Glossary
Test d'intrusion (pentest)
An offensive audit where a consultant simulates an attack on your infrastructure, under contract, to identify exploitable vulnerabilities.
A penetration test (pentest) is the inverse of a compliance audit. Instead of verifying that a control exists, the consultant actively tries to bypass it. The goal is to find exploitable vulnerabilities before an attacker does.
Common pentest types: external (internet perimeter, public sites), internal (from a workstation on your network), application (your web app), red team (multi-week campaign simulating a real attacker). The choice depends on your exposure and obligations.
A typical French SMB should run an external + application pentest every 12 to 24 months. Enterprise B2B customers often ask for a recent one (< 12 months) during due diligence. The deliverable: an executive summary (1 page), a technical report (typically 25–50 pages), a prioritised remediation plan, and ideally a re-test included if you remediate within 90 days.