Penetration Testing
Part of Security Operations, alongside Cyber Security Solutions, Network Operations Center (NOC) Services, Security Awareness Training, and Vulnerability Assessments.
TTS Cyber offers penetration testing: external network, internal network, web application, phishing and social engineering, and cloud and Microsoft 365 tests. A partner firm that TTS Cyber manages does the testing. TTS Cyber follows NIST SP 800-115, a guide from the National Institute of Standards and Technology (NIST). You receive a written report with findings ranked by risk and a one-page executive summary.
What a penetration test is, and how it differs from a scan
The sections below describe what NIST’s guide and other public sources say in general. They do not list the steps of the partner firm’s own tests.
NIST SP 800-115, published in 2008, defines a penetration test as security testing in which assessors mimic real-world attacks. They look for ways around the security features of an application, system or network. Most tests look for combinations of weaknesses that together give more access than any single one would.
A vulnerability scan is a different job. The Payment Card Industry Security Standards Council (PCI SSC) wrote guidance in 2017 for payment card environments. The guidance says a scan identifies, ranks and reports vulnerabilities, or weaknesses, usually with automated tools plus manual verification. A penetration test looks for ways to exploit them. It is a manual process that may use scanners and other tools.
NIST guidance is not itself a legal requirement for a private firm. NIST also notes that tests often use non-technical methods, such as social engineering.
Which rules or standards ask for penetration testing?
Two examples follow. Each reaches only the group it names.
- The Payment Card Industry Data Security Standard (PCI DSS) is an industry standard. In version 4.0, requirement 11.4 calls for penetration testing at least once every 12 months, and after any significant infrastructure or application upgrade or change. It covers entities that store, process or transmit cardholder data or sensitive authentication data, or that could affect the security of the environment holding it.
- The Federal Trade Commission (FTC) Safeguards Rule is a federal regulation for financial institutions under FTC authority, such as mortgage lenders and tax preparation firms. Without effective continuous monitoring or other ongoing detection of changes that may create vulnerabilities, it calls for a penetration test every year. That yearly test does not apply to institutions that keep customer information on fewer than 5,000 consumers.
This page cannot say whether either one reaches your business. Ask your counsel, auditor or insurer whether either applies to you and whether a test meets it.
Does HIPAA require a penetration test?
Not today. The Security Rule of the Health Insurance Portability and Accountability Act (HIPAA) does not name penetration testing. It requires an accurate and thorough analysis of risks and vulnerabilities to electronic protected health information. It also requires a periodic evaluation of whether security policies and procedures meet the rule. The rule applies to covered entities and business associates, so ask your counsel whether you are one.
In January 2025, the US Department of Health and Human Services (HHS) published a proposal to add penetration testing to the Security Rule. As proposed, a qualified person would test relevant electronic information systems at least once every 12 months, or more often if the risk analysis calls for it. It is not final, so it creates no duty today. If finalized as proposed, it would apply to the same entities. To check its status, search reginfo.gov for regulation identifier number 0945-AA22.
TTS Cyber is not a law firm, and this is general information, not legal advice.
What approval should come before a test starts?
NIST SP 800-115 puts approval first. In its planning phase, the rules of the test are identified, management approval is finalized and documented, and goals are set. NIST also offers a Rules of Engagement template, a document that sets the terms of a test. It covers scope, test schedule and hours, communication, and incident handling with criteria for halting testing.
Approval matters because federal law (18 U.S.C. 1030) makes it an offense to intentionally access a computer without authorization, or beyond authorized access, and obtain information from a protected computer. NIST says the Rules of Engagement provide the authorization for activities that are usually prohibited.
NIST recommends that legal advisors always be involved in intrusive tests such as penetration testing. It says legal departments may help with indemnity or limitation-of-liability clauses and may require testers to sign non-disclosure agreements. Ask whoever will run your test to show you the written rules and approval steps before any work starts.
What’s included
- External network penetration testing
- Internal network penetration testing
- Web application penetration testing
- Phishing and social engineering testing
- Cloud and Microsoft 365 testing
- Testing by a partner firm that TTS Cyber manages
- NIST SP 800-115 as the guide TTS Cyber follows
- A written report with findings ranked by risk
- A one-page executive summary
What it’s for
- You can see which findings carry the most risk, because they are ranked by risk.
- People who will not read the full report can still get the main points from a one-page summary.
- The kinds of test cover different parts of your environment, from networks to Microsoft 365.
Frameworks and standards covered
- NIST SP 800-115
Frequently Asked Questions
What do you get at the end of a penetration test?
You receive a written report with findings ranked by risk, and a one-page executive summary. Read the report as a snapshot. NIST calls an assessment a snapshot of security at one point in time. So the findings describe the systems on the days they were tested. NIST also says no single technique gives a complete picture.
How much does a penetration test cost, and how long does it take?
This page lists no prices. PCI SSC guidance says a scan takes several seconds to several minutes per scanned host, while a penetration test may take days or weeks. The time depends on scope and the size of the environment. It can grow if more scope turns up. That range is general and is not a TTS Cyber timeline.
How often should you run a penetration test?
The rules section above gives the schedules PCI DSS and the FTC rule set for the groups they cover. If neither applies to you, nothing on this page sets a test schedule for you today. Because a report is a snapshot, NIST says more frequent assessments may be chosen.
Can a penetration test crash your systems?
It can. NIST says systems may be damaged or rendered inoperable during a test, and that the risk can be reduced but never fully eliminated. It says a test should follow careful consideration, notification and planning. The approval section above covers the halting criteria in NIST’s template.
Will your insurer or auditor accept a penetration test report?
That is up to the insurer or auditor, so ask what they require before you plan a test. For entities covered by requirement 11.4, PCI DSS asks for a qualified tester who is organizationally independent. That means separate from the management of the tested systems. PCI SSC gives one example. A third party that did the PCI DSS assessment cannot also do the test if it helped install, maintain or support the target systems.
What do black-box, grey-box and white-box testing mean?
PCI SSC guidance defines them by how much the tester knows in advance. Black-box means no prior knowledge, grey-box means partial knowledge, and white-box means knowledge of the internals. Before you agree to a test, ask which approach it will use.
Related services
Vulnerability Assessments
TTS Cyber staff run outside, inside and logged-in scans and review cloud and Microsoft 365 settings. You get a prioritized report, a summary and a fix plan.
Cyber Security Solutions
Security in layers, so a threat one control misses can still be caught by the next. It covers your data, systems and network, and aims to prevent, detect and respond to threats.
Virtual CISO (vCISO) Services
A Virtual CISO for teams without a security executive: SOC 2, ISO 27001 and CMMC work, vendor risk, incident response ownership, and reporting.
Further reading
From our blog
Industries