The Pentest You're About to Buy Might Not Help You

The Pentest You're About to Buy Might Not Help You

At least, not in the way you expect.

Every year, we speak with organisations planning their first penetration test.

The reason is usually familiar. A client has asked about security. The board has raised concerns. There has been an incident. Or the business has simply decided it's time to take security more seriously.

The conclusion is often the same: we need a pentest.

That may be the right decision, but a penetration test isn't just something you buy and wait for. Its value depends on choosing the right service, sharing the right information, and acting on the findings.

Make Sure You're Buying the Right Test

The first question we ask is simple.

What are you trying to achieve?

If you want to find weaknesses in an application, network, or system, a penetration test may be the right choice.

If you want to test whether your team can detect and respond to a realistic attack, you'll likely need a red team engagement instead.

A penetration test looks for vulnerabilities within an agreed scope.

A red team engagement has a specific goal, such as gaining access to a critical system or compromising an important account. Success is measured by whether the goal can be achieved and how well your team detects and responds to the activity.

0:00
/0:08

One finds as many weaknesses as possible. The other finds out if you'd notice.

Both are point in time exercises. They tell you what your security posture looked like on the days testing took place, not next month, and not after your next release. New vulnerabilities get introduced constantly, through code changes, new infrastructure, expiring certificates, and services that quietly become internet facing without anyone noticing. A test that runs once a year gives you a snapshot, not a live picture.

Most organisations need a penetration test first. It makes sense to understand what's vulnerable before testing whether your team can detect it being exploited.

A good provider should help you choose the right service, not simply sell you the largest engagement.

Do Not Withhold Useful Information

Some organisations believe the test will be more realistic if they provide very little information.

The logic sounds reasonable. A real attacker wouldn't be given network diagrams, credentials, or previous security reports.

But a real attacker may have months to gather information. A penetration test usually lasts one or two weeks.

Every hour spent discovering something you could have explained is an hour not spent on deeper testing.

Architecture diagrams, application documentation, test accounts, and previous reports all help the testing team use their time well. Sharing information doesn't reduce the quality of the test. It usually improves it.

The Cheapest Quote Is Not Always the Best Value

Penetration testing quotes can vary a lot, even when the services look similar.

The difference is often in the time, experience, and approach behind the work.

A good penetration test involves more than running a scanner. It requires manual testing, careful thinking, and an understanding of how the system is meant to work.

When comparing providers, ask how the assessment will be divided between automated tools and manual testing. Automation, including AI-assisted tools, can help testers work more efficiently by speeding up reconnaissance, triaging large result sets, and identifying patterns across code or configurations.

However, these tools do not replace an experienced tester’s judgement. A person still needs to determine whether a finding is genuinely exploitable in your environment, connect several smaller weaknesses into a realistic attack path, and investigate unusual behaviour that automated tools may overlook.

A lower quote may reflect an efficient testing approach, but it may also mean less time has been allocated to manual investigation. The important question is not simply whether AI or automation is being used, but how the results will be validated and how much experienced human analysis is included.

Before choosing a provider, ask:

  • How many testing days are included?
  • Who will carry out the work and what are their qualifications?
  • What testing standards or methodology does the provider follow (such as OWASP, PTES, or NIST)?
  • How much of it will be manual, versus automated?
  • What will the report actually include?
  • What happens if something serious is found during the test?

A lower price may still make sense for a small scope. But price shouldn't be the only factor. The value of a penetration test depends on the quality of the investigation, the experience behind it, and whether the findings help you understand and reduce real risk.

Same scope, similar price - very different amount of testing behind each number.

You May Not Be Ready Yet

Not every organisation is ready to get full value from a penetration test.

If systems are out of date, default passwords are common, or basic security controls are missing, the test may only confirm problems you already know about.

In that case, a vulnerability assessment or security review may be a better first step. Such a review might examine patching, exposed services, identity controls, default credentials, asset inventory, and whether the testing environment is stable enough for meaningful manual assessment.

"Not ready" doesn't mean "not at risk." It means the basic problems should be addressed before paying for deeper manual testing.

A good provider should be willing to tell you this, even if it means a smaller project.

Plan for Serious Findings

0:00
/0:10

A typical SilentGrid engagement, from kickoff to retest

Do not wait until the final report to decide what happens if something critical is found.

During a recent web application assessment, our team identified multiple vulnerabilities, including a complex SQL injection flaw found after reviewing the source code of an open-source framework the application was built on. Understanding how the framework handled queries under the hood revealed a way to exploit the client's own implementation, giving an attacker direct access to the underlying database.

We didn't wait for the final report.

The client was working toward a product launch and needed to close out all high-severity findings before going live. Their remediation team was based in a different geographical location, several hours behind us, so we adjusted our own hours to overlap with theirs and worked through the fix together in real time. The vulnerabilities were resolved and verified before launch. That's the value of raising serious findings the moment they're discovered, and staying flexible enough to work around whatever the client actually needs, timezones included.

Findings such as exposed credentials, access to customer data, or a serious weakness in an internet-facing system should always be raised straight away. Before testing starts, agree on who should be contacted and how urgent issues will be handled, and make sure someone is available who understands the environment and can involve the right people.

Stay Involved During the Test

You shouldn't hand over access, hear nothing for two weeks, and then receive a large PDF.

You should know what's been tested, whether anything important has been found, and whether the team needs more information.

Regular communication also improves the report.

Your team may know that a finding is already accepted, or that a system is more important than it first appears.

That context helps the testers understand the real impact.

By the end of the engagement, the major findings shouldn't be a surprise.

The Report Is Only the Start

A penetration test only creates value when the findings are fixed.

Each finding should have an owner, a deadline, and a clear plan.

Important fixes should also be retested to confirm they work.

Many organisations test each year, after major system changes, or when important new services are launched.

Over time, the findings should change. Basic issues should reduce, and later tests should uncover more complex weaknesses.

As organisations mature, repeated testing often reveals fewer foundational issues and more nuanced weaknesses. Illustrative trend; actual findings vary by environment.

That doesn't mean a mature organisation should never see a high or critical finding again. When one does turn up, it's worth treating as more than just another item to fix. Understanding how a serious issue got through, whether it was a gap in a code review process, a missed configuration step, or a change that bypassed normal checks, often matters more than the finding itself.

That's a good sign. It shows the security programme is improving.

The Point

A penetration test can be a valuable investment, but only when it's the right service, scoped properly, supported with useful information, and followed by action.

Don't treat it as a checkbox.

Ask questions. Be open about your environment. Understand what you're buying. Make sure there's a plan for the findings.

A good penetration test does not end when vulnerabilities are found. Its value comes from helping organisations fix them, verify the fixes, and identify what should be tested next.

Planning your first penetration test, or unsure whether you need a pentest or a red team engagement? Get in touch. We'll help you scope the right assessment before testing begins, not after.