What does a penetration test prove?
A penetration test does more than list potential weaknesses. Under written authorization and agreed rules of engagement, specialists use real attack techniques to determine whether a weakness is exploitable, which assets it can affect, and what business risk it creates.
A sound engagement combines discovery, controlled validation, evidence collection, risk scoring, and retesting. An automated scanner export is not a penetration test report on its own; expert analysis and false-positive elimination are essential.
How is scope defined?
Scope identifies the domains, IP addresses, applications, user roles, API endpoints, and cloud accounts that may be tested. The same document should define testing windows, escalation contacts, excluded systems, and an emergency stop procedure.
- External internet-facing assets
- Internal network and Active Directory
- Web, mobile, and API components
- Cloud accounts and identity controls
- Explicitly excluded critical systems
How should a provider be evaluated?
Comparing proposals only by price or consultant-days is misleading. Consider the methodology, depth of manual testing, critical finding notification process, sample report quality, retest terms, and data handling practices together.
Every finding should include reproducible evidence, a CVSS assessment, business impact, and actionable remediation guidance.
What should the final deliverables include?
The technical report must give engineering teams enough detail to remediate findings, while the executive summary should communicate priorities and business impact. A retest then confirms whether reported fixes actually close the identified attack path.
- Technical findings report
- Executive summary
- CVSS risk table
- Evidence and reproduction steps
- Retest and closure report