Procurement departments buy penetration tests by the day rate, which means the market has learned to sell days rather than findings. The clearest way to judge a supplier is to ask for a redacted sample report before you award, and to know what you are looking for when it arrives.
Two documents in one
A usable report separates the executive summary from the technical detail completely. The summary should be readable by someone who will never open the technical section: what was tested, what the material risks are in business terms, and what the organisation should do first. The technical section is written for the engineer who has to fix it.
If the two are interleaved, neither audience is served, and it usually means the report was assembled from tool output rather than written.
Every finding needs reproducible evidence
- The exact request or action that triggered the issue, not a description of it.
- The response or observed behaviour that demonstrates the impact.
- The affected hosts or endpoints, enumerated rather than summarised as 'various'.
- A severity rating with the reasoning behind it, not just a CVSS number copied from a database.
- Remediation advice specific to your stack, not a paragraph of generic guidance.
A finding you cannot reproduce is a finding your engineers will dismiss, and rightly so.
Scope should be argued about before, not after
The most common cause of a disappointing test is a scope that excluded the thing you were actually worried about. Insist on a scoping document that names the systems, the testing window, the credentials provided, and explicitly what is out of scope and why. Where the supplier proposes to exclude something, make them say what risk that leaves unmeasured.
The re-test is the point
A test that is not followed by a re-test measures nothing durable — you know what was wrong on one day. A supplier confident in their work will include remediation verification within a defined window at no additional cost. Ask for that in writing, and ask how long the window is.
Questions worth asking a prospective supplier
- What certifications do the testers hold, and will those named individuals do the work?
- How do you handle a finding that puts a live service at risk during testing?
- What happens to our data and your notes after the engagement closes?
- Can we see a redacted report from an engagement of comparable size?
- Is the re-test included, and for how long after delivery?
The answers separate firms that test from firms that scan. As an ISO 27001 certified organisation we security-test our own builds before they reach a client's acceptance testing, and we are happy to be asked the same questions.
Sources and further reading
External links, provided for verification. CyberEdge is not responsible for third-party content.