StructureClerk

Penetration test

Also known as: pentest · ethical hacking

A penetration test is an authorised exercise in which specialists genuinely attempt to compromise a system, to discover what an attacker could do.

It differs from vulnerability scanning, which is automated and reports known weaknesses. A penetration test chains them: it demonstrates a complete attack path, which a tool does not.

It requires a written engagement defining scope, execution window and permitted actions. Without that document, the exercise is legally indistinguishable from an attack.

Its useful deliverable is not the list of flaws but their prioritisation, and the retest after remediation confirming the fixes hold.

What it means for a small business

It is a significant expense, rarely justified before the basics are covered. Multi-factor authentication, patching and tested backups deliver more, for less.

So what actually applies to you?

A definition tells you what a term means, not what your organization must do. The assessment answers the second question — free, no credit card.

Updated September 1, 2026 · Educational definition; not legal advice.