Skip to content
Back to the blog

Why your pentest report ends up in a drawer

A penetration test report nobody reads has secured nothing. The problem is rarely technical — it is how the risk gets presented to the people who decide.

2 min readCybersecurity

I have seen technically excellent penetration test reports handed to organisations that fixed nothing for eighteen months. That is not negligence. It is a translation problem.

The CVSS score decides nothing

A conventional report ranks findings by score. It is reassuring, reproducible, and close to useless for the person who has to arbitrate a budget. A 9.8 on an internal service three people can reach often matters less than a 6.1 on the portal every customer touches.

Leadership does not reason in scores. It reasons in consequence, likelihood and cost of the fix. A report that does not supply those three axes forces the reader to do the translation themselves — and they will not.

What goes in the first three pages

Nothing technical. Three questions, three answers:

  • What can an attacker obtain today, concretely?
  • How long would it take them, at what skill level?
  • What changes if you fix the top three items on the list?

If each answer fits on a page and reads without a glossary, the rest of the report will reach the right people.

The technical detail stays intact

None of this removes the technical section. Teams need the exact path, the requests, the versions, the timestamped logs. That detail comes afterwards, in a document the developer can open at the right section without reading the fifty pages before it.

Two readings, one document. That is the structure that works.

Rank by what the fix prevents

The final ordering is not by score but by blocking effect. A fix that cuts three distinct attack paths goes ahead of one that cuts a single path, even with a lower score. It is the only hierarchy that makes sense to someone choosing where to spend two weeks of effort.

A security report is not an inventory. It is an argument.

The penetration test produces knowledge. The report decides what happens to that knowledge. It is usually the least technical part of the engagement, and consistently the part that determines whether it was worth anything.

  • pentest
  • governance
  • communication
Share on LinkedIn

Also available in Français