Questions to ask before commissioning a pen test
Ask penetration testers about methodology, safeguards, who's doing the work, and retesting before you sign. Know what answers matter.
Most organisations commission a penetration test because they have to—a regulator, customer, or insurance requirement—not because they're confident the tester will surface what actually matters. The conversations that happen before you sign are the ones that reveal whether you're hiring someone who understands your risk or just someone who will generate a report.
"What's your testing methodology, and will you adapt it to our environment?"
A generic methodology applied to every client is a warning sign. A good tester will ask detailed questions about your systems, business criticality, and what a breach would actually cost you—not just in downtime, but in customer trust or regulatory fallout. They might describe how they'll start with reconnaissance, move through initial access attempts, then escalate privileges to show blast radius. They should explain *why* they choose manual testing over automated tools, and how they'll avoid crashing systems that can't tolerate aggressive scanning.
An evasive answer—"We follow industry best practice" or "Our process is proven"—suggests they run the same playbook regardless. Ask them to walk through how they'd approach *your* network. If they can't articulate specific angles (legacy systems, third-party integrations, remote access points), they haven't thought about you yet.
"How will you avoid bringing us down, and what's off-limits?"
Penetration testing can disrupt live systems. A tester who doesn't explicitly discuss downtime risk and mitigation hasn't worked in volatile environments. They should explain how they'll coordinate with your team, test in staging first if possible, and throttle attacks to avoid denial-of-service outcomes. They should ask what systems are critical and can't be touched, and which ones can be tested aggressively.
If they say testing "always" disrupts things, or they're vague about safeguards, they're either inexperienced or they don't care about collateral damage. You want someone who takes precautions seriously.
"Who'll actually do the work, and what credentials should I verify?"
Check whether the person signing the contract is the same person doing the test, or whether you're getting a junior with minimal oversight. Ask for their relevant certifications—OSCP, CEH, GPEN, or equivalent—and ask to verify them independently. Ask how long they've been doing penetration testing (not just IT work generally), and whether they've tested systems like yours before.
A team lead who outsources all the technical work to someone you've never met is a gamble. You want accountability. Similarly, someone who downplays credentials or says "certifications don't matter, experience does" is either insecure or hasn't kept up with the field. Both matter.
"What happens after you deliver the report—can we retest, and what's the retesting process?"
A single penetration test is a snapshot. If you're fixing vulnerabilities, you need to verify they're actually fixed. Ask whether retesting is included in the scope, what it costs separately, and how they'll confirm remediation worked. A good tester will offer retesting at a discount or build it into the initial fee, because they know a test without validation is incomplete.
Be wary of someone who treats retesting as a new engagement or quotes a full price again. They should also clarify whether they'll retest *everything* or focus on the vulnerabilities they originally found. Focused retesting is usually more practical and cost-effective.
Before you book, ask for a reference from a previous client in your sector—someone who can tell you whether the test found real issues, whether the tester was professional during the engagement, and whether the final report was actionable or just a long list of false alarms. A solid tester will have those references ready.
On Strove, you can compare testers' credentials, read verified feedback, and get quotes from multiple firms so you can ask these questions consistently and see who answers with clarity and depth. That comparison often reveals who's genuinely invested in your security and who's just running through a checklist.
Common questions
- What if a pen tester won't discuss how they'll avoid disrupting our systems?
- That's a red flag. Any tester working on live systems should explain their approach to risk mitigation—staging tests, throttling attacks, and coordinating with your team. If they say disruption is unavoidable or standard, move on.
- Should I ask for certifications, and which ones matter most?
- Yes. Look for OSCP, CEH, GPEN, or equivalent. Ask them to show you the credential and verify it independently. Certifications plus documented experience testing systems similar to yours is the combination to look for.
- Is retesting always necessary after a penetration test?
- If you're fixing vulnerabilities, retesting validates the fixes actually worked. Ask upfront whether retesting is included or how much it costs separately. A good tester builds it in or prices it fairly as a follow-up.
- What if the testing firm can't name the person who'll actually do the work?
- That's a problem. You want to know who's running the test and their experience level. If a team lead is outsourcing all technical work to someone unnamed, you're taking a risk on quality and accountability.
Find a verified provider on Strove
Compare vetted penetration testing providers, check their credentials, and book or request a quote — all in one place.
Find a Business