Penetration testing is the one thing you can do to vet the security posture of your business. Not all pentests are the same and they shouldn’t be. Netwerk Guardian has written the book on Penetration Testing…in fact its called Effective Penetration Testing and is on sale at this site.
A good test will be one that tests what you hold most valuable. Its not scanning IP addresses and finding holes. Any first grader can do that. No exploit those vulnerabilities and provide proof you got in or caused damage. That is testing. In the book we go over more in depth on the following: