What a penetration test actually buys you
A scan lists software versions. A pentest tells you whether someone can reach payroll. Here is how to buy the second one.
ITSIGN Administrator · January 8, 2025 · 2 min read
A vulnerability scan is a grocery list. A penetration test is someone walking into the store, taking the till, and showing you the camera angle you missed.
Canadian mid-market firms often buy the first and file it as the second. Underwriters and enterprise customers can tell the difference. They ask for the rules of engagement, the tester's credentials, and whether you retested the priority findings.
What you should walk away with
A ranked path to impact, evidence, and a remediation workshop. Not a severity score in isolation. If the report cannot name the business system that would have been reached, you paid for a scan.
We write findings so an engineer can close them and a director can brief a board in ten minutes. That is the penetration testing we sell.
How not to waste the money
Scope the systems that would hurt: identity, email, ERP, the shop-floor link. Exclude the abandoned marketing VM. Include a retest. If the tester is not allowed to use valid credentials on an internal test, you are paying to rediscover the front door.
Related reading
When a pentest is really for the insurance form
Be honest about the audience. Then still do the work so the form is not the only thing you get.
2 min read
Why the retest is the part you should not skip
A finding list without a retest is homework you never marked. Insurers and customers notice.
2 min read
Scoping a pentest without wasting money
Narrow the crown jewels. Write rules of engagement. Budget the retest. Everything else is theatre.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
