Back to Field Notes
API & Application Security/Field Note

Managing an Internal Penetration Testing Program That Pays Back

Pen tests scoped as 'find everything' produce reports no one acts on. Pen tests scoped to specific risk hypotheses produce change.

Author

Marco Pereira

Principal Application Security Engineer

Published

May 4, 2026

Read

9 min

Share
AI-generated illustration of a banking data center
AI-generated illustration of a banking data center
Key Takeaways
  • 01Penetration tests scoped as 'find everything wrong with our systems' produce 200-page reports that nobody acts on. Pen tests scoped to specific risk hypotheses — 'can an attacker who has compromised X reach Y' — produce focused reports that drive concrete remediation.
  • 02Hypothesis-based scoping: identify a specific concern (recent architectural change, regulatory question, known gap), state the hypothesis as an attack scenario with success criteria, scope the test to validate or disprove the hypothesis, pre-agree on remediation budget so successful tests do not produce backlog.
  • 03Internal vs external testing: internal teams know the architecture and can dive deep; external teams provide independent perspective and often spot patterns the internal team has rationalized. Use both; alternate primary ownership of major engagements between them so neither becomes complacent.
  • 04What the report should look like: executive summary (one page, business language), findings ordered by severity-to-business (not CVSS), each finding with reproduction steps, exploit demonstration, recommended remediation, and effort estimate. The format determines whether the report drives action.

Penetration tests scoped as 'find everything wrong with our systems' produce 200-page reports that nobody acts on. Pen tests scoped to specific risk hypotheses — 'can an attacker who has compromised X reach Y' — produce focused reports that drive concrete remediation.

Hypothesis-based scoping

  • 01Identify a specific concern (recent architectural change, regulatory question, known gap)
  • 02State the hypothesis as an attack scenario with success criteria
  • 03Scope the test to validate or disprove the hypothesis
  • 04Pre-agree on remediation budget so successful tests do not produce backlog

Internal vs external testing

Internal teams know the architecture and can dive deep. External teams provide independent perspective and often spot patterns the internal team has rationalized. Use both; alternate primary ownership of major engagements between them so neither becomes complacent.

What the report should look like

Executive summary (one page, business language). Findings ordered by severity-to-business, not CVSS. Each finding with reproduction steps, exploit demonstration, recommended remediation, and effort estimate. The format determines whether the report drives action.

#Pen Test#Internal#Program

/WRITTEN_BY

Marco Pereira

Principal Application Security Engineer · Alexa Cybersecurity