Penetration Testing

CATSCAN® Penetration Testing: What to Expect

A buyer's guide to scoping adversarial testing, setting safe boundaries, reviewing deliverables, and turning findings into remediation and retest decisions.

By Tom Brennan

Featured image for CATSCAN® Penetration Testing: What to Expect

A useful penetration test answers a buyer's question: within the agreed scope and rules, could an attacker reach a meaningful objective, and what should the organization fix first? A scanner can find signals. Adversarial testing adds human validation, attack-path context, and a practical conversation about remediation.

Start with scope, not a shopping list

Before testing begins, document the objective, systems, environments, identities, attack paths, dates, contacts, and rules of engagement. Possible scope areas include external infrastructure, internal networks, web applications and APIs, cloud or Microsoft 365 configuration, wireless, mobile, physical security, social engineering, or a focused red-team objective. Not every engagement includes every area.

  • In scope: named domains, IP ranges, applications, tenants, accounts, facilities, or workflows that the client has authorized.
  • Out of scope: third-party systems, production actions, denial-of-service activity, destructive changes, sensitive data collection, or social engineering targets that are not expressly approved.
  • Safety controls: testing windows, emergency contacts, stop conditions, rate limits, test accounts, data handling, and escalation procedures.

Scope boundaries are not a weakness. They protect operations, avoid unauthorized testing, and make the final risk statement honest.

What CATSCAN® testing may evaluate

CATSCAN® engagements are scoped to the agreed systems and attack paths. Depending on the objective, a team may assess:

  • External exposure, authentication, exposed services, and initial-access paths
  • Internal privilege boundaries, segmentation, lateral movement, and access to sensitive systems
  • Web application and API authorization, session handling, input validation, and business logic
  • Microsoft 365 and Entra ID identity, conditional access, privilege, and configuration risks
  • Cloud, wireless, physical, or human-layer controls when explicitly authorized

Deliverables to request

A buyer should receive more than a severity-ranked export. Confirm that the statement of work defines deliverables such as:

  • an executive summary tied to business impact and the agreed objective;
  • a technical findings report with evidence, affected assets, attack path, risk rationale, and reproduction or validation detail appropriate to the engagement;
  • scope and limitations, including systems not tested and constraints that affected confidence;
  • prioritized remediation guidance with owners or decision points the client can use;
  • a readout or working session to resolve questions; and
  • an agreed retest method, window, and report format.

Remediation and retest are part of the buying decision

Ask how findings are triaged, whether the client can discuss compensating controls, and what happens after a fix. A retest should state which findings and attack paths were rechecked, the date and environment, what evidence was observed, and whether the original exposure was resolved, reduced, or still present. Retesting is validation of the tested change—not a guarantee that no other weakness exists.

Remediation ownership remains with the client and its authorized technology providers. CATSCAN® testing does not guarantee compliance or prevent an incident; a testing firm can explain risk and validate agreed changes without treating a report or retest as a universal assurance.

Questions for a prospective tester

  1. What objective and methodology will govern the work?
  2. Which systems, accounts, and attack paths are included and excluded?
  3. How much manual validation is expected alongside automated tooling?
  4. How are sensitive data, production safety, and emergency stop conditions handled?
  5. What report, readout, remediation support, and retest are included?
  6. How will limitations and residual risk be described?

Proactive Risk can scope a CATSCAN® engagement around a defined business concern. Request a testing conversation with the systems and objective you want to validate.

Explore Related Resources

Back to the Proactive Risk blog · Talk with Proactive Risk