Knowledge Base
Engineer Login
Back to Knowledge Base

Penetration Test Preparation and Remediation

Security & antivirus penetration test pen test security assessment remediation By Cade · Updated 03/05/26 07:51 AM
A penetration test (pen test) simulates a real attacker to identify exploitable vulnerabilities before actual attackers do. For most SMBs, an annual external pen test (testing internet-facing systems) and a periodic internal test are appropriate. Some compliance frameworks (PCI DSS) require annual pen testing. Preparing for a pen test: provide the testing firm with a clear scope document — IP ranges, systems, and any out-of-scope restrictions. Notify your internet service provider and hosting provider to avoid triggering abuse complaints from the test traffic. Brief internal IT staff so they don't respond to the test as a real incident (coordinate with the tester on escalation procedures). Receiving the report: pen test reports categorize findings by severity (Critical/High/Medium/Low/Informational). Prioritize remediation: address Critical and High findings within 30 days — these are actively exploitable. Medium findings within 90 days. Low within 6 months. For each finding, the report provides a recommendation — follow it or discuss an acceptable compensating control with the testing firm. Retest Critical/High findings after remediation to confirm they're resolved.