What Is Pen Testing?
Penetration testing (or pen testing) is an engagement where an offensive security specialist (often from a pentration testing company or MSSP) is authorised to perform an attack on an organisation’s network and/or infrastructure.
A penetration test is conducted within a scope and terms of engagement document agreed with the client in advance. This scope sets out what the penetration tester is permitted to gain access to or disrupt, when they are permitted to do perform the test, and any other information that is pertinent to the engagement. The information contained within scope and terms of engagement will define whether the penetration test is black box, white box, or grey box.
What Are The Different Approaches To Penetration Testing?
Penetration testing can be performed in many ways, including physical testing, where a threat actor tries to access a company’s workplace and their on-site assets.
A penetration test can be conducted as an external threat (where you target an organisation’s internet-facing assets in order to gain access), or an internal threat (whereby you are already on a company’s internal network, behind their firewall.) Both relate to what type of box pen testing is being performed.
What Is The Difference Between Black, White, and Grey Box Pen Testing?
Black box, white box, and grey box relate to how much information and/or access a pen tester has before they begin testing. Different levels of information are provided so that the penetration tests mimic real-life threat scenarios.
Black box penetration testing is where penetration tester has no information or access to an organisation provided by the client in advance. This is as close a simulation of a real cyber-attack from an unfamiliar, external threat as is possible. During a black box penetration test, the pen tester will attempt to glean information from publicly available sources, such as the dark web and their own investigation of an organisation’s internet-facing assets.
Grey box penetration testing is where the company that has commissioned the penetration test provides some information to the testers that may assist them with the test. This could include software versions, asset types, and login credentials used by company employees and/or contractors. Reasons for doing this may be to understand the level of privilege an authorised user could gain and the extent of the damage they could cause. It allows for testing of role-based access controls (RBAC) and other multi-layered security features.
It is not uncommon for an external threat to conduct reconnaissance on a target environment, and grey box pen testing makes the overall test more efficient by removing this phase of a cyber-attack (which is often lengthy and, therefore, expensive).
White box penetration testing is where a pen tester is given access to an environment, such as a company’s internal network and devices inside of a company’s network perimeter. They may also be given network maps and full system information. This level of access means that a penetration tester can simulate a cyber-attack as though they were an insider working in the business. It gives the tester the opportunity to utilise as many channels (or attack vectors) as possible.
How Often Should Pen Testing Be Conducted?
Penetration testing should be conducted annually, particularly if there is a compliance reason for doing so (such as FCA regulation). A penetration test is a snapshot taken at a point-in-time however, and it has its limitations. For constant vigilance and awareness, network monitoring or a managed detection and response solution are better options.
What Is Best – White Box, Grey Box, or Black Box Penetration Testing?
There is no overall best option when it comes to penetration testing; the short answer is that it depends. If you have the time and money to conduct an effective black box penetration test, then it is worthwhile. However, to make this process more efficient, a grey box test is likely better than a black box penetration test. A white box penetration test is best if you are concerned about insider threats or your organisation’s overall internal security.
For more information on penetration testing, or if you are looking for external support with IT and security, get in touch with us today.





