Penetration Test Retesting: Proving a Fix Actually Worked
A successful security assessment doesn’t end when you receive a list of vulnerabilities; it concludes only when those risks are demonstrably closed….
Read articleMost of what decides whether a penetration test is useful happens before testing starts: what went into scope, how much information the tester was given, and how long they had. These articles cover commissioning and running an engagement, from scoping and methodology through to reading the report and proving the fixes held.
31 articles
A successful security assessment doesn’t end when you receive a list of vulnerabilities; it concludes only when those risks are demonstrably closed….
Read articleHow findings get validated before they reach your team, why false positives cause friction with developers, and what to ask your tester.
Read articleFrom draft report to retest: the debrief, the remediation window, and the decisions that determine whether the test was worth commissioning.
Read articleCVSS, tester-assigned severity and business risk are three different things. How to read the ratings in your report without over-reacting.
Read articleWhat each section of a penetration test report is for, which parts matter to whom, and the details that reveal how the testing was done.
Read articleHow to tell consultant-led testing from a rebranded scan: accreditation, methodology, reporting samples and the questions that expose the difference.
Read articleTurning a technical report into a board conversation: what directors need to decide, how to frame risk without a CVE list, and the questions that come back at you.
Read articleBuilding an internal case for testing spend using scope, risk and assurance obligations rather than fear.
Read articleRoles, user journeys, APIs and environments. The scoping decisions that decide whether a web application test finds anything worth having.
Read articleWhere an internal team adds value, where independence matters, and how most organisations end up running both.
Read articleTwo different models with different coverage guarantees. What each finds, what neither covers, and when running both makes sense.
Read articleWhat scanners are genuinely good at, the flaw classes they cannot reach, and how the two fit together in a testing programme.
Read articleHow much information to give a tester, what each approach costs you in coverage, and why grey box is usually the right answer.
Read articleReconnaissance through to reporting and retest, and what a tester is actually doing at each stage of an engagement.
Read articleA first-time buyer's walkthrough: scoping calls, rules of engagement, testing windows, findings as they land, and the report at the end.
Read articleWhat CREST assesses, what the individual certifications cover, and what accreditation does and does not guarantee about an engagement.
Read articleHow UK testing firms differ on delivery model, accreditation and reporting, and how to compare quotes that look similar on paper.
Read articleThe sections that matter in a testing proposal — scope, methodology, team, deliverables, retest terms — and the gaps that cause disputes later.
Read articleGetting scope right decides what a test can find. Asset inventory, environments, credentials, exclusions, and the mistakes that waste days.
Read articleWhat an internal assessment looks for once an attacker is already inside: credentials, lateral movement, and the path to domain admin.
Read articleDeciding what counts as your perimeter, handling cloud-hosted assets and third-party providers, and keeping the scope honest.
Read articleWhat if the lowest infrastructure penetration testing quote you receive is actually the most expensive mistake your security team makes this year?
Read articleIdentity, managed identities, RBAC, storage exposure and network controls: how an Azure environment is assessed and where it usually leaks.
Read articleIAM, S3, roles and trust relationships, plus what AWS permits you to test. How cloud testing differs from a traditional infrastructure test.
Read articleShared responsibility in practice: what your provider secures, what remains yours to test, and how cloud engagements get scoped.
Read articleWhat penetration testing is, the main engagement types, how testing is delivered, and where it fits alongside continuous assurance.
Read articleWhat CREST approval means for how an engagement is run, what evidence you can ask a provider for, and when it is worth insisting on.
Read articleThe questions that separate consultant-led testing from automated scanning, covering methodology, team, reporting and retest terms.
Read articleWhat drives the price of a penetration test, what a sensible scope looks like for a smaller organisation, and how to avoid paying for a scan.
Read articleWhy quotes for the same application vary so widely, what a day rate actually buys, and how to compare proposals on a like-for-like basis.
Read articleWhat organisations get from testing beyond a list of vulnerabilities: validated risk, evidence for customers, and a plan worth acting on.
Read articleCREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.