Insights ·

Choosing a penetration testing supplier wisely

By Nanorisk

Choosing a penetration testing supplier wisely

Before you commission a penetration test, ask the supplier one question: can I see a sample report?

Scope and day rate get most of the attention during procurement. They matter, but they're not what you're left with. The report is what your security team, your board, and your remediation engineers will be working from for the next 12 months. It needs to be usable.

A good report tells you what was found, how it was exploited, what the realistic impact is, and what to fix first. It's written by someone who understood what they were testing, not generated by a scanner and exported to PDF. You'll see the difference immediately when you compare the two.

If a supplier is hesitant to share a redacted sample, that's useful information. If their sample reads like a CVE list with severity scores attached, that's also useful information.

At Nanorisk, every report we produce is written by the consultant who conducted the test. Findings are evidence-led, prioritised by actual exploitability, and written so that both technical teams and senior stakeholders can act on them. If you'd like to see what that looks like, get in touch.

Concerned this affects you?

We can assess your exposure and tell you plainly where you stand.

← All insights