Skip to main content

CEIS, centro de ensayos Innovación y servicios

Contact us
This field is required
This field is required, enter a valid email
This field is required
This field is required
This field is required

Penetration Testing: What should your business test first?

08-10-2026 Cybersecurity | Pentesting

Find out whether your main security risk lies in your web applications, internet-facing systems, or the connection between your corporate network and production.

Which part of your business should you test first?

Most companies already have security measures in place: antivirus software, firewalls, backups, multifactor authentication, or support from an IT provider.

The real question is not simply whether those controls exist. It is whether they would work when someone actually tries to get in.

A penetration test helps answer that question through an authorised and controlled assessment. The goal is not to produce the longest possible list of vulnerabilities. It is to understand what an attacker could reach, what the consequences could be, and what should be fixed first.

However, not every organisation needs to test the same systems or begin in the same place. The right starting point depends on the technology that supports the business.

Could a security flaw affect your business?

Web platforms are no longer just corporate showcases. Many companies use them to manage customers, orders, documentation, distributors, and internal services.

A security assessment may be advisable if your organisation operates:

  • A customer or supplier portal.
  • A private user area.
  • An ordering platform.
  • An e-commerce site.
  • An API.
  • A platform connected to an ERP or CRM.
  • An application that processes personal or commercial information.

In these environments, checking whether the software is up to date is not enough. Authentication, permissions, user sessions, separation between accounts, and business logic must also be tested.

A security flaw could, for example, allow one customer to access another customer’s orders, enable a user to modify information without the appropriate permission, or expose an internal function to the internet.

Web penetration testing answers a very practical question:

Could a flaw in the application affect customers, operations, or sensitive information?

The OWASP Web Security Testing Guide covers areas including configuration, identity management, authentication, authorisation, session management, input validation, and business logic.

Does your company have an open door?

To support remote work, provide maintenance, or operate business systems, companies make different services available over the internet:

  • VPN connections.
  • Remote desktops.
  • Corporate portals.
  • Administration panels.
  • Supplier access.
  • Cloud platforms.
  • Remote maintenance services.

Some of these services are essential. Others may have remained exposed after a migration, a change of supplier, or the end of a project.

An external penetration test examines what can be seen and reached from the internet without initially having access to the organisation.

The assessment helps answer questions such as:

  • Do we know every asset published under our domains?
  • Are all those services still necessary?
  • Are they running supported and updated software?
  • Are they exposing sensitive information?
  • Are they using weak or outdated access mechanisms?
  • Could they provide a route into other systems?

A service being visible from the internet does not automatically mean that it is vulnerable. It is therefore important to distinguish between necessary exposure, an area for improvement, a known vulnerability, and a risk that can actually be exploited.

CISA recommends identifying internet-accessible systems and paying particular attention to exposed management interfaces on devices including firewalls, VPN concentrators, routers, and remote administration systems.

Is production truly isolated?

In an industrial organisation, the corporate and production networks may appear separate on an architecture diagram while still sharing connections that are not immediately obvious.

The risk may lie in:

  • Remote access used by manufacturers or maintenance providers.
  • Devices connected to both IT and OT networks.
  • Engineering workstations.
  • Legacy firewall rules.
  • Wireless networks.
  • Cellular routers.
  • Monitoring systems.
  • Intermediate servers.
  • Administrative interfaces.

A segmentation assessment does not need to begin by interacting with PLCs, SCADA systems, or sensitive industrial functions. The first stage can focus on architecture, communication paths, third-party access, and available services.

The objective is to answer:

If an office device, supplier connection, or auxiliary network were compromised, could the incident reach production?

Testing should be performed within agreed limits, on authorised assets, with continuous communication and clearly defined stop conditions.

The ISA/IEC 62443 series addresses industrial cybersecurity through concepts including risk assessment, zones, conduits, and security requirements adapted to industrial automation and control systems.

What does a penetration test deliver?

A useful assessment should provide clear answers:

  • What can be reached.
  • Which attack paths are genuine.
  • Which data, services, or processes could be affected.
  • What should be fixed first.
  • Which controls are working correctly.
  • What residual risk remains after improvements.

The results should be presented at two levels.

For Management

A concise explanation of the business risk, the processes that could be affected, and the recommended order of action.

For the Technical Team

Evidence, affected assets, exploitation conditions, and practical remediation guidance.

Not every company needs the same assessment

The first decision should not be which type of penetration test to purchase. It should be which part of the business needs to be tested first.

At CEISLAB, we review the organisation’s context before proposing a clearly defined scope that reflects its systems, priorities, and operational constraints.

Tell us which systems support your business, and we will help you identify what should be tested first.

Get in contact with our team at: [email protected]