“We Don’t Need a Pentest. You Won’t Find Anything.”
“We don’t need penetration testing. Don’t waste your time, you won’t find anything.”
That was the first sentence a client of mine said to me when I suggested a penetration test. He told me they had run one a month earlier, and boasted that nothing had been found. He explained that they had ordered it because they were obliged to give a report to some customer showing a test had been done – so they went with a generic security-testing vendor.
He insisted nothing had been found.
My first instinct was to smile. I have experience with this situation.
And honestly, their systems looked impressive. Everything was tidy, their team worked to a high standard, and at first glance it really was hard to think there was something they had missed.
But from experience, I know that every system, however good, has something.
Why “nothing was found” is a finding of its own
A report ordered to satisfy a customer requirement and a report ordered to find problems are two different products, even when they carry the same title. The first one is finished the moment it exists. The second is finished when someone has genuinely tried to break the system and written down what worked.
A clean report from a test nobody pushed hard on is worse than no report, because it buys confidence that was never earned – and the confidence is what stops the next test from happening.
I wrote about the other side of this – a client who came to us after a previous vendor’s report said everything was fine – in The Previous Test Found Nothing.
I first shared a version of this as a LinkedIn post on 2024-11-25. It is republished here, lightly edited, so it is easier to find and reference. — Erez Metula
