What a penetration test actually is
A penetration test is a controlled attempt to compromise a system, run by people using the methods a real attacker would. It differs from a vulnerability scan in one important way: a scan lists weaknesses that might be exploitable, a test establishes whether they are, and what an attacker reaches once they are through.
What a useful test tells the board
Not a list of findings sorted by CVSS score, which is what a scan produces. A useful test answers a question the business cares about: could someone outside reach customer data, could a compromised laptop reach the finance system, could a junior account escalate to administrator. Scoping around those questions produces a report the board can act on.
How CLA Emirates scopes and runs tests
We agree the objective and the rules of engagement in writing before anything starts, including what is out of scope and who is informed. Testing is evidenced throughout so every finding can be reproduced. The report separates what was proven from what was observed, ranks by business impact rather than technical severity alone, and includes a retest of remediated findings so closure is verified rather than asserted.
The testing we perform for clients
- External and internal network testing
- Web and mobile application testing
- API security testing
- Configuration and cloud review
- Red team and social engineering
- Remediation retesting
