Skip to content
Skip to content

Mobhitech — Gérard Levicki

IT Security Testing & Penetration Testing: Put Your Defenses to the Test Under Controlled Conditions

Whether it's an external or internal penetration test, web applications, APIs, mobile apps, social engineering, or a Red Team exercise, security testing identifies what can actually be exploited within a defined scope and translates the results into remediation priorities.

The goal is not to compile a list of vulnerabilities, but to understand plausible attack vectors and their implications for the business.

Discuss your testing needs

What is an IT security test?

An information security test evaluates, within a predefined authorized framework, the resilience of a system, application, network, or organization against attack scenarios. A penetration test, or “pentest,” seeks in particular to identify and—when the framework allows—validate the exploitability of vulnerabilities.

The scope, permitted techniques, schedule, data to be accessed, and termination conditions are defined prior to the operation. A professional penetration test is never an uncontrolled attack on the information system.

Which security test should you choose based on your goal?

ObjectiveTestEvaluation
Online ExhibitionExternal Penetration TestExposed Services and External Access Paths
Forward already on the rosterInternal Penetration TestPrivileges, Segmentation, and Lateral Movements
Website or business softwareWeb Penetration TestingAuthentication, Authorization, Input, and Logic
Interfaces Between SystemsAPI Penetration TestingAccess, Data, Authentication, and Functions
Android/iOS AppMobile Penetration TestingApplications, Storage, Communications, and Backend
Broad Adversarial ScenarioRed TeamAbility to achieve agreed-upon goals
Improve Offense and DefensePurple TeamDetection, Response, and Monitoring

When Should You Conduct a Penetration Test?

  • before a critical system or service goes live;
  • after a redesign, migration, or major update;
  • to investigate a vulnerability identified by a cybersecurity audit;
  • to verify that a corrective action has been successful through a targeted retest;
  • when justified by a customer requirement, a contractual obligation, or an applicable regulatory requirement;
  • to evaluate detection and response using a Red/Purple Team approach.

External and Internal Penetration Testing: How Far Could an Attacker Get?

An external penetration test focuses on the perimeter accessible from the Internet. An internal penetration test is based on a scenario in which the attacker already has access to the network or a compromised system and, within agreed-upon limits, assesses privilege escalation, lateral movement, and access to sensitive resources.

The value of the test lies in its contextualization: a technical vulnerability must be linked to the scenario it enables and the assets it could affect.

Web, API, and Mobile Penetration Testing: Going Beyond Automated Scanners

Applications expose business functions, data, and identity mechanisms that automated scanners cannot always adequately assess. Manual testing specifically examines access controls, authentication, inputs, business logic, and data exposure.

TheOWASP guidelines serve as reference sources for structuring application testing: the Web Security Testing Guide for web applications and services, the OWASP API Security Project for APIs, and the Mobile Application Security Guide for mobile applications.The OWASP Top 10, currently in its 2025 edition, remains a useful awareness-raising document on the main web risks, but it does not replace a comprehensive testing methodology.

Penetration Testing, Red Team, Blue Team, or Purple Team: What Are the Differences?

ApproachPurposeFeature
Penetration TestValidate exploitable vulnerabilitiesTechnical Scope Defined
Red TeamAchieving Agreed-Upon Goals by Simulating an OpponentA broader and more realistic scenario
Blue TeamDefend, Detect, and RespondDefense Perspective
Purple TeamImproving Offense and Defense TogetherCollaboration and Learning

A Red Team is therefore not simply a “large-scale penetration test”: its objectives, scope, and rules of engagement are different.

Social Engineering and Phishing Simulations: Testing Without Unnecessarily Trapping Teams

Social engineering scenarios can assess certain reflexes in response to fraudulent requests. They must be proportionate, authorized, and designed with a clear educational objective.

A phishing simulation should not turn into a contest designed to “catch” employees. The results are used to improve alert procedures and raise awareness.

How is a penetration test conducted?

  1. Scope: objectives, scope, exclusions, permitted techniques, emergency contacts, and conditions for termination.
  2. Recognition: Identification of relevant surfaces and tracks within the authorized area.
  3. Controlled validation: verification of operational readiness when necessary and authorized.
  4. Qualification: linking evidence to assets, privileges, and potential impacts.
  5. Report: attack vectors, priority vulnerabilities, and recommendations.
  6. Retest: targeted review of significant corrections when appropriate.

What does a penetration test report include?

  • executive summary;
  • scope and rules of the test;
  • vulnerabilities and relevant technical evidence;
  • demonstrated attack paths;
  • assessment of impacts and priorities;
  • recommendations for corrective action;
  • boundaries and items outside the scope;
  • retest results, when included.

A technical score on its own is no substitute for business context.

Vulnerability scanning or penetration testing: What's the difference?

A vulnerability scan primarily automates the detection of known weaknesses within a system. It is useful for monitoring and maintaining security, but it does not replace human analysis.

The penetration test aims to determine whether a vulnerability is actually exploitable, whether multiple weaknesses can be combined, and what consequences this might have within the context of the organization.

CriterionVulnerability ScanPenetration Test
AutomationStrongPartial, with human review
Operational Feasibility ValidationLimitedYes, when necessary and permitted
A Series of WeaknessesUnderratedCan be analyzed
Business ContextLimitedMust be included in the report

Cybersecurity audit or penetration test: Which one should you choose?

CriterionAuditPenetration Test
QuestionWhat are our gaps and risks?Which vulnerabilities can be exploited?
ApproachEvaluation and AnalysisControlled Offensive Simulation
OperationNot necessarilyWhen necessary and permitted
ResultAssessment and RemediationProofs, Proof Strategies, and Solutions

What a penetration test does not guarantee

A penetration test does not prove that a system is “secure” and does not guarantee the absence of vulnerabilities. It assesses a specific scope over a given period of time, based on specific assumptions and rules. The information system may evolve, and certain scenarios may fall outside the scope.

Who conducts Mobhitech's security tests?

Penetration testing requires specialized skills depending on the scope of the project. Mobhitech can engage partners selected for their expertise, while providing guidance, oversight, and accountability for the service.

Mobhitech remains the point of contact for the project and ensures that the technical findings are translated into actionable priorities.

What should you do after a penetration test?

The first step is to validate the high-priority vulnerabilities, assign responsibility for fixing them, and distinguish between immediate fixes and long-term projects.

A retest is particularly useful for verifying that critical or high-severity vulnerabilities have been addressed. Depending on the results, the next steps may also include a broader audit, a cybersecurity consulting engagement, management by an outsourced CISO, or an awareness campaign.

A mission supervised by Gérard Levicki

Gérard Levicki provides guidance and oversight using an approach that integrates technical, risk, governance, and business considerations. He has more than 25 years of experience in cybersecurity.

Learn about his career · LinkedIn Profile

Additional Services

Frequently Asked Questions About Penetration Tests

How much does a penetration test cost?

The cost depends on the scope, complexity, expected depth, access provided, and expertise required. The scoping phase precedes the cost estimate.

How long does a penetration test take?

The duration depends on the scope and the scenario. A targeted test and a Red Team exercise do not require the same level of effort.

Can a penetration test disrupt production?

An offensive test involves operational risk that must be managed through the test framework, rules of engagement, exclusions, and termination conditions.

What is the difference between a vulnerability scan and a penetration test?

The scan primarily automates the detection of known vulnerabilities. The penetration test adds a human analysis and can verify exploitability and the chaining of vulnerabilities within the authorized scope.

Should we retest?

It is important to verify that the significant vulnerabilities identified during the test have been fixed.

Does a penetration test guarantee security?

No. It provides an assessment limited to a defined scope, time period, and set of rules. It reduces uncertainty but does not guarantee the absence of vulnerabilities.

How often should a penetration test be conducted?

There is no universal frequency. It depends on the criticality of the scope, technical changes, applicable requirements, incidents, and the acceptable level of risk.

Which test is actually right for your scope?

The initial assessment helps determine whether your needs call for an external, internal, application, API, or mobile penetration test; a Red/Purple Team exercise; or an audit.

The goal: to choose a test that addresses a real risk issue, not to test just for the sake of testing.

Request my free initial assessment · Contact Gérard Levicki