Let's Cut Through the Jargon
"Penetration testing." It sounds expensive. Probably something that only banks and large enterprises worry about. Something involving people in hoodies staring at terminal windows.
In reality, the concept is straightforward — and understanding it helps you make better decisions about your own website security.
This guide explains what penetration testing actually is, what it doesn't cover, and how to figure out whether your business needs it.
What Is a Penetration Test?
A penetration test (or pentest) is a controlled, authorised attempt to find and exploit security vulnerabilities in a system before an attacker does.
The key word is *authorised*. A pentest is performed with explicit permission from the system's owner. The tester uses the same techniques an attacker would — but the goal is to expose weaknesses and provide a report, not to cause damage.
Penetration testing has existed as a formal discipline since the 1960s and has grown into a multi-billion pound industry. Today it covers web applications, mobile apps, network infrastructure, APIs, cloud environments, physical access controls, and social engineering.
For most small and medium UK businesses, **web application penetration testing** is the most relevant category: assessing the security of your website, online store, customer portal, or API.
Manual Penetration Testing vs Automated Security Scanning
These two terms get conflated constantly. They're different things.
Manual Penetration Testing
A human security professional — or a team — manually probes your application. They think creatively, chain vulnerabilities together, test business logic, and look for issues that automated tools miss: privilege escalation through complex workflows, authentication bypasses that require understanding the application's intent, multi-step attack chains.
**Strengths:** Deep, creative, context-aware. Can find complex vulnerabilities. **Weaknesses:** Expensive (£3,000–£15,000+ for a web application), time-consuming (typically 2–5 days), not repeatable without re-engagement, and quality varies significantly between testers and firms.
Automated Security Scanning
Software performs a large number of structured checks against your website automatically. Modern scanners test for hundreds of known vulnerability classes, misconfigurations, and security weaknesses across your attack surface.
**Strengths:** Fast, affordable, consistent, repeatable. Covers the vast majority of common vulnerabilities. Can be run regularly. **Weaknesses:** Cannot replicate the creative reasoning of a skilled human tester. May miss complex business-logic flaws. Requires thoughtful interpretation of results.
**The honest answer:** Most small businesses don't need a full manual penetration test right now. They need good automated scanning — run regularly — to catch the common vulnerabilities that account for the majority of real-world breaches. Manual testing becomes appropriate when you're handling sensitive data at scale, operating in a regulated industry, or preparing for a significant transaction.
What Does a Web Application Pentest Actually Test?
Whether manual or automated, a web application security assessment typically covers:
**Injection attacks** — SQL injection, NoSQL injection, command injection, Server-Side Template Injection (SSTI). These vulnerabilities allow attackers to interfere with your application's backend queries and commands.
**Cross-Site Scripting (XSS)** — Injecting malicious scripts into your pages that execute in visitors' browsers. Can be used to steal session cookies, redirect users, or perform actions on their behalf.
**Authentication and session management** — Weak passwords, broken login flows, session tokens that don't expire, missing multi-factor authentication options.
**Broken access controls** — Can a regular user access admin functions? Can User A view User B's data? Insecure Direct Object Reference (IDOR) vulnerabilities fall here.
**Security misconfiguration** — Missing security headers, default credentials left in place, unnecessary services exposed, verbose error messages revealing internal details.
**SSL/TLS weaknesses** — Outdated protocols, weak cipher suites, expired certificates.
**Server-Side Request Forgery (SSRF)** — Tricking your server into making requests to internal systems or external services on an attacker's behalf.
**API security** — GraphQL introspection, unauthenticated endpoints, missing rate limiting on sensitive operations.
**Information disclosure** — Error messages, stack traces, server banners, or other responses that reveal information useful to an attacker.
Do You Actually Need a Penetration Test?
Here's a direct framework:
**You definitely need regular automated scanning if:** - You have a website that collects any user data (contact forms, accounts, orders) - You run an e-commerce store - You have a customer-facing application or portal - You've never had your site security-tested - Your site has changed significantly since it was last tested
**You should consider a manual penetration test if:** - You're handling financial data, health data, or other sensitive personal data at scale - You're in a regulated industry (financial services, healthcare, legal) - You're seeking a security certification (Cyber Essentials Plus, ISO 27001, SOC 2) - A client or partner is requiring one contractually - You're preparing for a significant transaction or funding round
**The most common mistake:** Businesses assume they don't need either until something goes wrong. By that point, the cost of a breach — remediation, downtime, customer notification, ICO investigation — dwarfs what testing would have cost.
What Comes Out of a Penetration Test?
A professional security assessment produces a report. That report should contain:
- **Executive summary** — the overall security posture in plain language - **Finding details** — each vulnerability with its severity, evidence, and reproduction steps - **Risk classification** — critical, high, medium, low, informational - **Remediation guidance** — specific steps to fix each finding - **Assessment coverage** — what was tested and what was out of scope - **Passed controls** — what's working correctly
This document is your evidence of due diligence. It can be shared with your development team, your board, your insurer, or a client requiring proof of security testing.
What Yrzo AI Provides
Yrzo AI is an automated web security scanner that performs 44 checks across your website and produces a formal PDF Security Assessment Report.
It's designed for businesses that want professional-grade security testing — real findings with real evidence — without the cost or timeline of a manual engagement.
Each report includes a formal cover page with assessment ID and date, an executive summary of findings, full finding detail with evidence, severity, and remediation, assessment coverage and passed controls, not-applicable tests clearly explained, and methodology and scope.
The £399 scan covers comprehensive automated testing. For businesses needing deeper analysis — extended subdomain enumeration, deeper JavaScript analysis, multi-stage vulnerability validation, and attack-chain analysis — the premium tier goes further.
Start With a Scan
You don't need to decide between a £400 automated scan and a £10,000 manual engagement right now. Start with understanding where you stand.
A scan of your website tells you your current security posture in minutes. If the results are clean, you have confidence. If they surface issues, you have a prioritised list to act on — and documentation of your due diligence.
[Run your security assessment at yrzoai.dev →](https://yrzoai.dev)
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →