In short: Penetration testing is a security test in which an authorised specialist uses real attacker techniques to break into your systems in a controlled way and reports every weakness found by severity. For SMEs, the right start is a narrow but clear scope beginning with internet-facing systems, written authorisation, fresh backups before the test, and a retest once the critical findings have been fixed.
The firewall is in place, antivirus is up to date and the passwords are “complex enough”. But if an attacker tried today, would they really stay out? Penetration testing (pen testing, pentest) answers that question with evidence instead of assumptions. The UK National Cyber Security Centre’s penetration testing guidance describes it as a way to gain assurance that your security controls work as intended, and stresses that it should complement, not replace, routine vulnerability management. The steps below bring that approach down to SME scale.
We covered the general layers of defence in our article on cybersecurity for SMBs. Here the focus is a single question: do those controls actually work, and how do you get them tested properly?
What is penetration testing and how is it different from a vulnerability scan?
A vulnerability scan is an automated tool listing known weaknesses and missing patches on your systems. It is fast and should run regularly, but it does not answer the question “can this weakness really be exploited?” In a penetration test, a specialist chains findings together: for example, they check whether an account opened with a weak password leads to the file server and from there to the customer database. The result is not a long list of issues but attack scenarios that show the real risk to your business.
How does the penetration testing process work?

A well-planned test is not a surprise but an agreed piece of work. The typical process has five steps:
1. Scope and written authorisation
The IP addresses, domains and applications to be tested, the systems that are strictly out of scope, the testing hours and the emergency contacts are all agreed in writing. A “test” without written permission is, legally, unauthorised access.
2. Discovery
The tester maps internet-facing services, subdomains, open ports and software versions. This stage often uncovers a forgotten test server or an old admin panel.
3. Exploitation attempts
The tester tries, in a controlled way, whether the weaknesses found can really be exploited. The goal is not to break anything but to prove how far an attacker could get, so risky steps are discussed with you beforehand.
4. Reporting
The report should include an executive summary, the severity of each finding (critical, high, medium, low), how to reproduce it and concrete remediation advice.
5. Remediation and retest
Once critical and high findings are fixed, the same scenarios are tried again. A penetration test without a retest is unfinished work.
What types of penetration test are there?
- External network test: testing your firewall, VPN, email and web servers from the internet. For most SMEs this is the first step.
- Internal network test: what an attacker plugged into the office network, or a malware-infected PC, could do. Missing segmentation and excessive permissions show up here; our server and network infrastructure checklist covers the basics.
- Web application test: session handling, authorisation and input validation in apps such as a customer portal, B2B ordering screen or online shop.
- Wireless test: checking that guest and corporate Wi-Fi are really separated.
- Social engineering test: measuring how staff react to fake emails or phone calls. To turn this into an ongoing programme, see our guide to phishing simulation for SMEs.
There are also three approaches depending on how much the tester is told: black box (no information), grey box (limited information such as a user account) and white box (architecture documents shared). For SMEs on a limited budget, grey box is often the most efficient choice because time goes into real risk rather than discovery.
How should an SME set the scope?
Trying to test everything at once means spending the budget on a shallow exercise. We recommend this order: first internet-facing systems (website, VPN, remote desktop, email), then applications holding customer or personal data (ERP, CRM, portals), and finally the internal network. If you process EU personal data, Article 32 of the GDPR expects a process for regularly testing and evaluating the effectiveness of your security measures; a regular penetration test is a practical way to document exactly that.
Pre-test checklist
- Are the IP addresses, domains and applications to be tested listed, and are out-of-scope systems written down?
- Are test dates, hours and blackout periods (month-end, campaign days) agreed?
- Is there a technical contact and an emergency phone number on both sides?
- Have critical systems been backed up and has a restore been tested?
- If your hosting company, cloud provider or software vendor must approve the test, has that approval been obtained?
- Does your security team or service provider know about the test, and how will alerts be handled?
What should you do once the report arrives?
Filing the report away throws away the value of the test. First assign an owner and a target date to every critical and high finding; critical issues on internet-facing systems should be closed within days. For findings that cannot be fixed right away, apply temporary measures (restrict access, switch the service off) and record the decision. If the test affects a system unexpectedly, your disaster recovery plan and current backups come into play. Finally, schedule the retest and repeat penetration testing at least once a year or after any major system change.
At ÇAP Teknoloji we support SMEs with scoping, coordinating the test and closing the findings. Take a look at our cybersecurity consulting service or get in touch to review your systems together.
Frequently Asked Questions
Is penetration testing the same as a vulnerability scan?
No. A vulnerability scan automatically lists known weaknesses; in a penetration test a specialist checks whether those weaknesses can really be exploited and chains them into realistic attack scenarios. The two complement each other rather than replace each other.
Can a penetration test break our systems?
With proper planning the risk is low. Scope, testing hours and risky steps are agreed in writing beforehand, critical systems are backed up and emergency contacts who can stop the test are named on both sides.
How often should an SME run a penetration test?
A common recommendation is at least once a year, plus after launching a new application, migrating infrastructure or making a major configuration change. A retest should always follow once critical findings are fixed.
What should we test first?
For most SMEs the best starting point is internet-facing systems: the website, VPN, remote desktop access and email servers. Applications holding customer or personal data, such as ERP, CRM or portals, should come next.


