Penetration testing services
Cloud Bilişim provides penetration testing for business networks and web applications in Türkiye. Testing requires written authorisation, agreed targets and a defined scope; findings are documented so your team can prioritise remediation and agree any retesting.
What must be agreed before penetration testing starts?
Written authorisation should define the targets, testing window, exclusions and escalation contacts. Agree reporting, evidence handling, remediation responsibilities and whether retesting is included.
How do security assessment approaches differ?
| Approach | Purpose | Typical output |
|---|---|---|
| Vulnerability scanning | Identify potential weaknesses using scanning tools. | A list of findings that needs review and prioritisation. |
| Penetration testing | Assess exploitability within an authorised scope. | Validated findings, evidence and remediation guidance. |
Related services and next steps
Business firewall solutions, 5651 logging and KVKK-aware data handling, Contact Cloud Bilişim.
What is Penetration Testing?
Penetration testing (commonly called pen testing) is the process of attempting to attack an organisation’s systems with written permission and in a controlled manner to determine through which vulnerabilities an actual attacker could gain access. The goal is not to cause harm, but to identify points that could be exploited before an attacker gets in.
Most organisations, after making security investments, are left with a question: Does it really work? The firewall has been established, antivirus has been deployed, backups are being taken. But how this setup looks from the outside and whether a vulnerability can actually be exploited cannot be known until it is tested.
Penetration testing is the answer to this question. It turns assumptions into measurements: instead of ‘this port should have been closed,’ it says ‘this port was open and the management panel was accessed from here.’
As Cloud Bilişim, we conduct tests with the scope defined in writing, limitations discussed beforehand, and findings carried out in a proven manner.
Vulnerability Scanning and Penetration Testing Are Not the Same Thing
Vulnerability scanning is done with an automated tool and possible lists the vulnerabilities. This list often includes findings that cannot actually be exploited. In a penetration test, the expert proves that the identified vulnerability can actually be exploited and shows how far it can be taken.
In short: scanning lists the suspects, the test tells which one is actually dangerous.
Difference Between Vulnerability Scanning and Penetration Testing
| Topic | Vulnerability scanning | Penetration testing |
|---|---|---|
| Who does it | Automated tool | Expert, with tool support |
| Output | List of potential vulnerabilities | Proven vulnerabilities and reached points |
| False positive | Frequently seen | Reported by being eliminated |
| Chained risks | Cannot see | Shows the combination of small vulnerabilities |
| Business impact | Technical scoring | It is said ‘This vulnerability allows access to this data’ |
| Time and cost | Short, low | Longer, higher |
| Frequency | Regular, frequent | Once a year and for significant changes |
Black Box, Grey Box, White Box
Determines what the test team was informed and what the test measures. As information decreases, realism increases; as information increases, coverage deepens and time is used more efficiently.
How Is a Penetration Test Conducted?
The process begins with written permission and is closed with a retest after corrections. Each closed cycle raises the starting point for the next test.
What Is Included in the Test Scope?
- External Network Test
Internet-facing servers, firewall rules, remote access services, and email infrastructure are tested from the outside. - Internal Network Test
It is measured how far an attacker connected to the network can go: privilege escalation, lateral movement, access to servers. - Web Application Test
The application layer is examined, focusing on authentication, authorisation controls, data entry points, and session management. - Wireless Network Test
The encryption configuration of the wireless network, guest network isolation, and rogue access point risks are audited.
- Social Engineering
If requested, user awareness is measured through controlled phishing scenarios; results are reported collectively, not individually. - Configuration Audit
Server, firewall, and directory service configurations are compared with best practice examples. - Reporting
An executive summary and technical report are prepared; each finding is written with evidence, impact, and recommended remediation. - Retest
After repairs are completed, previously closed vulnerabilities are retested and verified as closed.
What Do You Get at the End of the Test?
The report is two-tiered: simple for management executive summary, detailed for the technical team technical appendix. Each finding is written along with its degree of importance, evidence, impact on work, and suggested correction.
Findings are ranked from critical to low; the report directly turns into a work list.
Authorisation is required. Penetration testing is conducted only with the written permission of the system owner; performing the same action without permission is a crime. Before the test, the scope, methods to be used, time interval, and communication channels are determined in writing, and the scope is not exceeded. All findings obtained are shared only with your institution under a confidentiality agreement.
How should a penetration test proposal and delivery report be evaluated?
Before requesting a proposal, identify the IP addresses, applications, user roles, and systems to be excluded from testing. For third-party infrastructures, required permissions, the testing time window, and the contact person who will stop the work in case of an emergency should be documented in writing.
A penetration test, in which findings are verified and their impact evaluated through automated vulnerability scanning, does not fall under the same scope. In the delivery report, request that the finding’s impact, priority, affected asset, and actionable remediation recommendation be included.
The price is influenced by the target number, identity-authenticated scenarios, the complexity of workflows, and the scope of retesting. Clarify in the contract whether post-fix verification is included, who the report will be shared with, and how test data will be protected and deleted.
Frequently Asked Questions
A penetration test is the process of testing an institution’s systems with written permission and in a controlled manner to determine which vulnerabilities a real attacker could exploit. The goal is not to cause damage, but to identify points that could be exploited before an attacker can enter.
Vulnerability scanning is performed with an automated tool and produces a list of potential vulnerabilities; this list may also include findings that cannot actually be exploited. In a penetration test, however, an expert proves that the discovered vulnerability can actually be exploited and shows how far it can be leveraged. Scanning lists suspects, testing tells which ones are really dangerous.
In black box testing, the team is given no information and a real external attacker is simulated. In gray box testing, a standard user account and a general network diagram are provided; an internal attacker or a malicious employee is simulated. In white box testing, full information including architecture and source code is provided; it ensures the most comprehensive audit and uses time most efficiently.
The scope and limitations are determined in writing before the test. Methods that could cause service interruptions are either excluded from the scope or applied during off-hours, with prior notice. Preferably, a test environment is used for critical systems.
The duration is determined by the scope: the number of IPs and applications to be tested, the chosen box type, and whether the internal network is included are decisive. While a small-scale external network test may take a few days, a study covering both the internal network and web applications can extend over several weeks.
The general approach is to have a test conducted at least once a year. In addition, the test should be repeated when a new system is deployed, a significant change is made to the infrastructure, or a new application goes live. Penetration testing is not a one-time task; it is a loop that closes with remediation and retesting.
A simple executive summary for management and a detailed technical report for the technical team are delivered. Each finding is documented with its severity, evidence, impact on the business, and remediation recommendation. Findings are ranked from critical to low, so the report can directly become a task list.
A penetration test is performed only with the written permission of the system owner. Performing the same action without permission is a crime. Before the test, the scope, methods, time frame, and communication channels are determined in writing; the scope is not exceeded. The findings are shared only with the organisation under a confidentiality agreement.
After the Test: Our Services That Close Findings
A penetration test tells what is missing; the main job is to close the findings. For findings at network entry Business firewall solutions, for findings at endpoints AI-based antivirus programs, for guest and wireless network findings hotspot solutions and 5651 logging solutions, and against data loss risk cloud backup our services come into play. To prioritize the findings according to your industry industry-specific cybersecurity solutions .
Let’s Determine the Scope Together
The correct result of the test depends on the proper establishment of the scope. We determine together which systems will be tested, which methods will be used, and which constraints will apply, and then we start working with written permission.
For scope discussion you can contact us.