---
title: Utilizing Penetration Assessments to Mitigate Actual Risk
description: Learn how penetration assessments can help mitigate actual security risks for your business.
---

IT doesn't have to be stressful [noun-call-7000071 937-535-4300](tel:9375354300) [Union 6 info@expedienttechnology.com](mailto:info@expedienttechnology.com)

[![Expedient Technology Solutions](https://blog.expedienttechnology.com/hubfs/Expedient_Logo_Large-qwxoiuw2i3o8gx7az70u3q7po0u9x7wmfrgigpaj0s.png "Expedient Technology Solutions")](https://expedienttechnology.com/)

[Menu](javscript:void(0))

- [About](https://www.expedienttechnology.com/about/) 
    - [Core Values](https://www.expedienttechnology.com/about/core-values/)
    - [Our Leadership Team](https://www.expedienttechnology.com/about/leadership-team/)
- [Services](https://www.expedienttechnology.com/services/) 
    - [Managed IT Services](https://www.expedienttechnology.com/services/managed-it-services/)
    - [Co-Managed IT Services](https://www.expedienttechnology.com/services/co-managed-it-services/)
    - [Cybersecurity Services](https://www.expedienttechnology.com/services/cybersecurity-services/)
    - [Cybersecurity Assessment Services](https://www.expedienttechnology.com/services/cybersecurity-assessment-services/)
    - [Managed Backup](https://www.expedienttechnology.com/services/managed-backup/)
    - [Managed Cloud & Virtual Desktop](https://www.expedienttechnology.com/services/managed-cloud-virtual-desktop/)
    - [Virtual CISO Services](https://www.expedienttechnology.com/services/virtual-ciso-services/)
    - [Compliance Services](https://www.expedienttechnology.com/services/compliance-services/)
- Resources 
    - [Blog](https://blog.expedienttechnology.com/)
- [Industries](https://www.expedienttechnology.com/industries/)

 Search

[Contact Us](https://expedienttechnology.com/contact/) [Careers](https://expedienttechnology.com/careers/)

# Utilizing Penetration Assessments to Mitigate Actual Risk

[Home](https://www.expedienttechnology.com/) | [Our Blog](https://blog.expedienttechnology.com) | Utilizing Penetration Assessments to Mitigate Actual Risk 

![page-intro-animation](https://blog.expedienttechnology.com/hubfs/page-intro-animation.svg)

 February 20, 2024

[blog](https://blog.expedienttechnology.com/tag/blog)  [Penetration Testing](https://blog.expedienttechnology.com/tag/penetration-testing)  [Cybersecurity](https://blog.expedienttechnology.com/tag/cybersecurity)

#### **Penetration Assessments are a tool to use in assessing our business risk**.

Specifically, a tool that assesses risk to our business by taking a real-world approach to finding and exploiting weaknesses in our security controls, policies, and practices. Implementing security controls to mitigate risk in our business without performing penetration tests would be similar to putting airbags in a new car model and shipping it without crash-testing to make sure they go off in the correct way and at the correct time. Sure we can rely-on and trust our defense-in-depth security strategies, but all defenses require skilled humans to configure them appropriately to each unique environment, compounding likelihood of human error. Regular penetration assessments can help find missed, overlooked, or ineffective configurations before they can be exploited.  

## **How can we tell if Penetration Assessments are the correct tool for the correct job?**

If we have heard it once we have heard it a million times. 'What is the Cost-Benefit Analysis?'. We will touch on this more in depth in another post, but for now what are the key factors to keep in mind for penetration assessment CBAs? According to IBM's "Cost of Data Breach Report 2023", the average cost of a data breach in the US is just shy of $9.5M. The most-expensive, full-scope penetration assessments for an average SMB wouldn't touch 10% of that figure in 10 years. Do we have security tools, policies, and practices in place to be validated? Do we have any obligations from governing bodies, auditing bodies, insurance policies, or clients? Are there verticals that we will be barred-from or granted-access-to by omitting or taking this course-of-action?  

## **So how do we effectively wield this admittedly expensive tool to build a better understanding of risk to our business?**

First we have to understand our business objectives, the critical components to meeting those objectives, the security systems around those components, and whether we handle any sensitive data (PII, HIPPA, financial data, CUI, etc.). Choosing a partner organization that understands these is critical when purchasing a penetration assessment, and a great organization will be able to help us determine these criteria if we haven't yet.

Once we define these criteria, we can start to understand better what aspects of our company are likely to incur the most risk to our business when attacked, which gives us the priority, type, and scope of penetration assessments needed. Once we receive the results of the penetration assessments and digest them, we should have a fairly solidified understanding of how our current security strategies are holding up under pressure, as well as where some of our weaknesses are. One thing we need to keep in mind is that penetration assessments findings (or lack thereof) are indicators of risk, not guarantors of security.  

## **How do we ensure we are actually getting a penetration assessment and not just a network scan?**

I cannot tell you how many times I have reviewed proposals for penetration assessments only to find out they were trying to sell me an environment scan; so how do we weed out scans and at the same time recognize a high-quality vendor? There are several indicators that can help us with this goal in mind, and as you have probably guessed, I am covering this topic even more in-depth in another post. One of the easiest ways to find this out is to ask for a sample report as part of our Request for Proposal.

Any valid service will have these ready to hand out and will be ecstatic that we asked for it up front! In addition to a sample report, we should see pen testing-relevant certifications from their team (most proposals include some form of qualifications section), a verifiable-history of the company working in the cyber-security space, and quite frankly a price that matches. 

If you are looking for a partner to help you understand and mitigate actual security risk to your company, [click here to schedule a free pen testing consultation](https://expedienttechnology.com/contact/). If you are looking for more information on this topic and many more, please check out our other [blog entries here](https://blog.expedienttechnology.com/). 

### SCHEDULE A FREE IT STRATEGY CALL

### [LEARN MORE ABOUT OUR OFFENSIVE SERVICES](https://content.expedienttechnology.com/lp-ets-offensive-services)

### [WHY PARTNER WITH ETS?](https://content.expedienttechnology.com/partnering-with-ets?hs_preview=DVXBKpwV-139853402908)

### Related Blog Posts

- #### [March 2, 2022 How Often Should Full Penetration Testing Be Performed?](https://blog.expedienttechnology.com/blog/how-often-should-full-penetration-testing-be-performed)
- #### [November 7, 2023 Penetration Testing Methods Explained](https://blog.expedienttechnology.com/blog/cloud/penetration-testing-methods-explained)
- #### [December 8, 2021 What is PEN Testing?](https://blog.expedienttechnology.com/blog/cybersecurity/what-is-pen-testing)

## Contact ETS Today for More Information

## Contact

noun-location-7264737 8561 Gander Creek Drive Miamisburg, OH 45342

[noun-call-7000071 937-535-4300](tel:9375354300)

[Union 6 info@expedienttechnology.com](mailto:info@expedienttechnology.com)

## Our Services

- [Managed IT Services](https://expedienttechnology.com/services/managed-it-services/)
- [Co-Managed IT Services](https://expedienttechnology.com/services/co-managed-it-services/)
- [Cybersecurity Services](https://expedienttechnology.com/services/cybersecurity-services/)
- [Cybersecurity Assessment Services](https://expedienttechnology.com/services/cybersecurity-assessment-services/)
- [Managed Backup](https://expedienttechnology.com/services/managed-backup/)
- [Managed Cloud & Virtual Desktop](https://expedienttechnology.com/services/managed-cloud-virtual-desktop/)
- [Virtual CISO Services](https://expedienttechnology.com/services/virtual-ciso-services/)
- [Compliance Services](https://expedienttechnology.com/services/compliance-services/)

- [Blog](https://blog.expedienttechnology.com/)
- [Careers](https://expedienttechnology.com/careers/)
- [Privacy Policy](https://www.expedienttechnology.com/privacy-policy/)
- [Contact](https://expedienttechnology.com/contact/)

## Follow Us

<https://www.linkedin.com/company/expedient-technology-solutions/> <https://www.youtube.com/@ExpedientTechnologySolutions>

[![Certified By MSP Alliance](https://blog.expedienttechnology.com/hs-fs/hubfs/CyberVerify-qyn0dtu0xuwymfmsad9c788s7gp1gyit9c4p021iaw.png?width=100&height=100&name=CyberVerify-qyn0dtu0xuwymfmsad9c788s7gp1gyit9c4p021iaw.png)](https://mspalliance.com/) [![SOC](https://blog.expedienttechnology.com/hs-fs/hubfs/SOC2Transparent-qzzbk3otf5nrscpt9i4od8svi4miprywdf472j5xpa.png?width=100&height=99&name=SOC2Transparent-qzzbk3otf5nrscpt9i4od8svi4miprywdf472j5xpa.png)](https://www.aicpa-cima.com/resources/download/soc-for-service-organizations-engagements-overview) [![CompTIA Certified Team Badge](https://blog.expedienttechnology.com/hs-fs/hubfs/CompTIA-Certified-Team-Badge-1-qzy6oqzm7cq9fwq7r4qrfyic1vkulmcd4q90z0oc8w.png?width=225&height=90&name=CompTIA-Certified-Team-Badge-1-qzy6oqzm7cq9fwq7r4qrfyic1vkulmcd4q90z0oc8w.png)](https://www.comptia.org/)

 ©2026 [Expedient Technology Solutions](https://expedienttechnology.com/). All Rights Reserved. | Website designed by [ONEFIRE](https://onefire.com/)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Jacob Brandau",
    "url" : "https://blog.expedienttechnology.com/author/jacob-brandau"
  },
  "dateModified" : "2026-01-05T14:29:39.236Z",
  "datePublished" : "2024-02-20T15:34:19.000Z",
  "headline" : "Utilizing Penetration Assessments to Mitigate Actual Risk",
  "mainEntityOfPage" : {
    "@id" : "https://blog.expedienttechnology.com/utilizing-penetration-assessments-to-mitigate-actual-risk",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.expedienttechnology.com/hubfs/Expedient_Logo_no_shadow_Small.jpg"
    },
    "name" : "Expedient Technology Solutions"
  }
}
```