// ARTICLE

    The structure of a good pentest report

    What a client really wants. And what they don't know.

    Here is something most people learn the hard way: the client almost never reads your report the way you wrote it. They open the PDF, glance at the summary, and go straight to what it costs them to fix. The testing can be excellent and still land badly if the document buries the answer.

    A report is a deliverable, not a log. Structure carries as much weight as the findings themselves.

    Two people read it, not one

    The person who signed the purchase order wants to know how exposed they are and what to do about it. The engineer who inherits the fixes wants to reproduce each issue and close it. These are different documents pretending to be one.

    Write for the manager first and the engineer second, in that order on the page. The exec summary answers 'how bad is it and what now'; the technical detail answers 'show me and tell me how'.

    The executive summary is what gets you renewed

    Two-thirds of the readers stop after the first page. Spend your best writing there. Business language, the three risks that matter, one honest sentence on overall posture. No wall of CVSS scores, no tool names they don't recognise.

    If a non-technical director cannot repeat your main point back to you after reading one page, the summary has failed, no matter how good the testing was.

    Findings people can actually act on

    Every finding needs five things: what it is, where it is, why it matters here, how to fix it, and how to confirm the fix worked. The last one is where most reports go quiet, and it is the one clients value most.

    A reproduction step or a verification command turns a claim into something the client's team can check themselves. It is also what separates a report someone trusts from one they quietly doubt.

    Honesty beats a compliance percentage

    It is tempting to print 'ISO 27001: 78% compliant' on the cover. Don't. A scan cannot measure a management system, and auditors know it. An invented percentage is the fastest way to lose a technical reader.

    Map each finding to the control it touches, as evidence, and let the assessor draw the conclusion. It reads as more credible, not less, precisely because it doesn't overclaim.