3 ms·
Some of this can be covered by the methodology section, where the pen testers shows the approach taken and has an overview of what they did. There's a happy med
by kenbaylor 11y ago
Some of this can be covered by the methodology section, where the pen testers shows the approach taken and has an overview of what they did.
There's a happy medium between one-line reports 'nothing found' (which encourages questions like 'did you even try?'), to the voluminous crap produced like old vulnerability scanners. Providing the report template in advance may help set expectations.
The industry is moving towards standards based pen testing. That has some pros but many cons as well. For the moment, setting expectations and having a thorough debriefing with the customer may have to do.
Your question is the scientific one: How do I know what you did was good enough. Just like a patient evaluating a medical professional care, the customer isn't an expert and goes with their gut in some cases. That's why the industry also wants you to use different pen testers. I've seen many a time, when one team finds nothing, and another rips the infrastructure apart. Competency is a variable over time and so is trust.
TLDR: The scientific question does not have a simple fix by any means.
- tptacek 11y agoI'm not sure I follow here. Is your firm getting access to pentest reports from the consultancies it matches to clients? That seems untenable; clients tend to be very possessive about those reports. Is your firm instead relying on self-assessment by clients? Then, like Ferruh Mavitunah said, I'm not clear how this system can work: most clients aren't qualified to evaluate the effectiveness of a pentest, and will instead evaluate based on soft-skills. I have another business question. The most lucrative clients across the board are "house accounts" that source repeated tests from a single firm. When one of these companies sources a consultancy through your market, what prevents them from bypassing you for all future engagements? This is a race-to-the-bottom problem that plagues freelancer programming markets.