- Job title
- Board member
- Sector
- Livestock
- Organization type
- a company within a holding
- Joined
- Jan 2024
- Message
- 209
Doki · Server maintenance contract · 2025
We're a 14-person B2B software company based in Lyon. Last week, we hired an external cybersecurity specialist for 4,500 Euro, and our first penetration testing engagement targeting our customer portal infrastructure kicked off. They're delivering the report next week, but because our in-house technical team is small we aren't entirely sure how to evaluate the document they hand over.
An acquaintance of mine previously complained about firms that just copy-paste the English output from an automated vulnerability scanner and hand it over as an empty 70-page PDF. Our goal is to both see a clear summary that explains the risks to company management and get actionable steps our developers can fix right away.
What main sections should be in a solid pentest report what evidence and details should be provided for each finding and what should our core criteria be to recognize an inadequate report and push back?