Technical Depth & Manual Testing
How the provider separates automated discovery from hands-on validation, exploitation, attack chaining, and evidence collection.
Penetration testing proposals can look remarkably similar on paper. The meaningful differences usually show up in who performs the testing, how much of the work is hands-on, how findings are validated, how easily you can reach the tester, and what happens after the report is delivered.
We created a practical interview and scoring guide to help organizations ask better questions before choosing a provider.
A strong penetration testing engagement depends on more than methodology language and a list of tools. The guide focuses on the parts of an engagement that often determine whether the work is useful in practice.
How the provider separates automated discovery from hands-on validation, exploitation, attack chaining, and evidence collection.
Who will perform the work, how experienced they are, and whether the named team is the team that shows up.
Whether you can communicate directly with the tester, receive meaningful updates, and quickly address important findings.
Whether reports are actionable, findings are reproducible, retesting is clearly defined, and support continues after delivery.
How the provider handles rules of engagement, sensitive data, severity, remediation guidance, and final report review.
None of these automatically disqualifies a provider, but they are worth understanding before signing an engagement.
If every technical question has to move through an account or project manager, context can get lost and real-time discussion becomes harder.
If the provider will not identify the people performing the work in advance, it becomes difficult to validate their experience and fit for your environment.
Junior staff can have a place on a team, but core hands-on testing should not become a training exercise at the client’s expense.
“We use industry-standard tools” is not an explanation of how findings are validated, investigated, or placed into context.
Without validation, findings can remain theoretical and leave the client to determine which issues create meaningful risk.
A penetration test should help close risk, not simply identify it. Clarification, remediation support, and retesting should be clearly defined.
The full scorecard includes suggested scoring criteria and example answers. These questions tend to reveal the most about how a provider operates.
The complete 10-page guide is designed for vendor interviews and proposal evaluation. It includes:
Whether you ultimately work with KobReySec or another provider, the goal is to help you understand what you are buying and who will be doing the work.