We would also be happy to consult with you in person if you have specific questions about penetration testing for your company

Nikolas Rösener
Security Expert
- cyber-security@ohb-ds.de
- 0421220950
The world is becoming increasingly interconnected, and no business can function without the internet. That’s why IT security affects every single business today. But every business is different and, as a result, has different requirements and needs when it comes to its own IT security. Penetration testing can help identify and address security vulnerabilities within a company. But what exactly is a penetration test, and which type of penetration test is the right one?
A penetration test is a security test in which a so-called “penetration tester” attempts to gain unauthorized access to, for example, a computer system or a network in order to assess its security and identify any potential vulnerabilities. Companies often conduct this test to ensure that their systems and networks are protected against external attacks. During a penetration test, various techniques and tools are also used to assess the system’s security for potential vulnerabilities and to improve it where necessary.
The differenttypes of penetration testsare classified as black box, white box, or gray box. But how can this classification help you choose the right penetration test?
The type of penetration test selected determines certain outcomes. Depending on which scenario is chosen, the scope and outcome of the penetration test are already defined. Other factors that influence the choice of penetration test include economic benefits (effort, costs) and the realism of the scenarios. The goal should be to optimize both.
In these scenarios:
The penetration testers have no inside information or prior knowledge of the company
simulates a scenario in which unknown external actors attempt to breach the company's IT infrastructure
While the focus is on obvious problems, vulnerabilities can easily be overlooked—such as the intern scenario (internal threats)

In these scenarios:
The hackers have extensive knowledge of the company’s IT infrastructure and may even be or have been part of the company (staff)
With a comprehensive view of all systems, even the most obscure vulnerabilities can be identified
However, the results of penetration tests and the prioritization of IT vulnerabilities often bear little relation to actual threats, and penetration testers may increasingly lose their “objective perspective” in the future

In these scenarios:
In some cases, the penetration testers have insights into and prior knowledge of the company
Scenarios can be simulated in which, just as is often the case in reality, no clear distinction can be drawn between internal and external threats

In addition to classifying penetration tests into white-box, black-box, and gray-box scenarios, there are other types and terms that we would like to discuss in the following section—for the sake of completeness.

Anexternal penetration test(also known as an external pentest) is a security test in which the pentester attempts to gain unauthorized access to a company’s network and systems from outside the organization. The counterpart is theinternal penetration test, in which the attack is simulated by an insider. Internal penetration tests are frequently used, for example, when the goal is to gain access to an employee’s email account (phishing attack).
Ablind penetration test(also known as a closed-box penetration test) is a type of security test in which the testers have no information whatsoever about the system or network being tested. They begin thetest without any prior knowledgeand attempt to uncover potential vulnerabilities and security gaps. This type of penetration test can be considered more realistic, as in real life it is possible that attackers have no information about the target and must therefore find a way to infiltrate the system.
A DoS (Denial of Service) test is a security test that attempts to overload a target system by bombarding it with a large number of requests. The purpose of this test isto assessthesystem’s stability and robustnessand determine how it responds to such a load.
Anetwork penetration testis a security assessment designed to identify potential vulnerabilities and security gaps in a network infrastructure. During the process, theentire internal infrastructureis evaluated, checked for security risks, and a plan of action is developed to address any identified security gaps. A network penetration test is suitable for companies of all sizes, as nearly all companies today work with sensitive data and process or transmit it via their internal network, for example.
Anapplication penetration test(sometimes referred to as an app pentest or simply an app test) is a type of security test designed to identify any vulnerabilities and security risks that may exist in an application (such as a computer program or a mobile app).
These tests are conducted by experts who attempt to attack the system in the same way a hacker would (also known as “ethical hacking”). The goal is to verify the application’s security and ensure that it has no vulnerabilities that could be exploited by hackers. Unlike other types of penetration tests, which focus on the entire network or system, an application penetration test specifically targets individual applications and attempts to identify and fix vulnerabilities in those applications.
Social engineering is a specific type of attack in which attackers attemptto obtain confidential information from people by persuading them to voluntarily grant access to such information. This can happen in various ways, for example, by posing as trustworthy individuals (such as a company employee or a service provider) and thereby convincing victims to disclose confidential information such as passwords or login credentials. In social engineering, attackers generally do not require technical skills. Instead, they use their skills in psychology and social influence to deceive victims and extract confidential information from them.
This can also happen indirectly through phishing attacks, among other means, which is why so-calledphishing simulationsare frequently used in penetration testing. Employees should also be made aware of such attacks through regularawareness training.
In addition to the types of penetration tests mentioned above, there are countless other classifications. These include cloud penetration testing, client penetration testing, and red teaming. We would be happy to provide you with personalized advice on how to effectively utilize penetration tests for your business.
Defining a clear objective isessential for the success of the penetration testand also makes sense from a time and cost perspective. You need to consider what you want to achieve with the penetration test. The objective can range from “simply identifying vulnerabilities” to “determining where the most significant business-critical issues lie within the company.” Is the priority on protecting sensitive data from unauthorized parties, preventing operational downtime caused by cyberattacks, or is the focus oncompliance with legal obligationsor quality management?
In fact, it is often worthwhile not only to choose a single scenario from one of the three categories, but also to consider the possibilities offered by scenarios in the other two categories. For example, selecting a pure black-box scenario carries the risk of failing to identify internal sources of risk. In many companies, these scenarios reveal problems that are actually quite obvious. New interns or student workers in the company often gain access to all of the company’s sensitive data unintentionally or unknowingly. Another common risk is a lack ofawareness among employees regarding password security. However, such scenarios are often not considered in black-box penetration tests. A carefully chosen scenario that strikes a realistic balance between black-box and white-box testing can reveal both in this case. It therefore always makes sense to select both a black-box penetration test scenario and asocial engineering penetration test.
In most cases, testing a company’s entire IT infrastructure and conducting every possible type of penetration test is too time-consuming and often too costly. That is why it is helpful to assess in advance which area is most vulnerable and where the greatest damage to the company could be inflicted. Once a careful decision has been made regarding a suitable penetration test, ideally 20% of the testing effort can cover 80% of the security vulnerabilities, in accordance with the Pareto principle.
Penetration testing and vulnerability assessments are two different types of security testing, both of which are used to identify vulnerabilities in a system or, for example, in a network environment. The main difference between the two approaches is thatpenetration tests actually attempt to access these vulnerabilities and exploit them in a targeted manner to determine whether they actually pose a security risk, whereasvulnerability assessments are limited to simply identifying vulnerabilities.
Penetration tests are typically conducted by security professionals (known as pentesters), who attempt to attack the system in the same way a hacker would, whereas vulnerability assessments are often performed by internal IT teams that regularly monitor the system and identify and address vulnerabilities. In general, penetration tests offer a higher level of security because they actively attempt to exploit vulnerabilities to determine whether they pose a security risk.
If the penetration test has been conducted by the contracted penetration testers with the right objectives and scenarios, you will receive a list of vulnerabilities. However, this list alone does not solve a single problem, nor does it provide any advice. To respond effectively to vulnerabilities in the company’s IT infrastructure, they must first beprioritized, as it is obviously impossible to fix all problems at once. To do this, risks that are frequent and have a significant impact should be prioritized (e.g., using the Eisenhower Matrix). A well-designed penetration test can largely provide this prioritization. The goal should be to address the most realistic, costly, and damaging scenarios for the company first. Therefore, one must consider which areas of the company are vulnerable, which of these are particularly critical, and become aware of the serious dangers and risks to which the company is exposed. To this end, it is essential to understand one’s own requirements.
The most important thing, however, is to act on the results of the penetration test and take proactive steps. If I remain passive after the penetration test and make no changes within the company to improve IT security and address our own vulnerabilities, then even the most comprehensive and costly penetration test will be ineffective.
Leverage space technology for your business. OHB Digital Services GmbH has been a trusted partner for secure and innovative IT solutions for many years. We are part of one of Europe’s most successful space and technology companies. With our products and services, we can help you digitize your business processes across the value chain and address all security-related issues.Feel free to contact us.

You are currently viewing placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will result in data being shared with third-party providers.
More InformationYou are currently viewing placeholder content from YouTube. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will result in data being shared with third-party providers.
More InformationYou are currently viewing a placeholder content from reCAPTCHA. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from hCaptcha to submit the form. Please note that doing so will result in data being shared with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will result in data being shared with third-party providers.
More InformationYou are currently viewing placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will result in data being shared with third-party providers.
More Information