If your pen test report looks like tool output with a cover letter, you didn't really get a pen test.

Real penetration testing starts before there's a signature on the statement of work. It starts with the question of what's actually keeping the client up at night, what makes their environment different from the last one, and how an attacker would adapt to that. In the short video above, Eric Buck walks through the philosophy that separates a tailored engagement from a templated one.

 

Watch the full conversation

Tired of pen test reports that read like a tool printout?

Get in touch to scope an engagement built around what's actually unique about your environment.

Talk to our team

The tool-output problem

There's a category of pen test report that buyers in this industry know on sight. It's a stack of CVE numbers, severity ratings, a few network diagrams pulled straight from a scanner, and an executive summary written to fit the same template the vendor uses for every client. The findings are technically accurate. They're also indistinguishable from what the client could have generated themselves by running the same tools.

That kind of report has a place. It's not a pen test. It's a vulnerability assessment with a different word on the cover. The reason that distinction matters is that buyers paying for the higher-priced engagement aren't getting what they're paying for, and the security team reading the report doesn't get anything they can act on that they didn't already know.

The work happens before the engagement starts

A real pen test starts with conversations, not scans. Before the kickoff call, before the statement of work, the testing team is trying to understand the client. What are they

Submit a comment

You may also like

Purple Team vs Pentest: Which Does Your Org Need First?
Purple Team vs Pentest: Which Does Your Org Need First?
19 May, 2026

Your browser does not support embedded video. Download the video. Purple team exercises are one of the most effective wa...

The Dark Web Prep Work Behind Every Pen Test
The Dark Web Prep Work Behind Every Pen Test
26 May, 2026

Your browser does not support embedded video. The work that happens before the test is what makes the test useful. Every...

Is Our Code Secure? Why You Need More Than Your Vendor's Word
Is Our Code Secure? Why You Need More Than Your Vendor's Word
22 May, 2026

Your browser does not support embedded video. Download the video. Every custom software vendor will tell you their code ...