Penetration Testing Provider Comparison: What is White Box?

February 4, 2022 Mike Smith

When comparing penetration testing providers, it’s important to know the difference between white box, gray box and black box.

In the video below, Mike Smith explains white box pen testing services, and when your company should choose this type of test, over gray or black box testing.

Want Mike’s recommendations on the top penetration testing service providers, your company should be quoting? Click below to ask him today.

Ask Mike

About Mike
Mike Smith is the Founder and President of AeroCom and has been helping companies with telecom and cloud services since 1999. He has been the recipient of numerous business telecommunications industry awards and in 2011, he was honored as one of the top 40 business people in Orange County, CA., under 40 years old. You can also hear him as the host of the popular Information Technology podcast, ITsmiths with Mike Smith. Follow Mike on YouTube, LinkedInReddit and SpiceWorks.

Transcript

Your company is in the market for penetration testing for whatever reason. I know that there might be some different reasons out there. Maybe it’s to fulfill an insurance policy, maybe it’s to fulfill a vendor requirement, or maybe it’s just because you are concerned about your company’s cybersecurity, but either way, you’re interested in doing some penetration testing.

And one of the questions you have is how do we go about it? What are some of the different types of penetration testing, or what type of penetration testing does our company need?

Well, one of the first things you need to determine is how much information you want to give to the penetration testing company before they start doing a penetration test. And the way you refer to that is either a white box penetration test, a gray box penetration test, or a black box penetration test.

In today’s video, I’m going to quickly explain a white box penetration test and what that is.

Shortcut to some recommendations

But before I get started, just a quick reminder, if you want my recommendation on the best penetration testing companies that your company should be quoting based on your requirements, just give me a call (714.593.0011), or send me an email. More information on that at the end of the video.

What is a White Box Pen Test?

So what is a white box penetration test?

It’s also called a clear box penetration test. And what it is, is when you give all the information to the testing company, so you give them all the targets, all of the details of your company, all of the different ways that they might be able to break into your company, you are completely forthcoming about all information to them, and you give them free rein and say, “Please try to hack in, here’s everything that we have and everything that we do in our most vulnerable areas. Go ahead and try to hack in.”

It’s faster and in-depth

It’s also the quickest penetrate test because, obviously, they know exactly what they want to do to get in. They know exactly how to get in. They don’t spend a whole time snooping around trying to find information about, well, does your company have a server online, or is there anything else that they need to know? They don’t spend any time doing that. They go right to business on trying to break into your company in exactly the spots that they think you’re going to be vulnerable. So it’s the quickest way to do it.

Penetration Testing Service Comparison - White Box-t2

Also, they can get into the most depth. They can spend a lot of time really trying to penetrate into your organization in the most vulnerable areas. So it can be the most in-depth penetration test. It can be the quickest penetration test.

And it’s a good idea to do that if you have specific vulnerable areas that you know a lot of people know about, a lot of people in the public know about, and you want to make sure that people cannot break into those areas and a threat actor cannot get inside. So that’s a white box penetration test.

More questions?

Again, if you want to know which white box penetration testing companies your company should be quoting, don’t research it on the internet. Just reach out to me, email me, call me (714.593.0011). I’m happy to ask you a few questions.

I’m a broker for all the major penetration testing service providers out there. So based on the information you give me, I’ll tell you the small handful of companies that I think your company should definitely be quoting and why. And I’ll also give you an introduction to those companies. And the nice thing is, is that you do not pay me a dime for my services. I’ve been doing this for 18 years, helped hundreds, if not thousands of companies do this type of stuff. So absolutely no reason not to at least reach out and ask me my opinion, and I’m happy to help.

So if you like the video, please like it and subscribe to the channel so we can get rid of the advertisements. And I will catch you on the next one.

Ask Mike

Related Content

Tagged with: