FREQUENTLY ASKED QUESTIONS
Why Block8.ai Penetration Testing
___
-
CREST Certified & ISO 27001:2022 Certified
AI-Powered Testing with Human Expert Validation
Speed, Efficiency & Accuracy
Cost-Effective & Affordable Testing, Anytime
Scalability & Adaptability to New Threats
Faster, Smarter & Simpler
Self-Serve Engagement & Delivery
-
A controlled attack on a computer system, network or application to identify security vulnerabilities that threat actors might exploit.
-
A Penetration Test provides you with confidence in your security posture. Without conducting Penetration Testing, organisations do not know where the weaknesses are that a threat actor may attempt to exploit.
-
Block8.ai offers two delivery models. Both use the same AI-powered testing engine and follow the same methodology — the difference is in how findings are validated before they reach your report.
AI-Only Testing delivers results in as little as 4 hours. The autonomous engine handles the full engagement: reconnaissance, vulnerability scanning, validated exploitation, and report generation. Findings are assessed through automated quality checks including a three-agent consensus process. Best suited for regular testing cycles, broad coverage, and internal risk triage.
AI with Human in the Loop Testing adds CREST-aligned tester validation on top of the AI engine. Human experts review key findings, confirm whether evidence demonstrates genuine business impact, and apply experienced judgement where context or proportionality matters — decisions that AI alone cannot reliably make. Best suited for compliance reporting, audit, board-level assurance, and customer-facing evidence.
Both models run on the same platform, produce the same structured evidence chain, and follow the same core process:
Planning and scope definition
Reconnaissance and vulnerability scanning
Validated exploitation of confirmed vulnerabilities
Remediation recommendations developed and prioritised
Structured report generated with traceable evidence for every finding
-
Block8.ai’s autonomous testing engine uses AI to orchestrate integrated scanners, validate suspected vulnerabilities with reproducible exploits, and generate structured findings — at a speed and breadth that manual testing alone cannot match. The AI handles reconnaissance, scanning, and exploitation. Human analysts and automated quality checks validate what it finds.
Find out more about the Block8.ai’s AI Platform here.
-
Block8.ai provides a self-service client portal where your team can scope, schedule, track test progress in real time, and download finalised reports. The portal includes real-time notifications at each stage of the engagement, team management for multi-user access, and a calendar view of all scheduled and active tests.
-
Block8.ai delivers three documents for every engagement:
An Executive Report — a concise summary of findings, risk posture, and recommended priorities, designed for non-technical stakeholders and board-level reporting.
A Technical Report — detailed findings including CVSS scoring, affected assets, step-by-step test evidence, proof-of-concept details, and prioritised remediation guidance for your security and engineering teams.
A Testing Certificate — formal confirmation that testing was conducted, suitable for providing to clients, auditors, and compliance teams.
Every finding in the Technical Report includes a traceable evidence chain: what was tested, which tools identified the issue, how it was validated, and what remediation is recommended.
-
Block8.ai's testing methodology is based on industry-recognised frameworks including OWASP (Open Web Application Security Project), PTES (Penetration Testing Execution Standard), and NIST Cybersecurity Framework. The appropriate methodology is selected based on the engagement type and target environment to ensure consistent, repeatable, and thorough testing.
Find out more about our methodology here.
-
Block8.ai aim to give you every opportunity to come out with a clear test result. To this end we offer free re-tests within 60 days of the original test. This gives you the time to remediate the vulnerabilities identified, following the recommendations provided by Block8.ai and provides a clear test with certificate to provide clients.
-
External (incl. Network, Infrastructure & Cloud) Penetration Tests target the Internet facing technologies of an organisation. Parts of the organisation could be accessed by anyone, anywhere in the world with an Internet connection.
Web Application (incl. APIs & Agents) Penetration Tests target the applications or websites that your organisation uses to interact with clients and members of the public. This test looks to see if there are any vulnerabilities that could be exploited by the threat actors or by the staff managing the application
Internal Penetration Tests target weaknesses within your internal networks and systems that could be exploited by a rogue contractor or staff member with access to a network port within the inner portions of the organisations networks or systems.
-
White Box: Authenticated testing with full documentation of network/application. You will provide Block8.ai an account for an internal service and full documentation of your application or network so Block8.ai can specifically target high values assets first.
Grey Box: Authenticated testing with no documentation. You will provide Block8.ai a basic user account as part of scoping and no additional detail about your application, network or services. Block8.ai will use the provided account to attempt actions like privilege escalation and exfiltration of sensitive data.
Black Box: Unauthenticated testing, this best emulates the starting point of a bad actor trying to access your network or application.
-
All Penetration Testing should be conducted as often as possible and at a minimum:
Before first going live with an internet facing system.
After major changes occur to the externally facing components of the organisations technology.
Following an actual or suspected incident involving the organisations internet facing technologies.
Following changes to the externally facing technology.
To meet compliance requirements.