Pensure
Plan a test

Resources

Make the next security conversation easier.

Practical material for US small and mid-sized businesses planning a penetration test, explaining exposure and preparing evidence for customers, tenders, insurers and audits.

Frequently asked questions

Answers before you plan a test.

Practical answers about scope, testing safeguards, reporting and data handling.

What is the process?

The process starts with you providing a URL or domain name. We will confirm the target and environment, then schedule a testing window. Once testing begins, we will work through the agreed scope and provide a report with findings and recommendations. To get started, click Plan a test.

How much does a test cost?

You can see more about plans and pricing here.

Can you test my application or API?

Yes. The launch flow starts with one public HTTPS target and can record website, API and authentication coverage decisions. Broader or more complex scope can be discussed through the same Plan a test process.

Do you need passwords or credentials?

We can do a black-box test with no credentials, or a grey-box test with credentials that you provide. For a more comprehensive assessment, it is recommended to test with user credentials.

Can the test run in production?

We strongly recommend testing on a non-production environment, however production can be considered where the target, authorisation, safeguards and testing window are appropriate. The target and environment are confirmed before testing begins.

What does penetration testing help with?

Penetration testing helps identify exploitable weaknesses in the agreed target so your team can reduce exposure. It does not prevent every cyber incident, and it is one part of a broader security programme.

Pensure resources

Technical guide

Testing past the WAF without dropping your guard

Use the platform runbooks for Vercel, Cloudflare, Akamai and AWS WAF to create a narrow, temporary path for authorised testing.

Open the WAF runbooks

Planning guide

Start with the target that matters

A short guide to choosing the right application, API or digital asset for a first penetration test.

Read the scoping guide

Buyer guide

What to ask for in a penetration-test report

Use the report output, evidence and remediation context to compare what different testing offers actually provide.

Read the report guide

Trust and data

Understand the testing boundary

Review how Pensure approaches data handling, authorised scope and the information needed before testing begins.

Read Trust & Data

First-time buyer guide

“Go get a pen test.” Now what?

Turn an urgent request from a customer, insurer or procurement team into a clear and controlled plan.

Read the buyer guide

Buyer guide

Vulnerability scan or penetration test?

Understand what each approach does well, where the difference matters and when you may need both.

Compare the approaches

Official resource · United States

Verizon 2026 DBIR

Current government or national cyber security evidence for US small and mid-sized businesses.

Open Verizon 2026 DBIR