17 September 2026 / 10 minutes of reading
It is important to make clear from the outset that an audit is a fundamental part of cybersecurity. It typically compares the organisation’s actual state with a standard, regulation or internal framework. During the audit, the auditor reviews company policies and identifies weaknesses in the system. Is the system configured correctly? Are the passwords strong enough? When was the system last updated?
For management, customers and, in the case of standards and regulations such as ISO 27001, CRA, DORA or NIS2, regulators in particular, an audit provides evidence that the company approaches risk seriously and systematically. However, if the organisation wants a much more realistic picture of its resilience, it needs to go one step further.
Do you want to know whether your security is set up correctly? An audit confirms that the company’s defence mechanisms are built on sound foundations. The company understands its obligations, has established policies and has implemented the required controls. This is essential, but it does not answer a much more practical question: will those controls withstand someone deliberately trying to bypass them?
Standards and regulations must be broadly applicable across an entire industry. A real attacker, however, targets a specific company, its particular technologies, employees, internal processes and weaknesses in the way they are connected.
A penetration test is an authorised simulated cyberattack. Ethical hackers work within a clearly defined scope and set of rules as they attempt to gain access to an application, API, cloud environment or infrastructure. Like real attackers, they look for the most efficient and exploitable route to their objective. The result shows whether a security control withstood the attempted exploitation and, if not, what an attacker could gain from its failure.
Automated scanning can quickly flag known vulnerabilities and misconfigurations. However, it may produce a large number of findings that are not actually exploitable. Serious issues can also become buried in a long list and fail to receive the right priority.
An ethical hacker puts each finding into context. They can distinguish a false positive from an exploitable vulnerability and combine several weaknesses into a single attack path. Instead of dozens of isolated items, the company receives a coherent picture of where an attacker could get and what needs to be addressed first.
A single system flaw or unpatched vulnerability does not usually lead directly to data theft or infrastructure compromise. In most cases, an attacker follows an entire chain of actions. For example, they may obtain a standard user account, abuse excessive permissions or move through an inadequately segmented network to reach a sensitive system.
When assessed separately during an audit, each of these weaknesses may appear manageable. Only when combined do they create a path to sensitive data or critical company infrastructure. The ability to uncover and build such attack paths is one of the greatest benefits of ethical hacking.
Before the penetration test begins, the organisation and the ethical hackers agree on its scope and objective. Confirmed vulnerabilities are then exploited in a controlled manner, and the testers document the impact achieved. This is not proof of absolute security. It is, however, the most direct way to verify whether the protection within the agreed scope can withstand an active intrusion attempt.
An audit can produce dozens of findings with varying levels of severity. Without further context, however, it can be difficult to decide which issues should be fixed first, especially when time and budget are limited. Ethical hacking helps set the right priorities. A vulnerability that can be exploited easily from the internet without authentication should naturally take precedence over an issue requiring physical access, a specific role and several additional conditions.
Deciding where to invest a limited security budget is a challenge for many companies. A general warning about weak segmentation or excessive permissions may remain just one of many items on a remediation list. A pentest can significantly change that perspective.
There is a fundamental difference between saying “the service account has excessive permissions” and “we used the service account to gain access to production data.” The second statement describes the business impact, supports the case for priority and budget, and enables management to decide which risk must be addressed immediately.

After an audit, an organisation can demonstrate that it has updated a policy or introduced a new control. This is important, but it does not necessarily guarantee that the technical attack path has disappeared. A retest repeats the original scenario. It gives the company confidence that the vulnerability has genuinely been removed and that the fix has not opened a different, similar route. In this way, the pentest fulfils its role as a practical verification of resilience.
According to Deloitte’s latest survey, as many as 85% of security leaders are confident in their strategy, yet their actual ability to execute it is, on average, 15% lower. The “cyber-confidence gap” describes a situation in which organisations have budgets, management support and plans but lack prepared teams, consistent processes or adequately managed third-party risks in day-to-day operations.
In 2025, Citadelo assessed 628 IT projects and identified 3,293 vulnerabilities. More than half of the tested projects contained at least one critical or high-severity finding. According to the Ethical Hacking Report 2025, a critical vulnerability was found in 71% of infrastructure projects and 42% of cloud projects.
Even an organisation with established processes and security tools may have an attack path within a specific application, identity or configuration that only an active intrusion attempt can uncover.
Yes, if you want evidence and confidence in practical resilience in addition to compliance. A pentest determines whether the controls established through the audit can be bypassed. It neither repeats nor replaces the audit. It builds on its findings and subjects selected parts of the organisation’s defences to a practical test.
Simply stating that a company has undergone an audit is not enough. Its scope and the obligations applying to the specific organisation are what matter. NIS2 also includes the assessment of the effectiveness of security measures. Under regulations and standards such as DORA, ISO 27001 and the newer CRA, a cybersecurity audit can verify compliance with requirements. A pentest adds practical verification of the resilience of selected technical controls.
For many companies, a pentest at least once a year is a reasonable baseline. However, a new critical application, cloud migration, major architectural change or serious incident should also trigger testing. It is equally important to vary the scope. Testing the same web application every year is of little value if the company has not assessed its internal infrastructure, identities, APIs or supplier access for several years.
The price depends on the scope, complexity of the environment, types of systems and required testing depth. A basic web application test may start at approximately EUR 800. Extensive infrastructure or cloud testing, or a Red Teaming engagement, may cost more than EUR 10,000.
When comparing offers, consider the amount of manual work involved, the testers’ experience, how findings are verified, the quality of the deliverables and whether a retest is included. The cheapest list of vulnerabilities may not answer the question that led your company to commission the test in the first place.
If you want to assess your ability to withstand a real attacker, an audit is only the starting point. A team of ethical hackers actively tests the security controls, connects individual weaknesses into a potential attack path and demonstrates their real impact.
If you already have an audit, the logical next step is a practical assessment of your most important systems. Citadelo will help you define the scope of penetration testing so that you receive a clear answer as to whether and how a real attacker could succeed in your environment.
All news