Common Penetration Test Findings in Small Businesses
The most common penetration test findings in small businesses are boring: reused passwords, logins without multi-factor authentication, accounts that should have been disabled months ago, missing patches, one flat network, and file shares everyone can read. Not zero-days, not exotic exploits, not anything from a movie. If you’re considering a test and wondering what it would turn up at a business like yours, this is the honest preview. It’s written for owners and managers, and it matters because the boring findings are the ones real attackers actually use, and every one of them has a known, affordable fix.
The list, up front
In most small and mid-sized environments, the findings cluster into six families:
- Passwords that work in more than one place
- Logins without multi-factor authentication
- Accounts nobody turned off
- Patches that never landed
- One flat network
- Shares everyone can read
If your instinct is “that sounds too ordinary to be the real threat,” that instinct is the thing this post is here to adjust. Verizon’s Data Breach Investigations Report has shown, year after year, that stolen credentials and other everyday weaknesses sit at the center of real breaches. Attackers are opportunists. They don’t need a brilliant way in when an easy one is available.
Passwords that work in more than one place
The classic chain starts here. Someone’s password leaks from an unrelated website, an attacker tries it against your email or VPN login, and it works because it’s the same password. During internal network penetration testing the same pattern shows up in another costume: one password reused across systems, so a single foothold quietly becomes five.
The fix: a password manager so people can keep long, unique passwords without memorizing them, and a ban on recycled ones for anything that matters. Cheap, unglamorous, effective.
Logins without multi-factor authentication
Multi-factor authentication, the extra prompt on your phone when you sign in, is the difference between a stolen password being a bad day and being an incident. When a test finds a reused password, the very next question is whether a second factor stands behind it. Where MFA is missing, one leaked credential is the whole ballgame; where it’s present, the stolen password usually stops at the gate. Insurers know this, which is why MFA questions fill the first page of most cyber insurance questionnaires.
The fix: require MFA on email, VPN and remote access, and anything administrative. Start with those three and you’ve closed the most-walked path.
Accounts nobody turned off
The employee who left in March still has a working login in September. The vendor who finished the project last year can still get into the system they set up. Stale accounts are a finding in most environments we see, and they’re valuable to an attacker for a simple reason: nobody is watching them. The rightful owner isn’t logging in, so nobody notices when someone else does.
The fix: make account cleanup part of offboarding, and review the full account list a couple of times a year. It’s a checklist habit, not a technology purchase.
Patches that never landed
Software vendors publish fixes for known flaws constantly, and attackers read those announcements too. A missed patch on something reachable from the internet is one of the most reliable ways in, and the flaws being exploited are often old ones. CISA’s Known Exploited Vulnerabilities catalog, the US government’s running list of flaws attackers are actively using, includes entries that are years old. The exploits keep working because the patches keep not landing.
The fix: patching as a routine with a schedule and an owner, not a when-someone-remembers activity. External testing tells you which internet-facing systems are behind; the routine keeps them from falling behind again.
One flat network
A flat network means everything can talk to everything: the front-desk PC, the file server, the cameras, the payment system, all on one open floor. It isn’t a crisis by itself, and plenty of businesses run this way for years. What it changes is the cost of any other mistake. On a flat network, one compromised laptop can reach the systems that matter; on a segmented one, that same compromise stops at a wall. In our reports a flat network is scored honestly, as a multiplier of other findings rather than a five-alarm item on its own.
The fix: basic segmentation, separating the systems that matter from the general population. It’s real network work your IT team or MSP can phase in, and the test tells you which walls are worth building first.
Shares everyone can read
Somewhere on most office networks is a folder everyone can open that nobody remembers creating. Inside: payroll exports, scans of driver’s licenses, a spreadsheet named passwords.xlsx. Open shares are among the quietest findings, no alarms, nothing broken, and among the first places anyone who gets inside will look, because they turn a foothold into the exact information that makes everything else easy.
The fix: find the open shares, decide who actually needs each one, and lock the rest down. Access should follow a simple rule: people can reach what their job requires, and not the rest.
What usually is not a finding
Just as useful is what shouldn’t be on the list. Your VPN, your email server, your website, your remote-access portal: these are on the internet because that’s what they’re for, and their existence is not a vulnerability. The real questions are the ones above, whether each is patched, configured correctly, and behind MFA. A report that pads its count by flagging normal infrastructure is telling you more about the vendor than about your network; our guide to reading a penetration test report covers the other tells.
The other absence worth naming: dramatic zero-day exploits. They exist, they make headlines, and they’re rarely how anyone gets into a small business, because they don’t need to be. The six families above are easier, quieter, and everywhere.
Why boring is good news
Every family on this list has a known fix, most of them inexpensive: a policy, a setting, a habit, a piece of ordinary IT work. Nothing here requires a security team or a six-figure budget. That’s the practical difference between fearing the exotic and fixing the ordinary, and it’s why a test should leave you calmer, not scared. You trade a vague worry for a short, prioritized list, hand the list to your IT team or MSP, fix the top of it, and verify the fixes with a retest. The pricing is public, and the retest is included.
Frequently asked questions
What is the most common penetration test finding?
Weak or reused passwords, usually combined with a login that doesn’t require multi-factor authentication. The pairing is what matters: a reused password gets an attacker to the door, and the missing second factor lets them through it. Fixing either one breaks the chain, which is why both sit at the top of most fix lists.
Do penetration tests find zero-day vulnerabilities?
Rarely, and that’s worth knowing before you buy. Brand-new, never-seen flaws make headlines, but real intrusions mostly run on old, known problems: unpatched software, weak credentials, and accounts nobody turned off. A test that finds boring things is not a disappointing test. It’s an accurate one.
Is having a VPN or remote access portal a security finding?
No. A VPN, an email server, or a remote-access portal on the internet is there by design, and its existence is not a problem. The findings that matter are whether it’s patched, configured correctly, and protected by multi-factor authentication. Be wary of any report that pads its count with things that are supposed to exist.
How hard are common findings to fix?
Most of them are more about diligence than money. Enforcing MFA, disabling stale accounts, tightening a file share, and catching up on patches are ordinary work for your IT team or MSP, guided by a prioritized list. The fixes that take real planning, like segmenting a flat network, can be phased in over time.
Common penetration test findings, the short version
Expect the boring six: reused passwords, missing MFA, stale accounts, missed patches, a flat network, and open shares. Expect the report to rank them by what an attacker could really do, and expect the fixes to be ordinary work rather than a crisis budget. If you’d like to know which of the six are true at your business, that’s precisely the question a test answers. Tell us a little about your setup and we’ll come back with a fair, fixed quote. Request a quote.
Want to know where you stand?
Tell us a little about your business and what is prompting the test. We will come back with a fair, fixed quote.
Request a quote