Amaltitek Logo

Most organizations today have invested significantly in cybersecurity.

You have a firewall. Endpoint protection. MFA. Email security. Backups. Security policies. Maybe even vulnerability scanning.

Everything is patched—or at least somebody says it is.

So you're secure, right?

Hopefully.

And that's exactly why penetration testing exists.

What exactly is a penetration test?

A penetration test—or "pen test"—is a controlled security assessment where trained security professionals attempt to identify and exploit vulnerabilities in your environment using techniques similar to those used by real attackers.

The key word here is exploit.

A vulnerability scanner might tell you:

"This server may be vulnerable to X."

A penetration tester asks:

"Can I actually use X to get somewhere I'm not supposed to be?"

That's a very different question.

Vulnerability scanning and penetration testing aren't the same thing

We occasionally hear:

"We already run vulnerability scans. Why do we need a penetration test?"

Vulnerability scanning is an important part of a good security program, but it's largely automated. A scanner identifies known vulnerabilities, missing patches and configuration weaknesses.

Penetration testing adds a human being to the equation.

A tester can combine seemingly minor weaknesses, change tactics when something doesn't work, identify trust relationships and look for ways to move from one system to another.

A scanner might find three medium-risk vulnerabilities.

A penetration tester might discover that combining those three vulnerabilities provides access to something considerably more interesting.

That's the part attackers are particularly good at.

Your firewall isn't the whole security strategy

Having a good firewall is important. So are endpoint protection, MFA, email security and properly configured Microsoft 365 security controls.

But owning security products and having a secure environment aren't necessarily the same thing.

Configuration matters.

A firewall rule created six years ago for an application nobody remembers can matter. An old service account can matter. Excessive administrative privileges can matter. A forgotten server can matter.

Even something as innocent as an internal application still using an outdated authentication method can create an unexpected path through the network.

Penetration testing helps answer a much more useful question:

"If someone gets in, what can they actually do?"

External testing: What can someone see from the Internet?

An external penetration test looks at your organization from outside the network.

The tester evaluates your public-facing infrastructure and attempts to identify weaknesses that could potentially provide unauthorized access.

This can include Internet-facing systems, VPN services, web applications, remote-access infrastructure and other externally exposed services.

Think of it as hiring someone to walk around your building checking the doors and windows—except you're specifically paying them to try the handles.

Internal testing: Assume someone already got inside

This is where things can get particularly interesting.

An internal penetration test generally begins from the perspective that an attacker has already obtained some level of access to your network.

Maybe an employee clicked a malicious attachment.

Maybe a laptop was compromised.

Maybe credentials were stolen.

The question becomes:

What happens next?

Can that access be expanded?

Can credentials be obtained?

Can the tester move laterally between systems?

Can a regular user somehow become an administrator?

Can sensitive systems or data be reached?

Ideally, the answer to all of those questions is no.

A penetration test is a considerably better place to discover otherwise than during an actual incident.

It also tests all those security projects you've been doing

This is one of our favourite reasons for recommending penetration testing.

Organizations spend years improving their environments:

Network segmentation.

MFA.

Endpoint detection and response.

Restricted administrative accounts.

Firewall policies.

Server hardening.

Secure backups.

Penetration testing provides an opportunity to see whether all those controls actually work together.

You may discover that your network segmentation successfully prevented lateral movement.

That's a good result.

Security testing isn't only about finding things that are broken. It's also about validating the things you've spent considerable time and money getting right.

"But what if they find something bad?"

Good.

That's why you're doing the test.

Finding a serious vulnerability during a controlled penetration test means you have an opportunity to correct it before somebody discovers it without sending you a report afterward.

We'd much rather receive:

"Critical finding — remediation required."

than:

"Your files have been encrypted. Here's the Bitcoin address."

The first email generally makes for a better Tuesday.

How often should you perform one?

For many organizations, penetration testing should be performed at least annually, with additional testing considered after significant infrastructure or application changes.

Examples might include a major network redesign, deployment of new Internet-facing systems, mergers or acquisitions, significant cloud migrations or major changes to security architecture.

Certain industries, customers, insurers and compliance frameworks may also require penetration testing at specific intervals.

Most importantly, penetration testing shouldn't be treated as something you do once and then frame the report.

Your environment changes constantly.

So does the threat landscape.

What happens after the test matters just as much

A good penetration test should leave you with more than a 97-page PDF containing enough technical terminology to frighten everyone at the next management meeting.

Findings should be understandable, prioritized and actionable.

Which vulnerabilities represent the greatest risk?

What was actually exploitable?

What systems were affected?

What should be fixed first?

And how should it be fixed?

That's where remediation becomes just as important as testing.

The bottom line

Cybersecurity tools are essential, but ultimately organizations need a way to validate whether all those layers of protection actually accomplish what they're supposed to.

Penetration testing provides that reality check.

Through our penetration testing partnership with Red Sentry, Consultation AmaltiTEK can help organizations conduct independent penetration testing of their environments, review and understand the findings, prioritize identified risks, and implement the remediation required afterward.

Because when it comes to cybersecurity, "Nobody has hacked us yet" isn't quite the same thing as "They can't."

Stephen Tzintzis

Sep 17, 2026

Why Choose Us

Partner with us for reliable, expert-driven IT support that delivers:

  • Proactive, 24/7 Monitoring
  • Certified Experts (Cisco, Microsoft, Fortinet)
  • Personalized Support — No Tier-1 Runaround
  • Scalable Solutions, Local Presence in both
    Canada and the USA