Who Really Gets Something Out of a Pentest? Not Just Your Security Team
For founders and CTOs deciding whether a penetration test is worth the budget: what it returns, to whom, and when it returns nothing
Who Really Gets Something Out of a Pentest? Not Just Your Security Team
For founders and CTOs deciding whether a penetration test is worth the budget: what it returns, to whom, and when it returns nothing
Photo by Annie Spratt on Unsplash
A penetration test is an awkward purchase. It costs real money, it takes a few weeks, and what you get at the end is a document listing what is wrong with your systems. Nobody enjoys paying for bad news.
When founders ask me whether it is worth it, I find the honest answer depends on who in the company you ask. The security lead, the sales team, the auditor, the insurer, the engineers and the board all get something different out of the same engagement. And every one of those returns disappears if the test itself is not real.
So here is how I break it down: the return for each group, then the conditions that decide whether you see any of it.
Security gets proof instead of a list
A vulnerability scanner hands you a list. A penetration test hands you proof, and that difference decides what gets fixed first.
- Exploitability, not severity scores. A scanner’s critical rating may sit on a service nobody can reach, while a medium may be the first step of a chain that ends in your customer database. A tester finds out which is which by trying.
- Findings no tool can produce. Authorization flaws between users, multi-tenant isolation failures, business logic abuse and chained attack paths are what fill breach reports, and none of them has a signature a scanner can match.
- The whole path, not the pieces. The report shows how one foothold turned into a real compromise: which credential, which trust relationship, which forgotten host. Fixing the path does more than fixing the list.
- A real check on the controls you already bought. The firewall, the endpoint agent, the MFA rollout, the segmentation project. A test is the one moment someone independent pushes on them the way an attacker would.
There is also a side benefit most teams do not plan for. Even a cooperative test produces the signals of a real intrusion: scanning, failed logins, unusual lateral movement. Watching which of those your security team noticed, and how fast, is a free rehearsal and a preview of the red team exercise that usually comes later.
Audit gets the evidence that is asked for by name
Most security frameworks describe controls in general language. Penetration testing is one of the few things they name directly.
- PCI DSS Requirement 11.4 calls for external and internal penetration testing at least annually and after significant changes, plus testing of segmentation controls.
- NYDFS 23 NYCRR 500.5 requires covered financial entities to run annual penetration testing.
- SOC 2 auditors expect penetration testing evidence for the Security criteria, from a party independent of engineering.
- HIPAA requires a technical evaluation of safeguards, and a penetration test is the accepted way to provide it.
- ISO 27001, CMMC, the GLBA Safeguards Rule and cyber insurance applications all ask for the same thing in their own words.
What you get is a report and an attestation letter that go straight into the audit file. That is faster and cheaper than explaining to an auditor why you do not have one.
Sales and insurance get answers before the question is asked
Enterprise buyers send security questionnaires, and those questionnaires ask when your last third-party penetration test was, what it covered and whether the serious findings were fixed. With a recent test and a shareable summary, you answer in a day. Without one, you either lose the deal or spend a quarter getting tested while the buyer waits.
The return compounds. One test answers every questionnaire for a year, satisfies the SOC 2 auditor and gives the sales team a document to send before anyone asks. If a buyer wants ISO 27001 instead, the same test can serve both. For software companies, I would argue a pentest is as much a revenue tool as a security one.
Insurance works the same way. Cyber insurance applications increasingly ask whether your network and applications were tested in the last year, next to the questions about MFA and backups. A yes affects eligibility and, with some carriers, the premium.
It also matters after something goes wrong. A documented testing program is part of showing that reasonable security measures were in place, which counts under state rules such as the CCPA, Massachusetts 201 CMR 17.00 and the FTC Safeguards Rule. It counts with the carrier deciding whether to pay, too.
Engineering and leadership get something they can act on
A good report is written for the people who will do the fixing. In practice that means:
- Reproduction steps with the exact request and response, so a developer sees the flaw in minutes instead of debating whether it exists.
- Remediation guidance that names the fix, not only the problem.
- No false positives, because every finding was proven by hand before it went into the report.
- A retest, so the fix is verified by the person who found the flaw and the report shows it closed. I include a free retest in every engagement for exactly this reason.
The outcome is a security backlog engineers respect, and in my experience that is the only kind of backlog that gets worked.
Leadership reads a different part of the same document. The executive summary answers what a board or an owner actually wants to know: how an attacker would get in, what they would reach, how long it would take, how serious it is and what fixing it costs. That is a better basis for a budget decision than a vendor’s pitch or a news headline, and it leaves a record that the company examined its own security and acted on what it found.
Four conditions, or none of this happens
Every return above assumes the test was real. In our engagements I see four conditions decide that.
- It is manual. A scanner report with a cover page delivers none of the findings that matter, and auditors and customers do not accept it as a penetration test. Ask who does the work. Ours is done by senior in-house testers, manual-first, with no subcontractors.
- It is scoped honestly. A test of one login page tells you nothing about the API behind it. Scope to what the request is actually about.
- The findings get fixed. A report sitting in a folder is a liability, not an asset. The retest is where the benefit becomes real.
- It is repeated. Applications and networks change. Annual testing is the floor, and teams that ship often run a continuous program.
A pentest report nobody acts on is not an asset. It is written proof that you knew.
Weighing the price against the return
We price every engagement as a fixed amount agreed in writing before work starts: API testing from $4,000, external network from $4,200, web application from $5,200 and internal network from $6,000, each with a free retest included.
Put that next to a lost enterprise deal, a declined insurance application, a failed audit or the cost of an incident a test would have caught. The arithmetic is rarely close.
The short version
- A pentest proves what is exploitable; a scanner only lists what might be wrong.
- Compliance frameworks such as PCI DSS, SOC 2, HIPAA and NYDFS ask for penetration testing by name.
- One recent test answers a year of enterprise security questionnaires and insurance application questions.
- Engineers act on findings that come with reproduction steps, named fixes and a retest.
- None of it holds unless the test is manual, honestly scoped, fixed and repeated.
This article is based on Invadel’s guide “The Benefits of Penetration Testing: What You Actually Get for the Money”: https://invadel.com/blog/benefits-of-penetration-testing/ — read it for the full detail. Mark Kiss is the founder of Invadel, a penetration-testing firm — https://invadel.com/ has the services and fixed prices.
메타데이터
- post_id
- 2a573aeff11a
- slug
- who-really-gets-something-out-of-a-pentest-not-just-your-security-team-2a573aeff11a
- url
- https://medium.com/@invadel/who-really-gets-something-out-of-a-pentest-not-just-your-security-team-2a573aeff11a
- canonical_url
- https://medium.com/@invadel/who-really-gets-something-out-of-a-pentest-not-just-your-security-team-2a573aeff11a
- author_url
- https://medium.com/@invadel
- status
- ok
- fetched_at
- 2026-10-01 19:12:34