- Job title
- Purchasing manager
- Sector
- Sports and fitness
- Organization type
- 20-person company
- Joined
- Apr 2023
- Message
- 2
We are a 12-person software agency. We recently conducted a comprehensive penetration test on a B2B order portal for a long-time corporate retail client of ours. We completed the testing phase with our internal tech team, but the task of putting together the final pentest report has fallen on me. We committed to a security audit with a budget of around 45.000 TL, and this is the first time we'll be delivering something this formal at this scale.
I have automated scanner outputs, manually identified privilege escalation flaws, and a few screenshots of parameter manipulation exploits. However, both their IT manager and their non-technical VP will be reading this report. How should I strike a balance between deep technical details and language upper management can digest? What criteria should I use to classify risk levels, and what standard sections need to be included in the report?