Preparing for a Penetration Test and Scoping
Getting the most value from a penetration test depends on the preparation before it. A step by step guide to setting the purpose, scope (in/out), choosing the test type, timing, destructive test permission, communication line and legal authorization.
Quick answer: Getting the most value from a penetration test depends on the preparation done before it. Good preparation includes: clarifying the test's purpose (compliance or real risk measurement), clearly defining the scope (which systems, IPs, applications are in and out), choosing the test type and depth (black, grey, white box), setting the test window and destructive test permission, establishing a communication and emergency line, and putting the legal authorization in writing. The most common mistakes are leaving the scope vague and not giving the tester enough information; both reduce the value of the test. A well prepared scope directly determines both the budget and the usefulness of the findings.
Ordering a penetration test is a series of decisions most organizations face for the first time. What will be tested? How deep will it go? What will the tester know and not know? If the answers are not clear before the test, the result is a report that is either incompletely scoped or does not meet expectations. This article explains, step by step, how to prepare for a penetration test and set the scope correctly.
Purpose first: why are you testing
Everything starts with purpose, because purpose shapes the whole test. Some organizations test to meet a compliance requirement (a customer demand, an audit, a certification); here it matters that the scope and report follow a certain standard. Others want to see how resilient they really are in the real world; here depth and realistic attack scenarios come first. These are different tests. Clarifying your purpose upfront is the first step to choosing the right test type; we covered the differences between test types in the penetration testing types and scope article.
Scope: the most critical decision
The scope draws the boundaries of the test and is probably the most important part of preparation. A good scope clearly states: which systems, domains, IP ranges and applications will be tested; which are definitely out of scope; and in which environment the test will run (live or a copy). Keeping the scope narrow makes the test cheaper but leaves blind spots; making it too broad inflates the budget. The right scope focuses on the highest risk assets.
Pay attention to one point in particular: if your systems are hosted on a shared infrastructure or a cloud provider, only assets belonging to you should be tested; testing systems belonging to others is both a legal and an ethical problem.
Preparation checklist
| Decision | Question | Why it matters |
|---|---|---|
| Purpose | Compliance or risk measurement? | Determines the test type |
| Scope | What is in, what is out? | Determines budget and blind spots |
| Test type | Black, grey, white box? | Determines depth and duration |
| Timing | When is the test window? | Manages business disruption |
| Destructive test | Is it permitted? | Draws the safe boundaries |
| Communication | Who is called in an emergency? | Manages the crisis moment |
| Authorization | Is there written authorization? | Provides legal protection |
How much information to give the tester
A common question: how much information should I give the tester? The answer depends on your purpose. A test done with no information (black box) imitates a real external attacker but takes time and may miss some internal risks. A test done with full information (white box) goes far deeper in the same time and gives a comprehensive review. For most organizations, the middle ground (grey box) is the most efficient balance. What matters is making this decision consciously based on the test's purpose; withholding information does not always mean a better test.
The legal and communication side
No active test should begin without written authorization. This document defines the test's scope, duration, and permitted and forbidden actions, and protects both the organization and the tester; for details, see the penetration testing contract and legal authorization article. Also establish a communication line: if a critical finding emerges during the test or a system is unexpectedly affected, it must be clear in advance whom the tester will call.
The KAOS and DSET approach
DSET helps organizations set the right scope and purpose during preparation for a penetration test, then runs the test at scale with the local AI engine KAOS. KAOS quickly scans a broad surface to map the scope and reports every finding with a working proof, without false positive noise. The goal is to design not the most expensive or broadest test, but the one most suited to your organization's purpose and producing the most value.
Frequently asked questions
How broad should I keep the scope? It depends on your purpose and budget, but a good rule is to prioritize the highest risk assets. Keeping the scope too narrow leaves blind spots; keeping it too broad inflates the budget and can leave important areas superficial. Setting a phased scope with an expert, starting from the most critical systems, is usually the most efficient path.
Does giving the tester information about my systems reduce the test's value? No, it often increases it. A test done without information imitates a real external attacker but takes time and may miss some internal risks. A test done with full information goes far deeper in the same time. Which is better depends on the purpose; withholding information does not automatically mean a better test.
Should the test be done on the live system? It depends. Testing on the live system gives the most realistic result but requires careful planning and destructive test boundaries. On very sensitive systems that cannot tolerate downtime, testing on a copy (staging) environment is safer. This decision should be made during preparation along with the test window and destructive test permission.
Sources
- PTES penetration testing standard: http://www.pentest-standard.org
- OWASP testing guides: https://owasp.org
- DSET Penetration Testing and Security Services: https://dset.com.tr/hizmetler
To prepare correctly for a penetration test and set the scope for your organization, contact DSET. We provide penetration testing and consulting from our Ankara Hacettepe Teknokent laboratory.
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.