Penetration Testing Hub › Penetration Testing Explained
Do You Actually Need a Penetration Test Yet?
This page is about deciding whether to test at all, so it carries no how-to steps — but the rule still stands across this site: only ever test systems you own or are explicitly authorised to test, per the Criminal Justice (Offences Relating to Information Systems) Act 2017.
Most pages that ask this question are written by people who profit from the answer being yes. So let's be straight: quite often, the honest answer is 'not yet'. Here's how to tell which side of the line you're on.
You probably don't need one yet if…
- You've never run a vulnerability scan. A pentest will mostly re-discover what a scan would have found, at far greater cost. Scan and patch first.
- MFA isn't enforced on email, VPN, admin and cloud accounts. Turning that on removes more real risk than any single test will.
- You don't have an inventory of your systems. If you don't know what you have, a tester will spend your budget finding out.
- You've got one security spend this year and the basics aren't done. Patching, MFA, backups and segmentation beat a pentest every time when they're missing.
- You'd have no capacity to fix what the test finds. A report full of unactioned findings is a liability, not an asset.
None of that means security doesn't matter. It means a pentest is the wrong first purchase. It's a measuring instrument — it's most valuable once you've done the obvious work and want to know what a real attacker would find next.
You probably do need one if…
- You handle sensitive personal, health or financial data, or card payments.
- You've just built, bought or exposed something new — an app, a portal, a cloud migration, an acquisition.
- A framework or contract requires it: NIS2, PCI DSS 11.4, DORA, ISO 27001, or a customer's security questionnaire.
- Your cyber-insurer asks for evidence of testing at renewal.
- You've done the basics — scanning, patching, MFA, segmentation, backups — and genuinely want to know your real exposure.
- You're selling to enterprise customers who won't sign until you can show a clean report.
The cheaper things to do first
If you're on the 'not yet' side, here's the running order that gets you most of the risk reduction for the least money, before any pentest:
- Turn on MFA everywhere it'll go.
- Run a vulnerability scan and fix the criticals and highs.
- Build an asset inventory — even a spreadsheet beats nothing.
- Change every default password on network kit.
- Get backups offline or immutable and test a restore.
- Segment guest, OT and user networks away from your servers.
- Enforce patching on internet-facing systems first.
Do those, and when you do commission a test, you'll get findings worth paying for instead of a bill for confirming the obvious.
A quick way to decide
Ask yourself one question: if a tester handed me a report tomorrow, could I act on it? If the honest answer is 'no, we'd struggle to fix any of it', spend this year building the capacity to fix. If it's 'yes, and we want to know where we really stand', you're ready.
Common questions
Is a penetration test worth it for a small business?
It can be, but usually only after the basics are in place. For a small business that hasn't yet enabled MFA, patched, or run a vulnerability scan, that groundwork removes far more risk per euro than a pentest. Once it's done — or once you handle sensitive data or face a compliance trigger — a test becomes genuinely worthwhile.
Can I just run a vulnerability scan instead?
Often, yes, at least to begin with. A scan finds known weaknesses cheaply and repeatably, and for many organisations that's the right first step. A penetration test earns its extra cost once you've fixed what a scan finds and want to know what a human attacker could still chain together.
What should I do before my first penetration test?
Enable MFA, run and act on a vulnerability scan, build a basic asset inventory, change default passwords, sort your backups, and segment your network. Doing these first means the test finds real, non-obvious issues rather than billing you to rediscover the basics.
If you're not sure which side of the line you're on, we're happy to tell you honestly — including 'come back in six months'. Here's how a scoping conversation with CyberLabs works; there's no cost to being told you're not ready yet.
No prices on this page and no hard sell.
This page is educational and not legal advice. Only test systems you own or are explicitly authorised to test. · ↑ Back to top