
- 01Penetration tests scoped as 'find everything wrong with our systems' produce 200-page reports that nobody acts on. Pen tests scoped to specific risk hypotheses — 'can an attacker who has compromised X reach Y' — produce focused reports that drive concrete remediation.
- 02Hypothesis-based scoping: identify a specific concern (recent architectural change, regulatory question, known gap), state the hypothesis as an attack scenario with success criteria, scope the test to validate or disprove the hypothesis, pre-agree on remediation budget so successful tests do not produce backlog.
- 03Internal vs external testing: internal teams know the architecture and can dive deep; external teams provide independent perspective and often spot patterns the internal team has rationalized. Use both; alternate primary ownership of major engagements between them so neither becomes complacent.
- 04What the report should look like: executive summary (one page, business language), findings ordered by severity-to-business (not CVSS), each finding with reproduction steps, exploit demonstration, recommended remediation, and effort estimate. The format determines whether the report drives action.
Penetration tests scoped as 'find everything wrong with our systems' produce 200-page reports that nobody acts on. Pen tests scoped to specific risk hypotheses — 'can an attacker who has compromised X reach Y' — produce focused reports that drive concrete remediation.
Hypothesis-based scoping
- 01Identify a specific concern (recent architectural change, regulatory question, known gap)
- 02State the hypothesis as an attack scenario with success criteria
- 03Scope the test to validate or disprove the hypothesis
- 04Pre-agree on remediation budget so successful tests do not produce backlog
Internal vs external testing
Internal teams know the architecture and can dive deep. External teams provide independent perspective and often spot patterns the internal team has rationalized. Use both; alternate primary ownership of major engagements between them so neither becomes complacent.
What the report should look like
Executive summary (one page, business language). Findings ordered by severity-to-business, not CVSS. Each finding with reproduction steps, exploit demonstration, recommended remediation, and effort estimate. The format determines whether the report drives action.

