Choosing a Penetration Testing Provider: The Questions That Separate Them
Certifications and logos tell you less than eight specific questions do. What to ask, what a good answer sounds like, and the two answers that should end the conversation.
Every firm in this market says the same things on its website. The differences show up in the answers to specific questions, and most of those questions take under a minute to ask.
Ask who is actually doing the work
Not the company, the person. Ask for the name and background of the tester assigned, and whether the person who wrote the proposal is the person who will run the test. In firms of any size these are frequently different people, and it is not a scandal, but you should know.
Follow it with: who writes the report? On some engagements the testing and the writing are split, and the report reads like it. A good answer names one person and explains who reviews them.
Ask what happens on day two
"If you find something critical on the second day of a five-day test, what do you do?" The answer you want is that they stop and tell you, with a named contact and a phone number agreed in advance. The answer you do not want is that it will be in the report.
"We can test it without any accounts" for an authenticated application, and "we do not need to know your user roles". The first means the login page is the test; the second means authorisation is not being examined at all, and that is where the findings are.
Ask about the report before you see one
- Can you see a redacted sample? Any firm that cannot produce one has a reason.
- Is the reproduction section written so a developer can follow it without calling you?
- Do findings state what was NOT tested?
- Do you get a machine-readable version as well as the PDF, or only a document?
- Whose logo is on it? For a reseller or an MSP passing this to a customer, that is a commercial question as much as an aesthetic one.
Ask about the retest
Is it included? How long after the test is it valid? Does it cover everything or only the highest severities? Does it involve exploiting again or only inspecting the change? Those produce different levels of assurance and firms differ on all four, so the answers are genuinely comparative.
Ask where your findings will live
This is the question buyers ask least and should ask most. Your vulnerabilities, written down, in one place, is exactly the document an attacker would most like. Ask:
- What platform holds them, and who else is on it?
- How long are they kept, and can you ask for deletion?
- Who at the firm can read them, and is that restricted to the engagement team?
- If AI is used in drafting, whose model, and does your data leave the firm to reach it?
- How is the report delivered, and is it ever emailed as an attachment?
Certifications: what they do and do not tell you
Individual certifications tell you somebody passed an examination, which is a real signal about baseline competence and a weak one about judgement. Company-level schemes tell you the firm has a process and has been assessed against it, which matters more for consistency than for the ability of the person who turns up.
For UK buyers, scheme membership is sometimes a hard requirement of a framework or a customer contract, in which case the question answers itself. Where it is not required, treat it as one input rather than the decision.
Ask how they scope, and watch what they ask you
The scoping call is the best signal available and it is free. A firm that asks how many user roles there are, whether the application changes state, how much is bespoke, what it integrates with and whether an API is separately in scope is estimating. A firm that asks for a URL and sends a number is guessing, and the guess will be wrong in whichever direction suits them.
Notice also whether they push back. A provider who accepts an obviously optimistic scope without comment has decided the overrun is your problem, and you will meet that decision again on the last day.
What to check on the paperwork
- Insurance. Professional indemnity at a level that means something relative to the systems being touched.
- Subcontracting. Whether they may bring somebody in, whether you are told, and whether the same confidentiality terms follow.
- Ownership of the findings. Not the report, the findings. Some firms treat write-ups as reusable inventory.
- Deletion. A commitment with a date, in the contract, rather than an assurance on a call.
- Right to test. Confirmation they will not begin without written authorisation from somebody who can give it.
Ask for a reference in your own sector
Not a logo on a page. A conversation with somebody who bought the same kind of test on the same kind of system. Ask them one question: what did the report miss? People who have lived with a report for a year know the answer, and it is more informative than anything on a capability statement.
Pental is the platform a consultancy runs on rather than a testing firm, and the answer to "where do the findings live" is a database the firm owns, in their own account, under their own brand, with the AI running on their own key. It is a question worth asking whoever you buy from, and a firm that cannot answer it precisely has not thought about it.
Pental Is Built by the People Writing This
Engagement management for testing firms, on a database you own, under your brand, with the AI running on your key.