Your Penetration Testing Is Incomplete (Especially If You're Small)
John Sabo 6 min read
A penetration test is a simulation of an attacker against a defined target. The operative words are "defined target." If the target is wrong, the test can pass with flying colors and still leave your business wide open.
I have read a lot of small-business penetration test reports. The pattern is consistent: one website, one week of testing, a long list of findings, and no coverage of the places where small companies actually get breached. Here is what is usually missing.
1. Misconfiguration
Most real breaches I see on small business systems are not clever exploits. They are settings left at their defaults.
That includes a staging copy of your site that still has the same admin password it shipped with. It includes a web server that lists the contents of a folder instead of refusing. It includes an error page that prints the full file path of your web root. It includes a backup file sitting in the web directory with a name like backup.zip.
None of that is a software vulnerability, which is exactly why a scanner-driven test will miss it. Configuration review is a human task, and it has to be in the scope or it does not happen.
2. Exposed panels
If you can reach a login page from a coffee shop, so can anyone else. Small businesses tend to have more of these than they think: a firewall management page, a remote desktop service, a virtual private network login, a network storage console, cameras, printers, and the admin panel of whatever runs the phones.
A proper test asks two questions about every one of them. Is this supposed to be reachable from the open internet? And if it is, does it hold up to a focused login attempt?
Many small businesses discover the answer is no and never meant it to be exposed in the first place.
3. People
Most attackers do not break the website. They log in.
That is why a penetration test that never touches your email and your staff is only testing the least likely path in. A phishing simulation sends a harmless message that looks like a realistic one and records who clicks, who enters credentials, and who reports it. The reporting rate is the number to watch, because the person who reports it is the control that works.
I offer a flat-rate phishing simulation as part of an engagement. It is the single fastest way to find out whether your security awareness training is real or decorative.
4. Domain Name System and email authentication
The Domain Name System, usually called DNS, is the phone book of the internet. It decides where your email goes and who is allowed to send it on your behalf.
If your DNS is misconfigured, someone can send mail that appears to come from your domain. Three records control that: Sender Policy Framework, DomainKeys Identified Mail, and Domain-based Message Authentication, Reporting and Conformance. In plain terms, they tell the world which servers may send your mail and what to do with mail that claims to be yours but is not.
Two more DNS items belong in any test. Look for subdomains that point at services you no longer use, because those can be claimed by someone else. Look for domains that look like yours, because those get used against your customers.
None of these are exotic. All of them are missing from a typical small-business report.
Why the test ends up narrow
It is rarely laziness. Scope usually gets set by budget rather than by risk. A small business buys the test it can afford, the tester covers the target in the statement of work, and everyone signs off.
The fix is not a bigger test. The fix is a smarter one. Spend the effort on the four areas above and a modest engagement will tell you more than a two-week scan of a website that was never the soft spot.
What to ask for
When you buy a test, ask for four things in writing:
- A scope that names the systems, the people, and the DNS assets covered.
- A finding list sorted by what an attacker would reach first, not by tool severity score.
- A written re-test after you fix things. A finding that was never re-tested is a finding you are guessing about.
- A short list of the things you can fix this month without hiring anyone.
That last item matters more than the page count. A report you can act on is worth ten reports you file away.
One caution from experience: fix the findings in the order of reachability, not in the order they appear. Small businesses often patch the hardest item first because it looks impressive, while the exposed admin panel stays open the whole time.
Ties into everything else
Penetration testing is one of the six services I offer. It is also the one that most often turns up something that belongs to another service. A misconfigured website is a hardening job. A successful phishing test is a training and automation job. A lookalike domain is an intelligence job.
I would rather tell you that than sell you a second test.
Work with me
Every engagement starts with a free 30-minute consult and ends with a written quote. You will know what I would test, what it would cost, and what I would leave alone. No obligation.
Book a free 30-minute consult at /book, or call 602.501.0772. I answer the phone.
John Sabo — Lono Security Chandler, Arizona · Phoenix Metro · Remote everywhere
John Sabo
John Sabo — 30 years in cybersecurity, GoDaddy WAF architect
Work with me
Every engagement starts with a free 30-minute consult and ends with a written quote.
Book a free consult