At JRM360 Security, one of the biggest mistakes I see businesses make is looking for a penetration testing company before they even know what they want tested. I know that may sound backward. After all, isn't that what you're paying the experts for? The answer is yes, but only to a point.
If you've ever hired a contractor to renovate your office or your home, you probably had an idea of what you wanted before you picked up the phone. You knew whether you wanted a new roof, remodeled kitchen, or additional office space. You didn't simply call and say, "Come tell me what's wrong." Cybersecurity is no different.
A penetration test is an investigation. Every investigation begins with a question. If you don't know what question you're trying to answer, don't be surprised if you receive a report that tells you a lot but answers very little.
I've worked in Information Technology for many years, and one thing I've learned is that organizations often purchase security assessments because someone told them they should. Maybe their cyber insurance requires it. Maybe a client asked for one. Maybe HIPAA recommends it. Those are all valid reasons, but they shouldn't be the only reasons.
A penetration test should give you confidence in your security posture. It should help you understand where your real risks lie, how an attacker thinks, and what to address first. If all you receive is a long list of vulnerabilities with no explanation of what they mean for your business, you've probably paid for information rather than insight.
Start With the Right Question
Before you spend money on a penetration test, ask yourself a simple question.
What am I trying to learn?
That single question changes the entire conversation.
Are you trying to find out whether someone can break into your network from the Internet? Are you wondering if ransomware could spread throughout your organization? Are you concerned about protecting patient information or financial records? Maybe you're moving to Microsoft 365 and want to know whether your cloud environment is secure. Every one of those concerns requires a different approach.
A good penetration testing company won't immediately hand you a quote. They'll ask questions. Lots of them.
They'll want to understand your business, your technology, your concerns, and your goals. If the first question they ask is, "How many IP addresses do you have?" they're already focused on the wrong thing.
The better question is, "What keeps you awake at night?"
That answer usually tells us far more than a list of servers ever could.
Do You Know Your Environment?
You don't need to know every switch, every firewall rule, or every subnet in your network. That's not realistic for many business owners. But you should understand the basics of your environment.
You should know what systems are critical to your business. You should know where your sensitive data lives. You should know which systems are exposed to the Internet and which ones are only accessible internally.
If I asked you where your customer information is stored, could you answer that question confidently?
If I asked whether your employees authenticate using Multi-Factor Authentication, would you know?
If I asked whether your backups are isolated from your production network, could you answer without guessing?
These aren't technical questions. They're business questions.
The better you understand your own environment, the more valuable your penetration test becomes.
Not Every Penetration Test Is the Same
This is probably one of the biggest misconceptions I encounter.
People often say, "We need a penetration test."
My response is usually, "What kind?"
There's usually a long pause.
Most people don't realize there are several different types of penetration testing because every environment is different.
At JRM360 Security, we regularly speak with organizations that believe they need a penetration test. After a few conversations, many discover they actually need something different. That's why every engagement begins with understanding the business, not the technology.
External Penetration Testing
This type of assessment answers a very important question.
If someone on the Internet targeted my business today, what could they see and what could they access?
An external penetration test focuses on the systems attackers can reach without ever stepping inside your building. That includes websites, VPNs, firewalls, cloud services, email security, remote access solutions, and anything else exposed to the Internet.
If your organization has never had an external penetration test, this is often the best place to begin.
Internal Penetration Testing
Now let's assume something different.
An employee clicked on a phishing email.
A laptop became infected with malware.
A contractor connected an infected device to your network.
The question is no longer whether someone can get inside.
The question becomes, what happens after they do?
An internal penetration test evaluates how far an attacker can move once they're already inside your environment.
This is often where organizations discover they have far more exposure than they realized.
Web Application Testing
If your business depends on a customer portal, online scheduling system, patient portal, ecommerce platform, or internally developed application, that application deserves its own assessment.
Web applications have unique security concerns that traditional network testing may never identify.
Authentication weaknesses, insecure programming practices, broken access controls, and exposed application programming interfaces are just a few examples.
A Vulnerability Scan Is Not a Penetration Test
This is probably the most important part of this entire article.
I cannot tell you how many times I've heard someone say they had a penetration test when what they actually received was an automated vulnerability scan.
There is a big difference.
A vulnerability scanner identifies known weaknesses.
A penetration tester determines whether those weaknesses can actually be exploited and what the business impact would be if they were.
Think about visiting your doctor.
Your blood pressure reading is useful.
Your cholesterol numbers are useful.
But those numbers alone don't tell the whole story.
Your physician interprets the results, considers your history, evaluates your overall health, and helps you understand what they actually mean.
A professional penetration tester does the same thing.
The scanner provides data.
The tester provides understanding.
Price Should Never Be the First Question
I understand budgets matter. Every organization has financial constraints.
But if the very first question you ask is, "How much does a penetration test cost?" you're asking the wrong question.
Imagine calling a mechanic and asking how much it costs to repair your vehicle without telling them what's wrong.
They couldn't possibly give you an accurate answer.
The same principle applies to cybersecurity.
The cost depends on the complexity of your environment, the scope of testing, the number of systems involved, your business objectives, and the amount of manual testing required.
A reputable company won't give you an instant price because they first need to understand what they're being asked to evaluate.
Questions Every Business Should Ask
If you're interviewing penetration testing companies, here are a few questions I would encourage you to ask.
- How much of your testing is manual?
- What methodology do you follow?
- How do you validate your findings?
- Will I receive an executive summary that leadership can understand?
- Do you prioritize findings based on business risk?
- Will you explain the results after the engagement is complete?
- Do you provide remediation recommendations?
- Will you perform retesting after issues are corrected?
If a company struggles to answer those questions clearly, continue your search.
The Report Should Help You Make Decisions
I've seen penetration testing reports that were well over one hundred pages long.
They looked impressive.
They were filled with screenshots, vulnerability identifiers, technical terminology, and pages of scanner output.
The problem was that nobody outside of IT knew what any of it meant.
A good report shouldn't just explain what was found.
It should explain why it matters.
If you're the CEO, I want you to understand your organization's biggest risks within the first few pages.
If you're the IT Director, I want you to know exactly what needs fixing first.
If you're the Board of Directors, I want you to understand the organization's overall risk without having to become cybersecurity experts.
That's what a quality penetration testing report should accomplish.
My Final Thoughts
If there's one thing I hope you take away from this article, it's this.
Don't buy a penetration test because someone told you to.
Buy one because you're looking for answers.
The right penetration testing company won't begin by selling you a service. They'll begin by understanding your business.
They'll ask questions you may not have considered. They'll explain their methodology. They'll help you define the scope. Most importantly, they'll help you understand not just where your vulnerabilities are, but what those vulnerabilities actually mean to your organization.
Whether your business is located in Ocala, Gainesville, The Villages, Belleview, Dunnellon, Lady Lake, Leesburg, Inverness, Crystal River, or anywhere throughout Central Florida, cybersecurity isn't about checking a box. It's about understanding risk well enough to make informed decisions.
Technology will continue to change. Attackers will continue to evolve. New vulnerabilities will always be discovered.
What shouldn't change is how we approach security.
The organizations that understand their environments will always make better security decisions than those that simply purchase more security products.
At JRM360 Security, we believe cybersecurity should help business leaders make informed decisions, not overwhelm them with technical jargon.
That, in my experience, is where good cybersecurity begins.
Johny Metellus, MBA, PMP, CISSP
Founder & Principal Consultant
JRM360 Security
Cybersecurity | Governance, Risk & Compliance (GRC) | Infrastructure | Healthcare IT | Security Leadership