GetPentest

Are you ready to be penetration tested?

The first two days of a badly prepared engagement are spent waiting for credentials. You paid for those days. Seven questions, then a readiness verdict and the blockers to clear before the tester starts.

Last reviewed 2026-09-14Written by Jacob Masse, TrazTech Inc.

A penetration test is bought in days and delivered in days. Anything that stops the tester working burns those days at the same rate as the testing does, and the tester cannot give them back at the end. The usual pattern is a Monday start, an account that does not work, a firewall silently dropping the traffic, and testing beginning in earnest on Wednesday afternoon.

This checks the seven things that cause that. The verdict appears on this page. Nothing is emailed anywhere unless you ask for it at the end.

Which environment will be tested, and does it exist now?

Testing production finds real problems and carries real risk. Testing a stripped staging copy is safe and often measures something you do not ship.

What test accounts can you hand over on day one?

Two accounts in the same role is what makes access between equals testable. One account per role only proves what a role can do, never what it should not reach.

Is there data in those accounts?

An empty account has no records to reach, no workflows to complete, and nothing for a second account to try to see.

How will rate limiting and the web application firewall be handled?

A tester blocked at the edge measures your edge, not your application. Whichever way you decide, decide it before day one and write it in the rules of engagement.

Is the scope written down?

Are the rules of engagement signed?

Test windows, permitted techniques, emergency stop and the authorization to test systems you do not own.

Who is the point of contact during the window?

How long is the testing window?

What unreadiness actually costs

Canadian tester days sit at roughly $1,500 to $2,800 CAD, so half a day lost to a broken account is $750 to $1,400 of testing you paid for and did not receive. On a five-day engagement, losing the first day and a half removes thirty percent of the coverage, and it removes it from the deep end, because the work that gets cut is always the last thing on the plan rather than the first.

The loss does not show up on the invoice. It shows up as a report that covers the login page thoroughly and the permissions model barely, and nobody in the room ever connects that to the credentials that arrived on Tuesday.

The account question is the one that matters

Most serious application findings are authorization failures: a user reaching a record that belongs to somebody else, a role performing an action reserved for another role, a tenant seeing across the boundary. Testing any of that requires at least two accounts at the same privilege level, each holding data the other should not see. One account per role is the single most common gap, and it quietly removes the most valuable class of finding from the engagement.

Seeded data matters for the same reason. Two empty accounts prove nothing, because there is nothing in either one to reach. Put realistic records, files and completed workflows in both before the tester logs in. More on getting the scope right in how to write a penetration test scope.

Common questions

Should we allowlist the tester at the firewall?

Usually yes, for the application test, and then measure the edge separately. A blocked tester produces a report about your filtering rules rather than your software, and an attacker with time will work around filtering that a tester on a five-day clock will not. Whichever way you decide, write it in the rules of engagement so nobody changes it mid window. See rules of engagement.

Is staging good enough?

Staging built from the same pipeline and the same configuration is fine and much safer. Staging with debug settings, different authentication or missing integrations produces findings you cannot act on and misses the ones you have. If the two differ, list the differences and give the list to the tester on day one.

How much notice does the point of contact need?

Enough to have cleared their week. The role is not ceremonial: accounts break, a test user gets locked out, an alert fires at two in the morning and somebody has to say whether it was the tester. A contact who is answering in an hour turns a lost day into a lost twenty minutes.

Do we need to tell our cloud provider?

Check the current terms for the provider you use. Most major platforms now permit customer testing of your own workloads without a form, and all of them draw a line around shared infrastructure, denial of service testing and anything touching other tenants. Whoever signs the rules of engagement should confirm it in writing rather than from memory.

We are not ready and the date is booked. Now what?

Move the date if the gaps are accounts, data or environment, because those three decide what the test can find. Keep the date if the gaps are paperwork, and clear them in the first hour. A firm that will not move a date a week when told the environment is not up is telling you how the rest of the engagement will go.