Business

Choosing a Penetration Testing Provider: The Questions That Separate Them

Certifications and logos tell you less than eight specific questions do. What to ask, what a good answer sounds like, and the two answers that should end the conversation.

Pental4

Every firm in this market says the same things on its website. The differences show up in the answers to specific questions, and most of those questions take under a minute to ask.

Ask who is actually doing the work

Not the company, the person. Ask for the name and background of the tester assigned, and whether the person who wrote the proposal is the person who will run the test. In firms of any size these are frequently different people, and it is not a scandal, but you should know.

Follow it with: who writes the report? On some engagements the testing and the writing are split, and the report reads like it. A good answer names one person and explains who reviews them.

Ask what happens on day two

"If you find something critical on the second day of a five-day test, what do you do?" The answer you want is that they stop and tell you, with a named contact and a phone number agreed in advance. The answer you do not want is that it will be in the report.

"We can test it without any accounts" for an authenticated application, and "we do not need to know your user roles". The first means the login page is the test; the second means authorisation is not being examined at all, and that is where the findings are.

Ask about the report before you see one

  • Can you see a redacted sample? Any firm that cannot produce one has a reason.
  • Is the reproduction section written so a developer can follow it without calling you?
  • Do findings state what was NOT tested?
  • Do you get a machine-readable version as well as the PDF, or only a document?
  • Whose logo is on it? For a reseller or an MSP passing this to a customer, that is a commercial question as much as an aesthetic one.

Ask about the retest

Is it included? How long after the test is it valid? Does it cover everything or only the highest severities? Does it involve exploiting again or only inspecting the change? Those produce different levels of assurance and firms differ on all four, so the answers are genuinely comparative.

Ask where your findings will live

This is the question buyers ask least and should ask most. Your vulnerabilities, written down, in one place, is exactly the document an attacker would most like. Ask:

  • What platform holds them, and who else is on it?
  • How long are they kept, and can you ask for deletion?
  • Who at the firm can read them, and is that restricted to the engagement team?
  • If AI is used in drafting, whose model, and does your data leave the firm to reach it?
  • How is the report delivered, and is it ever emailed as an attachment?

Certifications: what they do and do not tell you

Individual certifications tell you somebody passed an examination, which is a real signal about baseline competence and a weak one about judgement. Company-level schemes tell you the firm has a process and has been assessed against it, which matters more for consistency than for the ability of the person who turns up.

For UK buyers, scheme membership is sometimes a hard requirement of a framework or a customer contract, in which case the question answers itself. Where it is not required, treat it as one input rather than the decision.

Ask how they scope, and watch what they ask you

The scoping call is the best signal available and it is free. A firm that asks how many user roles there are, whether the application changes state, how much is bespoke, what it integrates with and whether an API is separately in scope is estimating. A firm that asks for a URL and sends a number is guessing, and the guess will be wrong in whichever direction suits them.

Notice also whether they push back. A provider who accepts an obviously optimistic scope without comment has decided the overrun is your problem, and you will meet that decision again on the last day.

What to check on the paperwork

  • Insurance. Professional indemnity at a level that means something relative to the systems being touched.
  • Subcontracting. Whether they may bring somebody in, whether you are told, and whether the same confidentiality terms follow.
  • Ownership of the findings. Not the report, the findings. Some firms treat write-ups as reusable inventory.
  • Deletion. A commitment with a date, in the contract, rather than an assurance on a call.
  • Right to test. Confirmation they will not begin without written authorisation from somebody who can give it.

Ask for a reference in your own sector

Not a logo on a page. A conversation with somebody who bought the same kind of test on the same kind of system. Ask them one question: what did the report miss? People who have lived with a report for a year know the answer, and it is more informative than anything on a capability statement.

Pental is the platform a consultancy runs on rather than a testing firm, and the answer to "where do the findings live" is a database the firm owns, in their own account, under their own brand, with the AI running on their own key. It is a question worth asking whoever you buy from, and a firm that cannot answer it precisely has not thought about it.


Pental Is Built by the People Writing This

Engagement management for testing firms, on a database you own, under your brand, with the AI running on your key.

Related reading

Business · 4 min read
How Long a Penetration Test Takes, and Why Estimates Vary So Much
From first call to final report, with the parts nobody counts. What drives the testing days, how long reporting really takes, and where the calendar time goes that is not testing at all.
Business · 4 min read
Penetration Testing for a SaaS Startup: When to Start and What to Buy
The first test is usually bought because a customer asked. Here is when it is genuinely worth doing sooner, what to spend on it, and what enterprise buyers will ask for next.
Business · 4 min read
What a Penetration Test Costs, and What Actually Changes the Number
Quotes for the same scope routinely differ by a factor of three. Here is what the number is made of, which variables move it most, and how to tell a cheap quote from a small one.