Penetration testing services
June 28, 2023
How are Secure Impact penetration tests different to the market standard?
This is a question we're asked a lot by clients, so we've produced the summary below to outline how our penetration testing services compare to others in the market.

Rather than a tick box exercise, our penetration tests are always geared to ensure meaningful change for our clients, and we're proud to be setting a new industry standard.

Engagement Scoping

Market Standard

  • A short call, often with a commercial individual only, which misses key context and detail regarding your risk profile and security objectives.
  • Outcomes of this call often produce a rough scope, based on some generic metrics, which may mean  you don’t get a targeted test, nor the right insights to your vulnerabilities  to make the most important changes.

Secure Impact

  • A  one-to-one call with our technical team lead and consultants that will be  working on the engagement, meaning you get value and technical expertise from  day 1. We always endeavour to provide you value even if money doesn’t change  hands.
  • The entire technology stack is considered in the context of the wider organisation to better understand your risk profile. This affords a more holistic understanding of your ecosystem.
  • The most  important areas are identified to be tested, with specific objectives in mind  - this makes it more cost-effective for you in terms of where and how a  consultant’s time is spent, and the value generated.
  • The scope is designed to maximise the value and impact of the engagement, meaning targeted  outcomes and remediation advice, based on your specific risk profile.

Use of Automated Scanning

Market Standard

  • Scanning is often heavily utilised as this is low effort for consultants, and means they can carry out more pentests in a certain timeframe. However, this approach causes excess noise and traffic during an engagement, and often drowns clients in unnecessary findings that don’t truly impact their security.
  • Over-reliance on scanning produces a large number of false positives in findings reports, meaning some of the results given to clients aren’t even correct, furthermore confusing security teams and reducing the actionability and value of your pentest.

Secure Impact

  • We take a strong, manual approach, with “just the right amount” of automation.
  • We validate our findings to avoid reporting false positives.
  • We take the time to demonstrate and explain the real-world threat that each vulnerability poses to your organisation - this creates actionable learnings for you and your team and encourages knowledge transfer.
  • Manual testing vs overly automated scanning produces actionable results, specific to your business, meaning the remediations you make will have a definitively positive impact on your security maturity.

Engagement Reporting and Deliverables

Market Standard

  • Reports are often over-templated, generic, and long and difficult to read. This is not useful for time-pressured security teams to instigate change. These reports are often overwhelming and end up being “hidden in a drawer” vs acted upon.
  • Other formats such as public-facing or redacted reports are often low-quality, which may send an unintended message to your own clients.

Secure Impact

  • High-quality, concise reports that are easy to read, easy to understand by multiple teams, and easy to action change as a result. We include screenshots and icons and colour coding to clearly denote severity of findings, and more.
  • We provide supplementary report formats, including public-facing reports and redacted summaries. These documents are clear and visually attractive documents that you would be proud to share with your stakeholders.

Post-Engagement Closing Call

Market Standard

  • Sometimes offered, however, these can be solely focused on selling you future tests or other products vs ensuring the results and recommended remediations are fully understood to induce action.

Secure Impact

  • During a post-engagement call, our consultants will guide you through your report and provide specific remediation advice for each finding, answering any questions or concerns you or your team may have.

Quality of Testing

Market Standard

  • Some small degree of manual testing in addition to scanning, which often varies in quality. Automated scanning does not find many of the most severe vulnerabilities – skilled testers do, manually.
  • Often performed by inexperienced and minimally qualified testers.

Secure Impact

  • We don’t rely on generic, automated scanning - we provide high quality testing which utilises the latest, real-world attacks and techniques against your environment.
  • All of our engagements are performed by highly qualified consultants who love what they do and hold certifications from industry-leading providers such as GIAC and OffSec

Finding Remediation Advice

Market Standard

  • Often templated and generic, not necessarily useful for your team, and missing a clear roadmap which actively helps you improve your cyber maturity.
  • Usually no code-specific examples which makes remediation that much harder and less actionable - context and specifics are needed!

Secure Impact

  • We provide tailored remediation advice which is specific to your application code-base and our understanding afforded from the original, in-depth scoping call.
  • Our consultants will walk you through the remediation advice in a post-engagement closing call, to ensure that you have a clear actionable plan.

Ad-Hoc Calls and Engagement Updates

Market Standard

  • Notifications during the engagement for critical findings only.
  • Customers are often left in the dark about the status and stage of the engagement.

Secure Impact

  • We allow you to define a custom notification threshold for the severity of findings, providing you with exactly the information you need throughout the engagement, not just a report at the end.
  • We notify you as the engagement moves through the different stages, so you know exactly what is happening and when.

Company Accreditation and Quality Management

Market Standard

  • Often variable and not guaranteed, meaning you have no way to ensure you have chosen a team that can be held to international standards of best practice and quality management.

Secure Impact

  • We hold numerous accreditations, including CREST, Cyber Essentials Plus and ISO 9001, so you have the assurance that we have the the correct, up-to-date skills, strategies, and techniques to give you the best assessment of your cyber security.

If you have any questions, or would like to speak to our team about your next pentest, please get in touch!

Sign up to our newsletter to receive the latest updates