PEN Consultants Logo
Don’t Be a Victim: Find your weaknesses before the criminals do. PEN Consultants can help!

Reporting Levels

[rank_math_breadcrumb]

One of the deliverables for the majority of PEN Consultants’ services is a customized Findings and Recommendations Report, in addition to a variety of raw tool outputs, vulnerability scan reports, etc., for nearly every service. However, we understand that in some cases, our default, full, premium-level reporting may not be needed, allowing us to focus more time on actual testing, or even reduce engagement time and costs.

Reporting options we provide:

Details:

  1. STANDARD REPORT
    • Scenario: The consumers of the report will range from Auditors, IT staff, developers, technical managers, C-level, etc.
    • Summary: Our default, premium report that has been highly customized, polished, and QA’d. Example sections that may be included: Executive Summary, commendations, scope, dates of testing, tester source IPs, methodology, assumptions and limitations, summary and findings and recommendations, etc.
    • Example report: https://penconsultants.com/report
    • Cost: This level of reporting represents 15-25% of the testing time/cost. Smaller-scoped engagements with a large number of findings use a higher percentage, while larger-scoped engagements with fewer findings use a smaller percentage. Example: A $10,000 engagement may include ~$2,000 in reporting costs.
  2. FULL REPORT (REDUCED QA)
    • Scenario: The consumers of the report would generally be the same as the Standard Report option (option #1).
    • Summary: The report would be similar to the Standard Report option (#1). The primary difference is that the Findings and Recommendations section receives very little QA (comparable to the Raw Report, option #4).
    • Example report: See summary and examples above (option #2).
    • Cost: This level of reporting represents 10-20% of the testing time/cost.
  3. RAW REPORT + EXECUTIVE SUMMARY
    • Scenario: The consumers of the report would generally be the same as the Standard Report option (option #1).
    • Summary: The report would be similar to the Raw Report option (#4), but also include the Executive Summary (only) from the Standard Report. The remaining introductory, supporting, and concluding sections (such as methodology, scope, assumptions, appendices, and conclusion) are omitted.
    • Example report: See Executive Summary under option #1, and description of finding write-ups under option #4.
    • Cost: This level of reporting represents 5-15% of the testing time/cost.
  4. RAW REPORT
    • Scenario: The consumers of the report would primarily be limited to IT staff/developers. It is NOT written with C-level/executives or Auditors in mind.
    • Summary: Includes the individual findings and recommendations that have been lightly customized to your environment, but much of the QA process on our end is cut out, making this more closely aligned to a rough draft. There is minimal effort put into customizing our boilerplate content, so, in some cases, due to time constraints, the reporting may require the client to track down certain details. There are no other overview or ending sections with this report. There is a single PDF delivered with this option. This, along with a single-page attestation letter, could satisfy most audit requirements.
    • Example report: See the Findings and Recommendations description under Option #1.
    • Cost: This level of reporting represents 5-10% of the testing time/cost.
  5. RAW FINDINGS
    • Scenario: The consumers of the report will primarily be IT staff/developers with a deep understanding of system and network administration, information and cybersecurity, web development (if applicable), common vulnerabilities, attacks, and risks, etc.
    • Summary: This is included with most testing, and would not be a report at all, but rather, the testers' raw notes from each test that were taken during the engagement. These could range from just a few brief statements and screenshots, to a copy/paste of some of our raw boilerplate content. There may be no recommendations, nothing has been QA’d, it is far less formal, and assumes a highly technical reader who understands the risks for most vulnerabilities and what needs to be done to mitigate those risks. This reporting may require the client to track down certain details, but it is more than sufficient for IT staff/developers. There are individual documents delivered with this option (one for each finding, generally). This, along with a single-page attestation letter, could satisfy most audit requirements.
    • Example findings and notes: https://penconsultants.com/informed
    • Cost: $0 - Included with most vulnerability assessments and penetration tests
  6. CUSTOM
    • Alternatively, we could provide:
      • One of the less formal levels of reporting, send it to you for review, and then increase the reporting level as desired
      • Something midway between two of these options
      • Another format altogether
magnifiercrosschevron-down