If you are responsible for protecting an organisation’s systems, data or digital services, penetration testing is likely to form an important part of your security assurance programme. But knowing that you need a test is only the first step. The more difficult question is how to select a penetration testing provider that will give you meaningful insight, practical recommendations and confidence that your risks are being properly assessed in a controlled manner without causing any operational disruptions to your daily business.
Not all penetration testing approaches are the same, some providers focus heavily on automated vulnerability scanning with manual validation, while others deliver deeper, consultant led assessments that combine commercially available & proprietary tooling with manual investigation, exploitation and risk analysis. Some reports are highly technical but difficult for senior stakeholders to interpret whilst others are clear, concise and designed to support remediation planning, or a combination of both, or none of the above – hence it can be really difficult to find what you are looking for! Choosing the right partner therefore has a direct impact on the value you get from the engagement.
1. Start with recognised accreditations and practitioner credentials
For many organisations, recognised industry accreditations and practitioner credentials should be one of the first things to look for. The right answer will depend on your location, sector, regulatory environment and the type of testing required. For global and private sector engagements, CREST & Cyber Scheme is widely recognised as a strong indicator that a penetration testing provider has been independently assessed against defined standards for technical capability, professional conduct, methodology and quality management, whilst maintaining the correct professional assurances. In the UK public sector and CNI markets, NCSC CHECK is critically important as it encompasses security clearances to access government environments where testing must be delivered by cleared professionals.
For financial services and other highly regulated organisations, sector specific frameworks can be just as important as general penetration testing accreditation. In the UK, the Bank of England’s CBEST & STAR-FS framework, developed with CREST, supports controlled, TI led cyber security testing for systemically important financial institutions and financial market infrastructures. Similar threat-led penetration testing frameworks, such as TIBER in Europe, may also be relevant where organisations operate across multiple jurisdictions and have to deal with DORA requirements also.
It is also important to distinguish between company level accreditation and individual consultant certifications. Company accreditations help demonstrate organisational assurance, while certifications such as CREST CRT/CCT, Cyber Scheme Team Member or Team Leader, OffSec qualifications, CompTIA Security+ or PenTest+, CEH and other recognised credentials can provide evidence of individual tester competence. No single badge tells the whole story, but a credible provider should be able to explain why its accreditations and qualifications are appropriate for your market, environment and risk profile. The check list below can be used to help compare potential partners;
- Which company level accreditations does the provider hold, and are they relevant to your market; CREST, NCSC CHECK, The Cyber Scheme etc
- Are the individual testers appropriately qualified through recognised schemes such as CREST, Cyber Scheme, OffSec or equivalent routes in country?
- Can the provider explain which credentials are essential, which are desirable, and which are simply additional indicators of capability?
- Does the provider follow a recognised testing methodology, ethical code of conduct and quality assurance process?
- Can they explain how reports and critical findings are technically reviewed before being issued?
- Can they send you your final reports in a secure manner and provide follow on activities and support when you have questions?
2. Look for expert led testing, not scanning alone
Automated tools are valuable in so much as they help provide broad coverage, identify known vulnerabilities quickly and support repeatable testing across large environments. However, automated scanning alone is not a substitute for manual human led penetration testing. Many of the most important findings require human judgement, contextual understanding and creative thinking to identify them and ultimately articulate the risk to you business.
A strong penetration testing provider will use automation where it adds value, but will also manually validate findings, investigate business logic flaws, assess chained vulnerabilities and consider what an attacker could realistically achieve. This is particularly important for web applications, cloud environments, Active Directory, APIs and complex internal networks where the real risk may not be obvious from a VA scan output alone.
3. Check sector experience and relevance
The best provider for one organisation may not be the best provider for another. A healthcare body, transport operator, financial services firm, technology company or government department will each have different regulatory pressures, clearance of accreditation requirements, stakeholder expectations and operational constraints. That means sector experience matters.
Ask prospective suppliers to describe comparable engagements they have delivered, the types of environments they have tested, and how they adapt their approach for different sectors where risk profile change significantly based on what’s being tested. Client references, testimonials and case studies can be useful evidence of professionalism, responsiveness and quality – past behaviours is an indicator of future behaviours, so its wise to check how a company operates with similar companies.
4. Request a sample report
A penetration test is only useful if the findings can be understood, prioritised and fixed. Before selecting a penetration testing provider, ask to see a sample report. This will tell you a great deal about the quality of their work, their ability to communicate risk and whether their recommendations are actionable and easy to interpret. Be comfortable that there is/are;
- A clear executive summary for senior stakeholders?
- Findings prioritised by real world risk and business impact and use a recognised scoring mechanism such as CVSS 3.0?
- Sufficient technical evidences that are clear enough for internal teams to reproduce and remediate?
- Practical recommendations that are specific and proportionate?
- A report which distinguishes between urgent risks and lower priority improvements?
5. Consider the full engagement lifecycle
Good penetration testing starts before the first test is run and continues after the report is issued. Look for a provider that can support scoping, pre-engagement planning, controlled execution, communication during testing, escalation of critical findings, remediation advice and retesting. This is particularly important where testing needs to be coordinated around business critical systems, third party suppliers, change windows or sensitive data. Consider the relationship with the main point of contact a critical part, as you’ll be working closely with them to agree scope and ensure the requirements understood before you let the provider loose on your systems. Also, consider location of the provider, particularly relevant for onsite projects and time zines for ease of communication.
Where Prism Infosec can add value
At Prism Infosec, our view is that penetration testing should have frictionless engagement, provide practical and evidence led results, focused on improving resilience. The most valuable engagements combine recognised company accreditations, experienced consultants, proven methodologies and clear reporting with a collaborative approach that helps clients understand and reduce risk.
Prism Infosec brings together recognised penetration testing accreditations, experienced consultants, private and public sector assurance experience and a practical, client focused delivery model. Our work spans government, healthcare, transport, financial services and commercial environments, giving us a strong understanding of the different regulatory, operational and stakeholder pressures clients face. We combine automated tooling, proprietary methods and expert led manual testing to identify vulnerabilities that matter in context, not just produce long lists of scan results.
Selecting a penetration testing provider should not be based on price or availability alone. Accreditations, methodology, sector experience, report quality and post testing support all influence whether the engagement delivers genuine value. The right partner should help you understand what an attacker could realistically achieve, what needs to be fixed first and how to strengthen your security posture over time. To discuss your specific security requirements and how Prism Infosec can support your organisation’s resilience, contact our team for an initial conversation.
Image Source: Envato