Penetration testing: why and how to run a security audit?

The regulatory backdrop: GDPR, NIS2 and DORA
The digital world is moving fast, and so are the security requirements that come with it. Regulations such as the GDPR, NIS2 and the European DORA framework now demand a higher level of cybersecurity from companies, particularly in critical and financial sectors. With cyberattacks multiplying, organizations need effective preventive measures, and the penetration test sits at the top of that list.
For a less technical, higher-level view, strategic audits provide an analysis of the procedures and architecture of an information system.
Let's look at why running a penetration test has become essential.
What is a penetration test (pentest)?
Definition
A penetration test, also called a pentest, is a simulated cyberattack carried out in a controlled setting to identify security flaws in a system, a network or an application.
Performed by cybersecurity experts, it reproduces the techniques used by real attackers, giving companies a way to strengthen their defenses and stay ahead of cyberattacks.
Why run a pentest?
A penetration test is a core part of managing your cybersecurity. Because it spares you from discovering a flaw after it has been exploited, it gives you a concrete measure of your current security level and helps you prioritize your security efforts.
Many standards and regulations now require rigorous management of technical risk and vulnerabilities. An automated scan can catch some flaws, but it only goes so far. Only a penetration test led by a qualified expert provides a complete, reliable assessment of your security perimeter.
Beyond compliance, a pentest protects you against security incidents in very practical terms. By fixing vulnerabilities before they are exploited, you avoid consequences that can be severe: data loss, financial impact, reputational damage or business interruption.
Why choose HELX for your penetration test?
At HELX, our pentesters hold recognized certifications (OSCP, CRTO, CRTP, completion of HackTheBox pro labs) and follow proven methodologies (OWASP, PTES) to deliver a penetration test that is precise, reliable and actionable.
Our approach goes beyond the technical audit itself: we provide tailored support, aligned with your business constraints and security priorities. Every engagement is designed to give you clear results, practical recommendations and a prioritized action plan to strengthen your information system where it matters.
The 6 types of penetration test offered by HELX
External penetration test
An external pentest simulates an attack from the Internet, targeting the company's exposed services such as a web application, a VPN or a mail server. The goal is to identify vulnerabilities reachable from the outside and to verify how well the information system holds up against unauthenticated attackers.
Web penetration test
A web pentest also simulates an Internet-based attacker, but one specifically targeting a web application: a corporate site, an online store or a business tool. The risk here is an attacker gaining access to sensitive data or bypassing payment mechanisms. During this test, the auditor looks for flaws such as SQL injection, XSS, or errors in how authentication and permissions are handled.
Internal penetration test
An internal pentest simulates an attacker who already has access to the company network, for instance through a compromised employee. The auditor examines the entire information system for technical vulnerabilities and dangerous permissions, with the goal of taking control of the network and gauging how far an attacker could get. These tests reveal the weaknesses of a corporate network and help raise the overall security level of the information system.
Wi-Fi penetration test
The Wi-Fi pentest focuses on finding security flaws in a Wi-Fi access point that would allow an attacker to compromise sensitive data or gain unauthorized access to the corporate network.
Mobile penetration test
The mobile pentest is close to a web pentest in the kinds of vulnerabilities it targets. Here the auditor looks for technical flaws in the code of Android and iOS applications, but also examines how those applications store data on the device. The aim is twofold: verify that the services the application relies on (a web API, for example) are free of vulnerabilities, and confirm that compromising a phone would not let an attacker recover sensitive data stored unencrypted.
Physical penetration test
More unusual, the physical pentest involves attempting to physically enter a company's premises without full authorization. Typically only part of the management team knows the test is taking place, and the auditor's objective is to get inside the building to reach the company network or retrieve company data.
How does a penetration test engagement unfold?
The key stages
Penetration test engagements all follow the same structure:
- First contact and objective setting: We talk with you to understand your needs, define the scope of the test and set the goals of the engagement. Together, we identify the major risks to your information system and their potential impact, so the penetration test focuses on the most critical elements.
- Scoping and planning: the official project kick-off and the preparation of everything the engagement requires (schedule, approach, access validation)
- Security analysis and assessment: the main phase, running the penetration test on the scope agreed with the client and hunting for vulnerabilities
- Presentation of results: the client receives a detailed report, including an in-depth analysis of the vulnerabilities identified and their potential impact. Each vulnerability comes with a clear recommendation for fixing it
Setting objectives
A penetration test is not just a hunt for technical flaws: above all, it must assess the risks that threaten your business. That is why defining objectives starts with a concrete analysis of what is at stake for your organization.
During this phase, we work with you to:
- Identify critical assets (sensitive data, business applications, strategic infrastructure).
- Assess the risk scenarios that could hit your business hardest (data exfiltration, service downtime, compromise of a sensitive account, fraud on an application, and so on).
- Formulate concrete objectives: for example, "test an external attacker's ability to reach customer data", or "evaluate whether a payment application can withstand a bypass attempt".
- Prioritize attack scenarios according to their potential impact on your operations, your reputation or your regulatory compliance.
This business-risk-driven approach ensures the penetration test targets the real threats to your company, not just isolated technical vulnerabilities.
A closer look at the different approaches
A pentest can be conducted using several methods, also called approaches, often labeled by three colors: black, grey and white. These are the starting conditions of the test. Each approach corresponds to a different level of information given to the auditor before the security audit begins.
-
In a black box test, the auditor starts from scratch: no prior information and no special access to the target. This approach simulates a real external attack, where the attacker has to discover everything on their own.
-
In a grey box test, the auditor receives some information, such as credentials for an application or details about the network architecture. This simulates a scenario involving a malicious insider or an initial compromise already underway.
-
Finally, in a white box test, the auditor has as much information as possible, such as application source code or highly privileged accounts (administrator access, for example). This allows for a deep analysis and the most exhaustive identification of flaws.
In short
In a black box test, the auditor discovers everything alone; in a grey box test, they start with some information; in a white box test, they have full access for an in-depth analysis.
The choice between these approaches depends on the goals of the pentest, the type of infrastructure being audited, and the company's cybersecurity maturity. A black box pentest is useful for measuring overall resistance to external attacks. A grey box pentest is ideal for finding flaws reachable after initial access. A white box pentest, for its part, provides a detailed view for fixing every detected vulnerability effectively.
What comes after a pentest? The essential steps
Fix the vulnerabilities
After the pentest, the first step is remediation: fixing the identified flaws to strengthen security. The audit report contains every fix needed to close the vulnerabilities and raise the security level of the scope.
In most cases, the client's teams apply the fixes themselves, but some companies cannot, whether for lack of time or in-house skills. In that situation, our experts can support the client through this hardening phase.
Train and raise awareness among your teams
Sometimes the flaws are not technical but human: weak credentials, a phishing email, and so on. This can lead to a data leak on a business application even though the application itself is secure, or hand an attacker access to the corporate network even though external and physical penetration tests have been carried out.
Guarding against these risks means training both technical and non-technical staff. Through cybersecurity training courses, administrators and developers can learn about the most common flaws and, more importantly, how to avoid introducing them.
Less technical teams can attend cybersecurity awareness sessions to better understand the threats, adopt the right reflexes and reduce human risk.
Prepare for an incident
Even after all these steps, the risk of intrusion never drops to zero: a vulnerability can be introduced between two penetration tests, a service provider can get hacked, a software update can turn out to be malicious. The final step is therefore to prepare for the worst, an attacker actually getting in.
To do this, you can run an incident response capability audit, in which the auditors review your security policies, the procedures to follow during an attack, and the centralization of event logs. The goal is to make sure the company can react effectively when incident response becomes necessary.
FAQ - Frequently asked questions
How is this different from a vulnerability scanner?
A vulnerability scanner is an automated tool that checks a system against a known database of flaws. A penetration test, by contrast, relies on deep human expertise. The auditor can identify complex, context-specific vulnerabilities that an automated scan would simply miss.
How much does a penetration test cost?
The cost of a pentest depends on several factors: the scope of the audit, the complexity of the systems under test and the perimeter targeted.
As a rough guide, a penetration test can cost between 3,000 and 15,000 euros, depending on its scope: from a targeted test (such as a Wi-Fi audit or a small web application) to a broader assessment (internal and external network, several applications).
We also offer an SMB package designed for smaller organizations, with a format optimized for tight budgets. For a more precise estimate, use our online simulator.
To estimate your budget, you can use our online simulator or check out our SMB package built for smaller organizations.
What should I do before a penetration test?
Before a pentest, we hold a scoping meeting to define the objectives, the scope and the conditions of the audit together. Depending on your environment, you may need prior authorization from your hosting or infrastructure provider.
Is a penetration test dangerous?
A penetration test is designed to keep risk to a minimum. No load testing or denial-of-service testing is performed, which greatly reduces the risk of any impact on production. During preparation, we advise you on which environments to use to avoid any disruption.
Which environment should be tested?
It depends on how critical your scope is and on whether you can guarantee that the pre-production environment faithfully mirrors production. In most cases, tests are run on a pre-production or dedicated environment to avoid any risk. Once vulnerabilities have been identified, we can confirm their presence on the production environment in a controlled manner.
How do I know whether a vulnerability is still present?
After remediation, we carry out a follow-up audit (or verification test) to check that the identified vulnerabilities can no longer be exploited. This step is essential to confirm that the remediation measures actually work. If some flaws persist, we can also help you fix them.
How long does a penetration test take on average?
A penetration test typically takes between 5 and 15 business days, depending on the complexity of the scope, the chosen method (black, grey or white box) and the type of test (web, internal, physical, and so on). A test on a simple web application can take less than a week, while a full audit of an internal network or a critical system can run for several weeks.
Keep reading
Tell us about your project.
Let us talk through your needs and expectations and build the right service for you.

