- Job title
- System support specialist
- Sector
- Cosmetics
- Organization type
- medium-sized business
- Joined
- Apr 2025
- Message
- 15
We are a London-based B2B cross-border e-commerce and logistics software company with 25 employees. To sign a deal with a new enterprise client, we were required to have an independent penetration test conducted. We hired a security firm on the market and paid 3,500 GBP for the test. Following the assessment we received a 40-page PDF report.
The problem is that 25 pages of the report are just raw screenshots from an automated scanning tool and generic definitions about TLS certificates. We couldn't find a concise summary we could present to our board or the client. Since this is the first time we've ever received a penetration test report, we can't tell whether this document is truly high-quality and up to industry standards.
Where can we find good, sanitized or older sample penetration testing reports? What sections are absolutely essential in a professional report, and what are the dead giveaways of a poor one?