forumNew topic

We're getting our first pentest report, what should a good report include and what should we watch out for?

GGizem Y***Member
Job title
Board member
Sector
Livestock
Organization type
a company within a holding
Joined
Jan 2024
Message
209

Doki · Server maintenance contract · 2025

#1

We're a 14-person B2B software company based in Lyon. Last week, we hired an external cybersecurity specialist for 4,500 Euro, and our first penetration testing engagement targeting our customer portal infrastructure kicked off. They're delivering the report next week, but because our in-house technical team is small we aren't entirely sure how to evaluate the document they hand over.

An acquaintance of mine previously complained about firms that just copy-paste the English output from an automated vulnerability scanner and hand it over as an empty 70-page PDF. Our goal is to both see a clear summary that explains the risks to company management and get actionable steps our developers can fix right away.

What main sections should be in a solid pentest report what evidence and details should be provided for each finding and what should our core criteria be to recognize an inadequate report and push back?

GGökhan K***Member
Job title
Software team lead
Sector
Packaging
Organization type
20-person company
Joined
Feb 2022
Message
207
Most Helpful#2

Short answer: A solid pentest report should consist of an executive summary outlining business risks in plain English for management, alongside technical finding cards that allow developers to reproduce each vulnerability step by step. You should flat-out reject and demand revisions for reports that just dump raw automated scanner outputs, lack manual verification, and are detached from your business context.

A good report opens with an executive summary that outlines which systems were assessed, the overall security posture, and the commercial risks the company could face without drowning the reader in technical jargon. The second main part is the technical findings. For every vulnerability identified, this section should provide a standardized risk score, what the flaw is, proof-of-concept evidence like screenshots or request-response logs so developers can reproduce it locally, and concrete remediation steps to close the gap.

Your criteria for rejecting a subpar report should be: 1) It only lists automated tool outputs without false-positive verification, 2) It gives generic descriptions instead of explaining how the vulnerability affects your actual business logic, 3) It offers boilerplate advice rather than specific code or configuration recommendations to resolve the flaw. Additionally, any professional contract should include a commitment to a free re-test once you complete your fixes.

KKoray Ç***Member
Job title
Network Administrator
Sector
Tourism
Organization type
sole proprietorship
Joined
Apr 2025
Message
55

Doki · Penetration test · 2026

#3

Look at the CVSS scoring logic for each vulnerability in the report. A generic 'Critical' or 'Medium' tag isn't enough. The vector string should be explicitly stated, and request bodies or PoC commands proving the finding is genuinely exploitable must be included. Without those, your developers will be flying blind when trying to patch it.

HHande B***Member
Job title
Operations manager
Sector
Sports and fitness
Organization type
boutique agency
Joined
Jun 2023
Message
353
#4

When the report lands on your desk, check these three things: 1) Did they go out of scope, or did they scan all the subdomains outlined in the contract? 2) Can each finding's vulnerability be reproduced step by step? 3) Are the remediation recommendations tailored to your OS and the libraries you actually use?

edit: I wrote something wrong above, sorry about that.

AAycan O***Member
Job title
Front office accounting
Sector
Paper
Organization type
8-person team
Joined
May 2022
Message
6
#5

On our first test in Paris, which we paid 5,200 Euro for, we got 48 findings. Upon review, we realized 22 were just trivial server version banners. We pushed back, filtered them out, and focused on the remaining 6 critical flaws. It's not the page count of the report that matters, it's the number of verified critical findings.

MMert B***ExpertCommunity member
Joined
Sep 2024
Message
129
#6

Set up a meeting with your developer once the report is delivered. Try triggering the top two highest-priority vulnerabilities directly in your dev environment using the exact steps described in the document. If your dev can't reproduce the issue by following those steps, the report is deficient—ask the pentester for a live demo.

JJülide A***Member
Job title
Accounting Manager
Sector
Jewelry
Organization type
20-person company
Joined
May 2024
Message
103

Doki · Vulnerability scanning · 2026

#7

we panicked seeing pages of ssl warnings in our first report turns out the scanner just dumped it automatically. the guy hadn't even manually tested a single api injection. tbh reject any report that doesn't have screenshots or payloads right away.

note: I wrote this based on my own experience, it might not apply to everyone.

FFiliz S***Member
Job title
Software developer
Sector
Printing
Organization type
early-stage startup
Joined
Apr 2026
Message
129
#8

Did you agree on a black-box or white-box scope when drawing up the contract? If you gave them source code or a test account, the report should document much deeper logical privilege escalation flaws. The scope type directly dictates what you should expect from the report.

SSinan Y***Member
Job title
Graphic Designer
Sector
IT services
Organization type
early-stage startup
Joined
Dec 2023
Message
25
#9

Most companies shelve the pentest report the moment they get it. Just as critical as the report's quality is whether your deal includes a post-remediation re-test. If a re-test isn't included, that report is nothing more than an expensive document showing past issues.

YYağmur P***Expert
Job title
Customer Relations Manager
Sector
Electrical-electronics
Organization type
120-person company
Joined
Jun 2025
Message
405
#10

I felt relieved reading this answer, so it's not just me. An automated scan report is not the same as a penetration test.

I'm also curious if anyone does it differently.

HHasan Ö***MemberCommunity member
Joined
Dec 2025
Message
50
#11

Three different views emerged, they all complement each other. An automated scan report is not the same as a penetration test.

Hope this helps.

YYağmur P***MemberCommunity member
Joined
Jun 2025
Message
286
#12

If you're going this route, sort this out first. Don't hesitate to ask; those who don't ask always pay more.

Good luck with that.

OOrhan K***MemberCommunity member
Joined
May 2023
Message
83
#13

This thread is archived.

BBuseNew member
Job title
Fashion blogger
Organization type
early-stage startup
Joined
Sep 2024
Message
48
#14

noted thanks.

HHasan A***Expert
Job title
Customer service representative
Sector
Accounting & advisory
Organization type
family business
Joined
Nov 2025
Message
102
#15

You're right, I've been down that road too. Just because everyone does it doesn't mean it's right.

Correct me if I'm wrong.

YYasemin Y***Expert
Job title
Sales Manager
Sector
Machinery manufacturing
Organization type
a company within a holding
Joined
Aug 2022
Message
46
#16

do you think this works at any scale? if you get three different answers on a topic the question was asked wrong.

the answer varies greatly by industry; there is no one-size-fits-all rule. good luck with that.

PPınarExpert
Job title
Analytics Specialist
Joined
Jan 2024
Message
198

Doki · Mobile app · 2025

#17

You're right.

YYasemin S***MemberCommunity member
Joined
Feb 2024
Message
42
#18

There's a common mistake people make when doing this. If 2FA is on, a stolen password alone is useless.

If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection. If you have questions, write them; I'll answer as best I can.

BBeyza K***Member
Job title
Field sales representative
Sector
Advertising and promotion
Organization type
two-branch business
Joined
Feb 2024
Message
6

Doki · Log management setup · 2026

#19

Timely topic.

HHatice Ç***MemberCommunity member
Joined
Sep 2025
Message
2
#20

i agree, and I'd like to emphsize that... processes without records never improve, because you don't know what to fix.

the answer varies greatly by industry; there is no one-size-fits-all rule. this is my opinion, I'm not claiiming it's absolute truth.

Reply