The most common vulnerabilities we find in a small company pentest
Weak passwords, missing MFA, and forgotten test accounts are the findings that repeat most often in small-company pentests. Here's what actually turns up, and why it's so hard to keep in check.

Say the word "pentest" and most small-business owners picture a sophisticated attack that only a specialised firm with expensive equipment could uncover. In practice, most engagements turn up the same handful of findings — not because the attackers are exceptional, but because basic hygiene never gets addressed.
Weak or reused passwords
The most common finding stays the simplest one: a password that's either trivial or reused across several places. It only takes one password leaking from an unrelated service for an attacker to try it against the company VPN or website admin panel. For smaller companies, this finding lands in almost every engagement.
Missing multi-factor authentication
Where a password does leak or get guessed, a second factor would stop the attack right there. In practice, though, MFA is often missing on exactly the most sensitive accounts — website admin access, remote network management, the email account that could be used to reset every other password. Setting it up takes minutes; the gap is usually a matter of nobody formally requiring it, not a technical obstacle.
Unpatched or publicly exposed services
A router, a WiFi extender, or an old internal system nobody has updated in years but that's still reachable from outside — that's the second recurring pattern. Devices run for years unnoticed because they "work," and nobody ever put them on a regular review cycle. These forgotten devices tend to be the easiest way in, precisely because no one is tracking whether their firmware is still current.
Forgotten test and demo accounts
An account created for testing during a system rollout that stayed active with a default password afterward — this finding shows up more often than you'd expect. It's not an attack on the production system, it's a side door nobody closed once the work was done.
Flat internal network
The last recurring finding isn't one specific hole but an architecture problem: once an attacker gets in through any of the points above, they can move freely across the company network because there's no segmentation between operational and sensitive systems. That means even a minor mistake at the network edge can turn into full access, not just an isolated incident.
What this means for a smaller company
None of these findings need a big remediation budget — what they need is to stay on the radar on a recurring basis, not just get fixed once during a system rollout. Security posture quietly drifts back to its default state: a password resets to something simpler, MFA doesn't carry over when an employee changes, a test account stays active after the project wraps. That's why it makes sense to treat a security audit as a recurring check rather than a one-off project — that's how we build it at Cyber Forza, including a short report on exactly what to fix first.
