20 May, 2020

Can We See a Sample Report from a Penetration Test?

Can We See a Sample Report from a Penetration Test?
Kevin Tackett
Author: Kevin Tackett
Share:

If you are thinking about engaging a security consulting company, at some point you will probably be wondering what you will get out of it. Asking to view a sample report is a common request. After all, the report will contain your takeaways, making it one of the most critical parts of the engagement. In fact, you should think twice about working with any security company who refuses this type of request.

Looking for Ours? It's Right Here!

Download a Sample Penetration Testing Report

Download a Sample Network Testing Report

Not all reports are the same, so it is important to review the sample to determine if it meets your needs. If it doesn't, don't be afraid to ask for modifications. Many security companies (including us, of course) are more than happy to make accommodations as needed.


What's in the Report?

Sections covered:

  • An executive summary
  • Narrative of the testing
  • Findings and Recommendations
  • Strategic Guidance

Details within the findings should cover:

  • Explanation of the issue found
  • Details of why the issue is a problem, including its risk rating
  • Replication details so you can verify this finding and test for it in the future
  • Recommendations on remediating the issue

For more details on deliverables, feel free to read the What is in a Penetration Test Report article.

We want to have a sample that is as realistic as possible, without needing to redact details. The report below used a known vulnerable application, OWASP Juice Shop. This target allows the report to have the information that is customarily redacted.

To be clear, though, we did not perform an exhaustive test of Juice Shop. There are a couple of reasons. First, no one wants to read the enormous number of pages that would generate. Second, we did not want to ruin the fun of testing Juice Shop during a training class or as a hobby.

Have questions about our reports or ready to get started?

Our deliverables are thorough, actionable, and written for both technical and executive audiences. Reach out to discuss your security assessment needs.

Talk to Our Team