A penetration test is one of the most valuable investments an organisation can make in its security posture, but only when it is done properly. Too many organisations walk away from a pentest with a polished PDF, a false sense of security, and a set of findings that never translated into real risk reduction. If you are wondering whether your last engagement delivered genuine value, these six signs will help you find out.
What a thorough pentest actually delivers
A well-executed penetration test goes far beyond running automated scans and packaging the output into a report. It simulates the tactics, techniques, and procedures of a real attacker, probing your systems, applications, and people with creativity and persistence. The result should be a clear picture of what an adversary could actually achieve, how far they could move through your environment, and what the business impact would be.
Genuine penetration testing produces actionable, prioritised findings with enough technical detail for your team to reproduce and fix each issue. It also includes strategic context so leadership can understand risk in business terms, not just technical jargon. If your last report fell short of that standard, here is what likely went wrong.
Sign 1: The report reads like scanner output
Automated vulnerability scanners are useful tools, but they are not a substitute for human expertise. If your pentest report lists dozens of findings with generic descriptions, CVSS scores copied from a database, and remediation advice that reads like a vendor knowledge base article, the tester likely relied on scanner output rather than manual investigation.
A meaningful report explains how vulnerabilities were discovered, what exploitation would look like in practice, and which findings are most dangerous in the context of your specific environment. Generic, template-style language is a strong indicator that little original analysis took place.
Sign 2: No evidence of manual exploitation attempts
One of the defining characteristics of quality penetration testing is manual exploitation. A skilled tester does not just identify a vulnerability, they attempt to exploit it to demonstrate real-world impact. If your report contains no proof-of-concept screenshots, no evidence of privilege escalation attempts, and no narrative describing what the tester actually tried, the engagement likely stopped at identification rather than exploitation.
Manual exploitation is what separates a pentest from a vulnerability assessment. Without it, you do not know which vulnerabilities are truly exploitable in your environment, and you cannot prioritise remediation with confidence.
Sign 3: The scope was suspiciously narrow
Scope limitations are sometimes necessary and legitimate, but a scope that excludes large portions of your attack surface without a clear business reason is a red flag. Attackers do not respect artificial boundaries. If critical systems, cloud environments, internal networks, or third-party integrations were excluded without explanation, your organisation may have significant blind spots.
A thorough pentest scopes the engagement based on realistic threat scenarios, not on what is easiest or least disruptive to test. If the tester did not push back on an overly narrow scope or explain the risks of exclusions, that is a problem in itself.
Sign 4: Findings lacked business context
Technical findings only create value when they are connected to business risk. If every vulnerability in your report was rated purely on technical severity without any consideration of what data is at risk, what regulatory implications exist, or what the operational impact of a breach would be, the report is incomplete.
Security decisions are made by people who balance risk against cost, operational continuity, and strategic priorities. A pentest report that speaks only in technical terms forces those decision-makers to guess at the business relevance of each finding, and that guesswork often leads to the wrong priorities.
Sign 5: No retesting was included or offered
Fixing a vulnerability is only half the job. Verifying that the fix actually works is the other half. If your pentest engagement did not include a retesting phase, or if retesting was not even offered as an option, you have no independent confirmation that your remediation efforts were effective.
Retesting is a standard component of a mature penetration testing engagement. It closes the loop between finding and fixing, and it gives your organisation documented evidence that identified risks have been addressed. Without it, you are trusting your own team’s assessment of their own work, which is not the same as independent validation.
Sign 6: The tester couldn’t answer follow-up questions
A skilled penetration tester understands every finding in their report well enough to explain it clearly, answer technical questions from your developers, and discuss remediation options in depth. If you or your team asked follow-up questions and received vague responses, boilerplate answers, or silence, that is a serious quality indicator.
The debrief and post-engagement support phase is where a lot of the real value of penetration testing is realised. Testers who cannot engage meaningfully with your team after delivery are often testers who did not fully understand what they found, or who did not find it themselves.
How to demand more from your next pentest
Before engaging a penetration testing provider, ask direct questions: How much of the testing is manual versus automated? Will findings include proof-of-concept exploitation? Is retesting included? Can I speak with the tester directly after delivery? The answers will tell you a great deal about the quality of the engagement you can expect.
You should also look for a provider who takes time to understand your environment, your threat model, and your business context before scoping the engagement. A pentest that is designed around your actual risk is worth far more than a standardised package built for convenience. We work with organisations across the Netherlands and the broader EU to deliver vendor-independent security expertise that goes beyond checkbox compliance. If you want to understand what a rigorous engagement looks like for your organisation, get in touch with us and we will walk you through it.
Frequently Asked Questions
Wat is het verschil tussen een penetratietest en een vulnerability assessment?
V: Wat is het verschil tussen een penetratietest en een vulnerability assessment?nA: Een vulnerability assessment identificeert zwakke plekken in je systemen, maar stopt daar. Een penetratietest gaat verder door die kwetsbaarheden ook handmatig te proberen te misbruiken, zodat je precies weet welke risico's écht uitgebuit kunnen worden in jouw specifieke omgeving en wat de werkelijke impact zou zijn.
Hoe vaak zou een organisatie een penetratietest moeten laten uitvoeren?
De meeste organisaties laten jaarlijks een penetratietest uitvoeren, maar de ideale frequentie hangt af van je risicoprofiel, de snelheid waarmee je omgeving verandert en eventuele compliancevereisten. Na grote infrastructuurwijzigingen, nieuwe applicaties of beveiligingsincidenten is een extra test sterk aan te raden.
Waarom is retesten na het oplossen van kwetsbaarheden zo belangrijk?
Retesten geeft onafhankelijke bevestiging dat een gevonden kwetsbaarheid daadwerkelijk correct is opgelost, iets wat je eigen team niet objectief kan beoordelen. Zonder retesten heb je geen gedocumenteerd bewijs dat de risico's zijn weggenomen, wat problemen kan opleveren bij audits, klanten of toezichthouders die om aantoonbare verbeteringen vragen.
Welke vragen moet ik stellen voordat ik een penetratietestprovider kies?
Vraag altijd hoeveel van het testwerk handmatig plaatsvindt, of bevindingen worden ondersteund met proof-of-concept exploitatie en of retesten is inbegrepen. Informeer ook of je direct contact kunt hebben met de tester na oplevering, want een provider die hier open over is, levert doorgaans een aanzienlijk grondiger en betrouwbaarder engagement.