Home / Blog / “We Don’t Need a Pentest. You Won’t…
Engagements and Process
“We Don’t Need a Pentest. You Won’t Find Anything.”
That was the first sentence out of a client's mouth. They had tested a month earlier, with a generic vendor, because a customer required a report. Their systems really did look impressive.
“We don't need penetration testing. Don't waste your time, you won't find anything.”
That was the first sentence a client of mine said to me when I suggested a penetration test. He told me they had run one a month earlier, and boasted that nothing had been found. He explained that they had ordered it because they were obliged to give a report to some customer showing a test had been done - so they went with a generic security-testing vendor.
He insisted nothing had been found.
My first instinct was to smile. I have experience with this situation.
And honestly, their systems looked impressive. Everything was tidy, their team worked to a high standard, and at first glance it really was hard to think there was something they had missed.
But from experience, I know that every system, however good, has something.
Why “nothing was found” is a finding of its own
A report ordered to satisfy a customer requirement and a report ordered to find problems are two different products, even when they carry the same title. The first one is finished the moment it exists. The second is finished when someone has genuinely tried to break the system and written down what worked.
A clean report from a test nobody pushed hard on is worse than no report, because it buys confidence that was never earned - and the confidence is what stops the next test from happening.
I wrote about the other side of this - a client who came to us after a previous vendor's report said everything was fine - in The Previous Test Found Nothing.
I first shared a version of this as a LinkedIn post on 2024-11-25. It is republished here, lightly edited, so it is easier to find and reference. — Erez Metula
Keep reading
More from the blog
Engagements and Process
Learn Mode and Enforce Mode Are Sold in the Same Breath. They Are Not the Same Thing.
An agent that scans, finds and proposes, with a human deciding, is where the field should go. An agent that writes and…
Read itEngagements and Process
I Run a Company of Pentesters, and I Watch AI Bots Doing Their Job
Faster, cheaper, and far more of it. The question is not whether AI replaces pentesters - it is which pentesters survive, and…
Read itEngagements and Process
“Just Send Me a Quote and We’ll See” – Why I Don’t Work That Way
A prospective client asked for a price before telling me what the systems do. In security testing, a quote without a scope…
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.