gshc2020.com

Council Post: Penetration Testing Only Works When It's Scoped To Business Risk

tags:
@ 04/09/2026

Michelle Drolet is CEO of Towerwall, a specialized cybersecurity firm focused on proactive cyber preparedness and compliance services.

getty

Penetration testing is on its way to being worth $2.72 billion in 2026 and reach $5.54 billion within the next five years. Key drivers of this growth include rapid cloud adoption, AI-driven exploits and tightening regulatory deadlines. Serious money is being spent by organizations on both manual and automated penetration testing, which delivers insight on the state of a company’s cybersecurity posture.

A penetration test is a simulated cyberattack, run by ethical hackers, that shows where a company’s real-world defenses would actually fail. And although a pen test can inspire a degree of confidence in safety, data breaches may still occur and new vulnerabilities are introduced daily.

Vulnerability exploitation is behind some 31% of breaches. Most likely, this figure will increase as attackers’ malicious use of AI grows to exploit weaknesses before defenders can patch them. Pen testing remains one of the most effective forms of mitigation, but only if testing is scoped to reflect how the business actually operates.

Scope For Business Impact, Not Just IT Assets

Many organizations think too narrowly when scoping a pen test. It either revolves around their website, a business-critical application or a specific system compliance that needs to be checked. Unfortunately for them, attackers go after whatever is connected to the target. This may include a vendor’s API, a third-party integration or a tool a department deployed without IT authorization.​

Scoping a pen test shouldn’t begin with the question, “What systems do we own?” The right question should be, “What would actually hurt the business if a system failed?” This ‘hurt’ can take the form of data exfiltration, lost revenue, regulatory penalties and broken customer trust. The kind of information leadership must worry about.​

Four Questions To Define Your Scope​

Effective penetration test scoping requires addressing four critical questions regarding asset location, data prioritization, compliance scope and historical threat patterns. These key areas, including security frameworks and industry history, ensure that the assessment focuses on the most critical vulnerabilities.​

1. Where Do Assets Reside?​

Your organization may have a larger IT footprint than you realize. This can include in-house servers, cloud workloads and third-party tools that increase in number as the business grows. Data breaches tend to start in a corner of the IT ecosystem that hasn’t been well scoped.​

2. What Data Matters Most?

Data has an importance hierarchy: Financial records, intellectual property and personal health information (PHI) carry more risk than routine operational data. This essentially means that not every system demands the same level of scrutiny. If you don’t prioritize scrutiny, you might have to battle a lot of white noise that has the potential to overshadow the findings that matter most.​

3. Is Compliance The Beginning Or The End?

When it comes to scoping systems for weaknesses, compliance and security frameworks like PCI DSS, HIPAA and GLBA represent a baseline (not the ceiling). For instance, a retailer can pass a PCI DSS audit by locking down the POS system and still leave a loyalty-rewards app storing the same credit card data untested, simply because the audit never considered it.

4. What Does History Show?

According to the FBI’s Internet Crime Complaint Center, over $20 billion in losses were reported last year, with healthcare ranking as the most targeted critical infrastructure sector for ransomware attacks, followed by manufacturing, financial services and IT. This information should be considered when scoping. Supply chain dependencies, operational technology and recovery time for production systems, among other things, should fall within the scope.

Aligning The Test To The Risk

The right scope ensures the right mix of pen testing. External testing looks at what is exposed to the internet, including firewalls, Wi-Fi, web apps and APIs. Internal testing assumes the attacker is inside the network and measures how far an attacker can move laterally through the system to gain administrative control or escalate access privileges. Considering the growing cloud infrastructure and the shared responsibility model with cloud providers, cloud assessments will check a configuration against industry standards such as CIS benchmarks. Wireless testing takes a look across wireless networks, catching weak encryption and rogue access points.

Software carries its own exposure, too. Application testing digs into custom or third-party code for injection flaws, broken authentication or excessive access. With AI-tool sprawl, AI and agent testing has emerged as the newest category, probing how these systems handle manipulation, unauthorized data access and prompt injection. Tying it together, red or purple team exercises simulate a sustained, realistic attack, testing not just technical defenses, but how a security team actually detects and responds to incidents in real time.

Testing Is A Strategic Decision

The objective behind pen testing should ensure that leadership uncovers its high-priority cybersecurity risks. Test what will genuinely disrupt and harm the business and prioritize. This is both a business and a technical decision. If your pen test proves negative but the reasons outlined in the report findings are not clear, your instinct should trigger suspicion. Check to determine what was excluded from the scope. This is the area where risk might have been sitting undetected all along.

In Summary

Penetration testing is most effective when it is customized/tailored to reflect how the business actually operates and where the greatest consequences of failure lie. If the scope is too narrow, the results may offer reassurance without revealing the exposures that matter most. In the end, the value of a pen test is not simply that it was conducted, but that it was designed to uncover risks that leadership can’t afford to miss.​​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?