A penetration test the board could act on
This was the client's third penetration test in four years. The first two reports were thorough, technically correct, and had produced almost no change. The findings were real. They just never survived the journey to a budget decision.
The pattern was familiar. A report arrives rated critical, high and medium; it reaches a leadership team who cannot tell what any of it means for the business; and it is filed with the best of intentions.
How we ran it
The testing itself was ordinary work: external perimeter, the main customer application, and the internal network from the position of a compromised workstation. What changed was how each result was written up.
Every finding carried three things:
- What an attacker could reach, demonstrated rather than asserted
- What that would cost this business specifically, in their own terms
- What it would take to fix, in effort a manager could put against a quarter
One finding chained three low-severity issues into read access on the customer database. Rated individually, all three had been accepted as low risk in a previous report.
What changed
We presented to the leadership team ourselves, without the technical team having to translate on our behalf. The chain above took four minutes to explain and needed no security background to follow.
Remediation was approved in that meeting. Not because the findings were more severe than last time, but because for the first time the people holding the budget could see what they were buying.
The technical team had known all of this for two years. They had not been ignored; they had been asking in a language the room did not share.