Time Back

The Hours Around the Testing.

Testing is what your clients pay for. Everything wrapped around it, the write-up, the document, the chasing, the second document after the client edits the first, is cost you absorb. On our own engagements we have seen up to sixteen hours of it come back, which is two working days. The published industry figure for this category of tool is six, and that tool has a fraction of the automation here. Here is where both numbers come from, which jobs they are made of, and how to measure your own.

up to 16 hseen on our own engagements, one firm
~6 hthe published figure, and the floor we argue from
9jobs that stop being done by a person
The Number

Up to Sixteen Hours. Six If You Only Trust the Published Figure.

Sixteen is what we have measured on our own delivery with the automations in this product running. It is two working days on an engagement. It is also one firm on one kind of work, so it is an upper figure we have seen rather than an average you should plan on, and the honest thing is to show you the conservative number underneath it and the arithmetic for both.

The conservative number is six. Published industry figures put a penetration test report at eight to fourteen hours of work for a firm running on documents and templates, and at four to six hours for one running on a management platform. Take the middle of each and the difference is around six hours on the report alone. That five-hour comparison is a system with roughly a tenth of the automation here, which is most of the gap between the two figures on this page.

The Two Numbers, and Where Each One Comes From
Up to 16 h
Measured on our own engagements with everything below switched on. One firm, our kind of work, an upper figure rather than an average. More research across other firms is needed before it means anything to you.
About 6 h
Borrowed from a survey of penetration testing teams, derived below. Not a measurement of Pental, and the platform it compares against automates far less. We argue from this one because you can check it without trusting us.
11 hTypical report, working from documents and templates
5 hTypical report, working on a management platform
6 hThe published difference, and the floor we argue from
What That Figure Is, and What It Is Not

It is an industry figure for this category of tool, not a measurement of Pental. Nobody should hand you a number from their own marketing and call it your saving, so we are telling you exactly which claim we are borrowing and from where: it comes from a survey of penetration testing teams, and the same survey names the biggest time sink as copying and pasting prepared content, which is precisely what the library and the drafting below remove. A separate estimate from the training side of the industry puts reporting at forty to fifty per cent of the duration of an engagement, which lands in the same place.

It is also conservative in one specific way. Every figure above measures writing the report. None of them counts the time your firm loses AFTER it, reconciling the platform with the copy that was edited in Word and actually sent, because the platforms those firms were surveyed on cannot read that document back in. That job is on the list below and it is not inside the six hours.

How to Read the Sixteen

It is our own delivery, on our own kind of work, with the automations below running. One firm is not a study. It is an upper figure we have seen, not an average you should plan on, and more research across other firms is needed before it means anything to you. We are stating it because it is what we have actually measured and because the published figure understates this product, not because it is a number anybody should sign a contract against.

The five hours in the subtraction above is the reason for the gap. It is a firm working on a management system with roughly a tenth of the automation in this one: a tool that drafts nothing, reads no scanner output back into a report and cannot reconcile an edited Word document with the record. Those three jobs are on the list below, and none of them is inside the six.

So treat six as the floor, sixteen as the other end of what the same work has looked like, and neither as your figure. The way to settle it for your firm is at the bottom of this page: measure four numbers on your last three engagements, then measure the same four on one run through the trial.

What It Is Worth Annualised, at Both Ends
Two a Month
At six hours, around 144 hours a year, which is about eighteen working days of delivery capacity back in the same team. At sixteen it would be around 384, or forty-eight days.
One a Week
At six hours, around 300 hours a year, or roughly thirty-eight days. At that volume it is already the difference between hiring and not. At sixteen it would be around 830.
In Money
Multiply the hours by your own day rate divided by the hours you bill in a day. We are not going to guess your rate, and a saving nobody has converted is not yet an argument.
Why Yours Will Differ

Six Is the Middle. Yours Is the One That Matters.

The hours you lose depend on how much of your report is house boilerplate, how many hosts carry the same weakness, whether your reviewer works in Word, and how much of your week goes on chasing. So the rest of this page is the itemised list the six hours is made of, and a way to measure your own figure instead of taking ours.

Where an Engagement Actually Loses Time
Before
Scoping by email, chasing the answers, chasing credentials, writing the proposal, chasing the signature.
During
Writing up the same twelve weaknesses in slightly different words, scoring them, collecting the evidence into something readable.
After
Assembling the document, the executive summary, review comments, applying the edits, and reconciling the platform with the file that was actually sent.
Later
The retest write-up, the attestation letter, the invoice, and finding last year's report when the client's auditor asks.
Gone

The Jobs That Stop Being Done by a Person.

Not shortened. These are the ones where the output arrives without anybody producing it, and a human's remaining involvement is reading it and deciding whether it is right.

  • Writing a finding from scratchOne action drafts the title, description, remediation, CVSS with its vector, CWE, category, affected assets, your custom fields and the references, in that order, from the evidence you captured. Anything you have already written is left alone.
  • Rewriting what your firm has written beforeWhere your library already holds that weakness, your house wording arrives first and the drafting works around it rather than over it. The best description your firm will ever write gets written once.
  • Assembling the documentThe report is rendered into the Word template you already send, or the built-in PDF, with cover page, styles, headers and appendices intact. There is no assembly step and no copy and paste between tools.
  • Writing the executive summaryDrafted from the findings actually present in the assessment, along with the retest summary, then edited by a human before it ships.
  • Re-entering the edited reportEdit the document in Word as normal and upload it. Every difference is shown item by item and applied only where you tick, so the platform matches what the client received without anybody retyping it.
  • Merging duplicate scanner outputResults merge by title with every affected host and its own evidence in one table, so twenty-nine rows that are two issues arrive as two findings rather than a morning of manual tidying.
  • ChasingProposal reminders, scoping requests and invoice chasing send themselves on schedule, and you can see when a proposal was opened.
  • Producing an attestation letterIts own document type, generated with the rest, rather than a letter rewritten from an old one every time a client's auditor asks.
  • Finding last year's reportThe client already has it, in their own portal on your domain, which turns a search through email into no work at all.

The list above is checkable in an afternoon: run one real engagement through the trial and count what you did not have to do.

Shorter

The Jobs That Shrink Rather than Vanish.

These still need a person. What changes is how much of each one is spent on the actual decision rather than on the mechanics around it.

  • ScopingThe client answers a structured form in their own portal and it lands attached to the engagement. What is left is reading it and asking about the gaps, rather than reconstructing a scope from a thread.
  • Collecting credentialsRequested before the start date and arriving encrypted against the engagement, so the job becomes checking they work rather than hunting for where they were sent.
  • ScoringThe vector is built as you toggle metrics and cannot disagree with the score, so the time goes on whether the rating is right rather than on transcribing a string.
  • ReviewQA is a workflow with states, anchored comments and three explicit actions, so a reviewer spends the time reviewing instead of maintaining a list of things they meant to mention.
  • The retestThe original findings carry forward and each is marked fixed, still open or newly introduced, so the second report is about what changed rather than written again.
  • InvoicingRaised against the engagement it belongs to, on your own template, and synced to Xero, so month end is a check rather than a reconstruction.
Your Number

Work It Out for Your Own Firm.

This takes about ten minutes with your last three engagements in front of you, and the result is defensible in a way a vendor average never is.

  1. 01Take your last three reports and count the findings in each. Multiply by the honest average time your team spends writing one up from evidence, including the scoring and the references.
  2. 02Add the hours spent assembling and formatting the document, and the executive summary, per engagement.
  3. 03Add the round trip: review comments, applying them, and putting the changes back into whatever holds your findings today. For most firms this is the number that surprises them.
  4. 04Add the admin that is not billable: chasing scope, chasing signatures, chasing invoices, and producing attestation letters on request.
  5. 05Now run one engagement through the trial and measure the same four numbers. The difference is your figure, in your house style, on your kind of work.
Price It, Do Not Just Count It

Hours saved on delivery are only interesting once they are converted. Multiply them by your day rate to get what the time is worth, and by your utilisation target to see how many more engagements a year the same team could take without hiring. Those are the two numbers that make the case to whoever signs.

The Second Year

The Saving Grows Without Anybody Working on It.

A tool that saves the same amount every month is a tool. The parts of this that accumulate are the ones worth choosing a platform for.

  • The library gets betterEvery finding saved into it improves the starting point for the next engagement, and improving one write-up improves every future use of it.
  • The template is built onceYour Word template is mapped once in the report builder and then fills itself for every engagement afterwards, including the invoice, proposal and attestation.
  • Methodology stops being retoldChecklists and runbooks are written once in settings and attach to the phases they belong to, so onboarding a new tester is reading rather than shadowing.
  • Prompts get tunedEvery generated field uses a prompt you can rewrite. Ten minutes spent on the remediation prompt in month one changes every remediation after it.
  • The client answers their own questionsStanding portal accounts mean the requests for old reports, findings status and attestation letters stop arriving as email at all.
The Point of It

What the Hours Are Actually For.

The reason to take admin out of an engagement is not the admin. It is that the same team can do more of the thing clients are paying for, and do it better.

  • More testing inside the same dayHours that were going on document mechanics go back into the part of the engagement that finds things.
  • Deeper reviewWhen applying review comments is not itself a job, reviewing properly stops being the step that gets compressed when a deadline moves.
  • Reports that read betterRemediation written for the developer who has to action it, rather than the version that got written at seven in the evening.
  • Capacity without hiringThe difference between turning work away and taking it is often a handful of delivery days a month.

Measure It on Your Next Engagement.

Seven days free, no card, and the whole platform inside Starter limits. Run one real piece of work through it and compare the four numbers above against the last one you did the old way.