What Is Delivered After a Penetration Test? Report, PoC and Re-Test Process
What is delivered to organisations at the end of a web application penetration test? Executive summary, technical report, PoC and the re-test process.
The Value of a Penetration Test Is Measured by the Quality of the Report
The purpose of a web application penetration test is not only to find vulnerabilities. The real goal is to enable the organisation to understand, prioritise and permanently remediate those vulnerabilities. At SecureSys, our reports are structured to meet the needs of stakeholders with different levels of technical knowledge — software developers can reach the technical detail, while senior management can assess the risks in terms of business impact.
Our Deliverable Package
1. Executive Summary
Contains the scope of the test, the overall security level, the number of critical findings, the risk distribution and the priority action recommendations. The aim is to let non-technical managers understand the organisation's security posture within a few minutes.
2. Technical Findings Report
Each finding is detailed with its name, risk level, CVSS score, description, technical analysis, exploitation scenario, evidence screenshots, related HTTP requests/responses, reference standards (OWASP, CWE, CAPEC) and remediation recommendations.
3. Risk Prioritisation
Not every vulnerability has the same urgency; findings are prioritised taking into account their impact on the organisation's business processes, helping limited resources to be directed to the most critical risks.
4. Evidence (Proof of Concept)
Includes screenshots, HTTP requests/responses, parameter examples and technical explanations. When preparing the evidence, sensitive data is masked or anonymised.
5. Remediation Recommendations
Covers secure coding recommendations, server configuration changes, authentication improvements and architectural recommendations. The aim is not only to show the problem but also to support the resolution process.
6. Re-Test and Verification
After remediation work, previously identified findings are re-evaluated; it is checked whether the vulnerability has been fully closed and whether the applied fix has introduced any new risk. Successfully closed findings are marked "Verified" in the report.
Closing Meeting and Knowledge Sharing
In addition to the technical reports, a closing meeting can be held at the end of the project depending on the organisation's request. In this meeting the critical findings are reviewed, the development teams' questions are answered and the priority remediation plan is examined.
Deliverables
| Deliverable | Purpose |
|---|---|
| Executive Summary | To give senior management an overall security view |
| Technical Findings Report | To describe the vulnerabilities in detail |
| Risk Prioritisation Table | To plan remediation work |
| Evidence (PoC) | To enable verification of findings |
| Remediation Recommendations | To show how vulnerabilities can be fixed |
| Re-Test Results | Verification of the fixes |
| Closing Presentation (optional) | Sharing the technical and managerial assessment |
Priority Levels
| Priority | Description | Recommended Action Timeframe |
|---|---|---|
| Critical | Risk of data breach or system compromise | As soon as possible |
| High | A vulnerability that may affect business processes | With priority planning |
| Medium | Exploitable under certain conditions | In the planned remediation cycle |
| Low | Improvements that raise the security level | As part of regular maintenance |
For our testing methodology see our penetration testing methodology page, and for the full service our Web Application Penetration Testing Service page.
Related Articles
Web Application Security
OWASP Top 10 and the Security Vulnerabilities Tested in Web Applications
What is the OWASP Top 10 and which security vulnerabilities are tested in a web application penetration test? A comprehensive SecureSys guide.
What Is Broken Access Control? IDOR, BOLA and Authorization Vulnerabilities
What are Broken Access Control, IDOR and BOLA? Horizontal/vertical privilege escalation scenarios and prevention methods. A SecureSys expert guide.
Authentication and Session Management Security: MFA, Brute Force, Session Hijacking
Authentication and session management security: MFA, brute force, credential stuffing and session hijacking risks. A SecureSys expert guide.
What Is API Security? OWASP API Security Top 10 and BOLA Risks
What is API security, what are the OWASP API Security Top 10 risks and how are BOLA vulnerabilities prevented? A SecureSys expert guide.
Business Logic Security Vulnerabilities: Price Manipulation and Coupon Abuse
What are business logic security vulnerabilities? Price manipulation, coupon abuse and race condition risks. A SecureSys guide.
What Is Cross-Site Scripting (XSS)? Stored, Reflected, DOM-Based XSS and Prevention Methods
What is XSS (Cross-Site Scripting), what are its types and how do you protect your web application? A comprehensive guide from SecureSys experts.
Looking for professional support on this topic?
Our expert team will reach out for a free consultation as soon as possible.