Resources
See the report before you buy the test.
The report is the deliverable. Everything else is process. This is a real one, redacted, so you can judge the quality of the thinking rather than the quality of the sales pitch.
What is in it
- An executive summary that a non-technical reader can act on
- Findings with reproduction steps, not just descriptions
- Severity reasoning that shows the working, weighed against a compliance regime
- Remediation guidance specific enough for an engineer to implement
- The methodology and scope, stated plainly, including what was not tested
What to look for
If you are comparing vendors, the tells are consistent. Does every finding have a reproduction path, or do some just assert a risk? Is severity argued or asserted? Does the report say what was out of scope and why? Is there anything in it that a scanner could not have produced?
Those questions are worth asking of our report as much as anyone else's.
Would rather just talk it through?
Book a call and we will walk through the report with you on screen.
