Skip to content
RO
← All writing

Does my business need a penetration test?

  • security
  • audit
  • penetration-testing
  • gdpr

It usually turns up as one line in somebody else’s document. A tender, or a customer’s supplier form, asking whether you have had a penetration test in the last twelve months and inviting you to attach the report.

So you go looking for one, find firms that want to scope it before they will name a price, and start to wonder whether a business with eleven staff and a Microsoft 365 subscription really needs somebody to try to break in.

Sometimes it does. More often it needs something cheaper first, and I should say up front that the cheaper thing is what I sell. I do not sell penetration tests. I sell a read-only security audit, and this piece is about where the line between the two sits and why the order matters.

Three things that get called the same name

A penetration test is a person, authorised in writing, trying to get in. The NCSC’s guidance on penetration testing defines it as gaining assurance “by attempting to breach some or all of that system’s security, using the same tools and techniques as an adversary might.” The scope is agreed beforehand: which systems, what kind of test, how much effort.

A vulnerability scan is software. It looks at whatever it can reach, works out what is running and which version, and compares that against lists of known flaws. It is quick and noisy, and it is usually where the long report of red severity ratings nobody can act on comes from.

A configuration audit reads the settings from the inside. Mine runs 17 checks against Windows machines, changes nothing, and attaches to every finding the value it read, so your IT provider can check it without me. Nobody tries to get in. It answers a narrower question: how the machines are actually set up.

People use the three names loosely, and so do sellers. Ask of any quote which one you are being sold.

The NCSC’s answer is “not yet”

The line worth reading twice: penetration testing “should be viewed as a method for gaining assurance in your organisation’s vulnerability assessment and management processes, not as a primary method for identifying vulnerabilities.”

It compares a pen test to a financial audit. Your finance team keeps the books day to day, and the external auditor checks they kept them properly. “In an ideal world,” the guidance says, “you should know what the penetration testers are going to find, before they find it.”

Read that the other way round. If nobody has looked at your patch levels, your local admin accounts or whether SMBv1 is still switched on, a tester will find those for you, at tester rates, and they become the headline of an expensive report. The same page calls the exercise “powerful but expensive”, and points out that a test can only show you were not vulnerable to known issues “on the day of the test”. It is not unusual, it adds, for a year or more to pass between tests. A lot changes on a Windows estate in a year.

So my honest answer to most small businesses is to find out what you have and fix the obvious first. Then pay somebody to try to prove you wrong.

Does GDPR say you need one?

No. Article 32(1)(d) of the UK GDPR requires “a process for regularly testing, assessing and evaluating the effectiveness” of your security measures. The ICO’s guide to data security names vulnerability scanning and penetration testing as examples, then says the law “does not specify the type of testing, nor how regularly you should undertake it.”

What the ICO does expect is that you document the results and act on them, or have a valid reason not to. That is what a re-audit is for: the same checks run again, showing what got fixed rather than what somebody said got fixed.

When you genuinely need one

When the document says “penetration test”. If a contract or tender asks for one by name, my audit is not a substitute and I will not let it be passed off as one. Ask the customer whether they would accept something else. If they will not, buy a pen test.

When you run your own application on the internet. A customer portal, a booking system, anything with logins that you built or paid somebody to build. No settings check sees inside an application. The NCSC says testing can be usefully applied to “systems and applications developed ‘in-house’”, and that is where it earns its money. I build those portals for people, and the person who built something is the wrong one to sign off its security. One flaw I found in my own software was an assistant that obeyed an instruction hidden in a text file, eight runs out of eight. No configuration check would ever have seen it. Somebody had to attack it on purpose.

When you are public sector or critical national infrastructure. The NCSC runs its own CHECK scheme for that, and you probably have a procurement team who knows more about it than I do.

When you probably do not, yet

Ten people, Microsoft 365, a brochure website hosted by somebody else, nothing of your own facing the internet. An outside test of your office connection finds a router.

Meanwhile the government’s Cyber Security Breaches Survey, published on 30 April 2026, found phishing was the most common breach or attack “by far”, hitting 38% of businesses. A test of your IP range will not tell you whether your bookkeeper’s mailbox has a second factor on it. The same survey puts the businesses that had a pen test in the last twelve months at 13%. If a customer’s form asks and the answer is no, you are in the large majority, and a “no” with a date beside it is a respectable answer.

There is a quieter reason to start on the inside. When I went through my own server’s logs and configuration, one of the three things I found was a database running with no authentication. It was not reachable from the internet, which is exactly why an outside scan would never have found it. Reading the configuration did.

What my audit costs, and what it leaves out

It is a fixed price per audit, based on how many machines are in scope. Re-audits cost less. There is no retainer and no obligation to have me fix anything; if you want me to do the remediation, that is a separate conversation and a separate price. I quote once I know the machine count, because a published number would be wrong for nearly everybody.

What it does not do is the more useful list. It never tries to break in. It does not touch your website or any web application. It is Windows only, so phones and Macs are out. It cannot see your cloud services, which means MFA on Microsoft 365 is invisible to it, and that is the one I would worry about first. It does not send your staff a fake phishing email.

And it cannot certify you for Cyber Essentials. Only an IASME-licensed certification body can do that, and I do not hold it myself. What you get is each finding mapped to the Cyber Essentials control it relates to, which is the groundwork for passing it first time.

The order I would do it in

Audit, fix, re-audit. Then, if a contract or your own application calls for it, commission the pen test and hand the testers the audit report on day one. The NCSC lists “an opinion on the accuracy of your organisation’s vulnerability assessment” among the things a test report should contain, so you want them marking homework that exists rather than discovering that there isn’t any.

If somebody has asked you for a pen test this week, send me the exact sentence they used. I will tell you whether my audit answers it, and if it does not, I will say so before you pay me for anything.