How to Choose a Penetration Testing Company

How to choose a penetration testing company: the red flags to avoid and the questions to ask about testers, methodology, retesting and report quality.

Choosing a penetration testing company comes down to four questions: who will actually do the work, how they test, what their reports look like, and what happens after the report lands. Get straight answers to those and most weak vendors eliminate themselves before you ever see a quote.

Who actually does the work?

This is the question that matters most and gets asked least. Penetration testing quality is almost entirely a function of the individual testers — the same scope, tested by two different people, can produce wildly different results.

Ask directly:

  • Who, by name, will test our systems? A firm that will not name its testers before you sign is asking you to buy blind.
  • Is the work done in-house or subcontracted? Plenty of firms sell under one brand and quietly outsource delivery. That is not automatically bad, but you deserve to know whose hands are on your systems and under whose legal jurisdiction.
  • What is the testers' background? Look for evidence of genuine offensive security work: published research, CVEs, conference talks, open-source tooling, bug bounty track records. People who are visible in the security community are staking their reputation on the work.

Also ask how senior the person on your engagement will be. Some firms scope with their best people and deliver with their newest.

What methodology do they follow?

You are not looking for a buzzword bingo card — you are checking that testing is structured and predominantly manual.

  • Recognised references like the OWASP Top 10, the OWASP API Security Top 10, the OWASP Web Security Testing Guide and MITRE ATT&CK are good signs when the vendor can explain how they use them, not just name them.
  • Ask what proportion of the work is manual versus automated. Scanners have a place, but if the honest answer is 'mostly automated', you are buying a scan — see penetration test vs vulnerability scan for why that distinction matters.
  • Ask how they approach the things scanners cannot find: authorisation flaws, business logic abuse, chained attacks. A capable tester will light up at this question; a reseller will change the subject.

Ask for a sanitised sample report

The report is the product. Any serious firm can share a redacted sample, and it tells you almost everything:

  • An executive summary a non-technical stakeholder could genuinely read.
  • Evidence for every finding — reproduction steps, requests and responses, screenshots — not just a title and a CVSS score.
  • Remediation advice specific to the finding, not boilerplate pasted from a vulnerability database.
  • Signs of human thought: chained findings, business-context impact statements, notes on what was tested and found solid.

If the sample looks like a scanner export with a logo on it, believe what you are seeing.

What is the retest policy?

A pentest's value is realised when the findings get fixed — so ask what happens after the report:

  • Is retesting of fixed issues included, and for how long? (We include a free retest of fixed issues within 90 days; anything less generous should at least be priced transparently.)
  • Will they issue an updated report or attestation letter after retest? Enterprise customers usually want evidence that findings were closed, not just found.
  • Can you ask questions after delivery, or does support end when the invoice is paid?

Red flags that should end the conversation

  • A quote with no scoping questions. If nobody asked about your application, roles or environments, the number is fiction and the testing will match.
  • A price that is too good. A 'full pentest' for a few hundred dollars is an automated scan. Real testing consumes days of senior human time — here is what it actually costs in Australia.
  • Guaranteed outcomes. Guaranteed 'pass', guaranteed finding counts, or certification promises. Testing is an investigation, not a rubber stamp.
  • Refusal to name testers or share a sample report. There is no good reason for either.
  • No professional indemnity or cyber insurance. Ask; competent firms have it and will say so.
  • Fear-based selling. Pressure tactics and breach scare statistics are marketing, not competence.

Questions to ask every vendor on your shortlist

  1. Who, specifically, will perform the testing, and what is their background?
  2. What proportion of the engagement is manual testing?
  3. Can we see a sanitised sample report?
  4. What is your retest policy, and is it included in the price?
  5. How do you communicate during the engagement, and how are critical findings escalated?
  6. How is our data and evidence handled and destroyed afterwards?
  7. What do you need from us to make the test effective?

That last one is a quiet tell: good testers have a precise answer, because they have thought hard about what makes engagements succeed.

Certifications: a signal, not the whole story

Industry certifications (OSCP and its siblings, CREST accreditations and similar) demonstrate a baseline and matter in some procurement contexts. Treat them as one input. Plenty of exceptional testers are best evidenced by their research and results, and a certificate on the wall says little about how much effort goes into your ten days of testing. Weigh the person and the work product over the acronyms.

FAQ

Does our penetration testing company need to be Australian?

Not necessarily, but it helps with timezone overlap during testing, contracts under Australian law, and data sovereignty requirements that some industries impose. What matters more is knowing exactly who does the work and where — which is harder to verify with firms that subcontract across borders.

Are CREST or OSCP certifications essential?

They are a useful baseline signal, and some procurement policies require them. But they are not a proxy for engagement quality. A tester's public track record — research, tooling, disclosures — usually tells you more than any certificate.

How far in advance should we book?

Good teams typically schedule two to six weeks out, longer near end-of-quarter compliance crunches. If you have an audit or enterprise deal deadline, start vendor conversations at least a couple of months ahead.

If you want to put us through this exact checklist, please do — get in touch and ask us anything above. You will get named testers, a sample report, a free scoping call and a fixed quote within one business day.

Need cybersecurity expertise?

Drop your email and we'll be in touch within one business day.