A penetration test is a controlled attempt to break into a system with the owner’s permission, carried out by people using the same techniques a real attacker would. The goal is to find the weaknesses that matter in practice — the ones that actually chain together into a breach — and to prove them, rather than list theoretical risks.
It is different from an automated scan, which flags known issues. A good penetration test brings human judgement: understanding the business, chaining minor flaws into a real compromise, and prioritising by genuine impact. The deliverable that matters is not a long list of findings but a clear account of what an attacker could actually do and what to fix first.
Related terms