actions are handled, and the escalation path for a critical finding. Put it in writing. This protects both sides and keeps testing safe.
5. Tell the right people (and not too many)
Decide who needs to know. For a standard pentest, your ops and security teams should be aware so they don't mistake testing for a real attack. For a social engineering assessment, you'll usually keep the circle small so results reflect real behavior.
6. Plan for remediation and retest, before the report lands
The report is the start of the work, not the end. Make sure engineering time is set aside to fix findings, and confirm your vendor includes a retest to verify the fixes. (We do, at no extra cost.)
7. Ask your vendor the right questions
- Will testing be manual, by senior testers?
- What standards do you follow?
- What does the report include, and can I see a sample?
- Is a retest included?
Key takeaways
- Start with your goal; let it define the scope.
- Prepare access and test accounts up front. It directly improves the results.
- Put rules of engagement in writing.
- Budget time for remediation and insist on a retest.
Getting ready for your first test? Book a scoping call and we'll help you plan it, or see a sample report so you know exactly what you'll get.