- Job title
- Software developer
- Sector
- Printing
- Organization type
- early-stage startup
- Joined
- Apr 2026
- Message
- 129
We are a mid-sized wholesale trading company. We have both a B2B ordering portal and an in-house ERP system. Due to an audit requirement from one of our clients, we hired a cybersecurity firm to run a penetration test. Yesterday evening, they sent over a 42-page report.
We opened the report during our management meeting, but we couldn't make heads or tails of it. It's packed with dozens of technical terms like SQL injection, cross-site scripting, vulnerability scores, CVE codes, etc. The only thing the firm told us was that there are critical findings in our system and they need to be remediated immediately. However, on the IT side, we only have a single system admin, and he claims all of this is an exaggeration and that the system is running smoothly without issues.
What exactly is a pentest report, and where should a non-technical company executive look when handed one? How do we assess the severity of the findings, and in what order should we assign tasks to the developer or system admin?