Penetration Testing

What is a Penetration Test? A Plain-English Guide for UK SMEs

By Piotr Kleszcz, Fifth Ace 8 min read Updated July 2026

You've heard you should get a penetration test. Maybe a client asked for one. Maybe your insurer mentioned it. Maybe you read something about NIS2 and vulnerability management.

But what does a penetration test actually involve? How long does it take? How much does it cost? And do you actually need one?

This guide answers all of those questions in plain English — no jargon, no sales pitch.

What is a Penetration Test?

A penetration test (or "pentest") is a controlled, authorised attempt to hack into your systems — carried out by a security professional before a real attacker gets the chance to do it for free.

The goal is simple: find the weaknesses in your network, applications, or infrastructure before someone with bad intentions does. Then fix them.

Think of it like hiring a locksmith to try to break into your house — not to rob you, but to tell you which locks need replacing.

Penetration Test vs Vulnerability Scan — What's the Difference?

A vulnerability scan is automated. Software checks your systems against a database of known weaknesses and produces a list. Fast, cheap, but surface-level.

A penetration test is manual. A human tester actively tries to exploit vulnerabilities — chaining them together the way a real attacker would. It finds what automated tools miss.

What Does a Penetration Test Actually Involve?

A typical pentest for a small or medium business follows four phases:

Phase 1 — Reconnaissance

The tester maps your external attack surface: domains, IP addresses, open ports, public-facing services. This is what an attacker sees before they even try to get in.

Phase 2 — Scanning & Enumeration

Tools like Nmap identify running services, software versions, and potential entry points. The tester builds a picture of your infrastructure — looking for anything outdated, misconfigured, or exposed.

Phase 3 — Exploitation

This is the actual "hacking" phase. The tester attempts to exploit vulnerabilities to gain unauthorised access — escalate privileges, move laterally through the network, or access sensitive data. Everything is documented in real time.

Phase 4 — Reporting

You receive two deliverables: an executive summary (for management) and a technical report (for your IT team). Every finding is rated by severity, explained in plain language, and accompanied by a recommended fix.

Types of Penetration Tests

TypeWhat it testsBest for
Network PentestInternal and external network infrastructureMost SMEs — good starting point
Web Application PentestWebsites, web apps, APIseCommerce, SaaS, customer portals
Wireless PentestWiFi networks and access pointsOffices with guest WiFi or BYOD
Social EngineeringPhishing, pretexting, staff awarenessBusinesses with non-technical staff
Physical PentestPhysical access controlsData centres, server rooms

How Much Does a Penetration Test Cost in the UK?

Costs vary significantly depending on scope and provider:

ScopeTypical Cost (UK)Duration
Small network (up to 20 hosts)£800 – £2,0001–2 days
Medium network (20–100 hosts)£2,000 – £5,0003–5 days
Web application (single app)£1,500 – £4,0002–4 days
Full infrastructure (network + web)£4,000 – £10,0005–10 days
Watch out for: Very cheap "automated pentests" sold as manual assessments. If it costs under £500 and takes less than a day, it's almost certainly a vulnerability scan with a different label on it.

Do You Actually Need a Penetration Test?

You likely need one if any of the following apply:

Penetration Testing and NIS2

NIS2 Article 21 requires organisations to implement "vulnerability handling and disclosure" as part of their security measures. While the directive doesn't mandate annual pentests by name, regulators and auditors increasingly expect them as evidence of a mature security programme.

For UK businesses supplying EU entities, a documented penetration test — with remediation evidence — is often requested as part of supplier due diligence.

Frequently Asked Questions

Will a pentest take my systems offline?

A professionally conducted pentest should not cause downtime. Your tester will agree a scope and rules of engagement in advance, including which systems are in scope and what actions are permitted.

How often should I get a penetration test?

Most SMEs should aim for an annual test, with additional tests after major infrastructure changes, new application deployments, or security incidents.

What's the difference between black box, grey box, and white box testing?

Black box — tester has no prior knowledge of your systems (simulates an external attacker). Grey box — tester has partial knowledge (simulates a compromised account or insider threat). White box — tester has full access to documentation, source code, and credentials (most thorough, best value for money).

Do I need to fix everything in the report?

Not necessarily — findings are rated by severity (Critical, High, Medium, Low). Critical and High findings should be remediated immediately. Medium and Low findings can be scheduled and risk-accepted where appropriate.

Ready to find out what attackers would find?

Fifth Ace delivers penetration testing and NIS2 compliance audits for UK businesses with 10 to 100 employees. Fixed price. Plain-English reports. No corporate overhead.

Get a Quote →

Download our free NIS2 Readiness Checklist

Not sure where to start with NIS2? Take our free 5-minute self-assessment and get the PDF checklist straight to your inbox.

Download our free NIS2 Readiness Checklist →