Need urgent help?

Call our team on 0207 099 0740

Need urgent help?
0207 099 0740
Client Portal
view of earth from space which shows some areas with lights on as it is night time

3 May 2024

4 minutes read time

Types of Penetration Testing: Black vs White vs Grey Box Testing

Author

As Chief Information Security Officer at CloudTech24, I lead security strategy, governance and operational delivery. I help our clients’ executive teams make informed decisions about cyber risk. My role involves understanding how a customer’s business actually works, where the real risks sit, and what it takes to reduce them in a way that lasts, using existing capabilities wherever possible.

My background spans hands-on technical delivery and board-level advisory to clients across fintech, financial services, legal and other regulated industries. I also own our ISO 27001 programme and the ISMS behind it. As AI moves into everyday business use, I also ensure that our usage of AI aligns to best practise through governance and policy, and advise leadership and customers on safe adoption, aligning toward emerging standards such as ISO 42001 and the EU AI Act.

Outside of work, I’m a proud dad to two brilliant daughters and a lifelong LEGO enthusiast – if we’ve had a video call, chances are you’ve seen a few of my builds in the background. I’m also a passionate gamer and PC builder, a hobby I picked up in the early 2000s with my dad, who first sparked my interest in computers. Fun fact: back in the day, I was Europe’s #1 ranked Battlefield 1942 player – proof that my competitive streak goes way back!

Read blogs in other categories

What Is Pen Testing?

Penetration testing (or pen testing) is an engagement where an offensive security specialist (often from a pentration testing company or MSSP) is authorised to perform an attack on an organisation’s network and/or infrastructure.  

A penetration test is conducted within a scope and terms of engagement document agreed with the client in advance. This scope sets out what the penetration tester is permitted to gain access to or disrupt, when they are permitted to do perform the test, and any other information that is pertinent to the engagement. The information contained within scope and terms of engagement will define whether the penetration test is black box, white box, or grey box. 

What Are The Different Approaches To Penetration Testing? 

Penetration testing can be performed in many ways, including physical testing, where a threat actor tries to access a company’s workplace and their on-site assets. 

A penetration test can be conducted as an external threat (where you target an organisation’s internet-facing assets in order to gain access), or an internal threat (whereby you are already on a company’s internal network, behind their firewall.) Both relate to what type of box pen testing is being performed. 

What Is The Difference Between Black, White, and Grey Box Pen Testing? 

Black box, white box, and grey box relate to how much information and/or access a pen tester has before they begin testing. Different levels of information are provided so that the penetration tests mimic real-life threat scenarios. 

Black box penetration testing is where penetration tester has no information or access to an organisation provided by the client in advance. This is as close a simulation of a real cyber-attack from an unfamiliar, external threat as is possible. During a black box penetration test, the pen tester will attempt to glean information from publicly available sources, such as the dark web and their own investigation of an organisation’s internet-facing assets. 

Grey box penetration testing is where the company that has commissioned the penetration test provides some information to the testers that may assist them with the test. This could include software versions, asset types, and login credentials used by company employees and/or contractors. Reasons for doing this may be to understand the level of privilege an authorised user could gain and the extent of the damage they could cause. It allows for testing of role-based access controls (RBAC) and other multi-layered security features.  

It is not uncommon for an external threat to conduct reconnaissance on a target environment, and grey box pen testing makes the overall test more efficient by removing this phase of a cyber-attack (which is often lengthy and, therefore, expensive). 

White box penetration testing is where a pen tester is given access to an environment, such as a company’s internal network and devices inside of a company’s network perimeter. They may also be given network maps and full system information. This level of access means that a penetration tester can simulate a cyber-attack as though they were an insider working in the business. It gives the tester the opportunity to utilise as many channels (or attack vectors) as possible. 

How Often Should Pen Testing Be Conducted? 

Penetration testing should be conducted annually, particularly if there is a compliance reason for doing so (such as FCA regulation). A penetration test is a snapshot taken at a point-in-time however, and it has its limitations. For constant vigilance and awareness, network monitoring or a managed detection and response solution are better options. 

What Is Best – White Box, Grey Box, or Black Box Penetration Testing? 

There is no overall best option when it comes to penetration testing; the short answer is that it depends. If you have the time and money to conduct an effective black box penetration test, then it is worthwhile. However, to make this process more efficient, a grey box test is likely better than a black box penetration test. A white box penetration test is best if you are concerned about insider threats or your organisation’s overall internal security. 

For more information on penetration testing, or if you are looking for external support with IT and security, get in touch with us today.

Back to blog

Recent blogs from CT24

What is a virtual CISO (vCISO)?

Cybersecurity issues don’t pop up one at a time. They’re often frequent, urgent, and complex. When issues build up and the level of complexity increases to the point where your team needs an extra hand, having a vCISO can lighten the load. A vCISO (Virtual Chief Information Security Officer) is a security leader who serves…

Read more

Which one is better – AWS, Azure, or Google Cloud?

Choosing the right cloud infrastructure is a decision you can’t take lightly. Today, businesses must decide whether to build their applications on AWS, Azure, or Google Cloud. While these platforms offer similar core features like storage and computing power, each vendor approaches infrastructure, security, and developer experience with a completely different philosophy. This blog breaks…

Read more

The role of ethical hacking in penetration testing

Hacking into a business is, 99% of the time, a malicious act aimed at damaging an organisation. But penetration testing is that 1%, where it’s actually an incredibly safe and skilful way to find how you can improve your business.  In this guide, we’ll cover what penetration testing is, how it works, the process, and…

Read more