Skip to content

Home » Sample penetration test report

Sample penetration test report

Book a call

What does an Incursion Cyber Security penetration test report look like?

This is a real example of the report you receive after an Incursion Cyber Security penetration test. It is a complete internal infrastructure assessment carried out against a fictional company, then redacted and anonymised, with the same structure, depth and remediation detail as a live engagement. You can read the plain-English executive summary, the severity-rated findings with evidence and step-by-step fixes, and the retest section that records what was resolved. Download it below. There is no form and no email required.

Example internal infrastructure report. PDF. No sign-up required.

What the report contains

The report is written to be read by two audiences at once: someone who needs to understand the business risk without the technical detail, and someone who has to fix the issues. Each section below appears in the example.

Executive summary

The executive summary states, in plain English, what we found and what it means for the business. It is written for a board or a manager, avoids jargon, and can be read on its own without the technical sections. In the example it describes how testing moved from an ordinary position on the network to full control of the domain, and why that matters.

Scope and approach

This sets out exactly what was tested, when, and on what basis, including anything agreed as out of scope and any change made during the engagement. It means a reader can see the boundaries of the work and what the findings do and do not cover.

How risk is rated

Every finding carries a severity from Critical to Informational and a CVSS score, and the report explains how those ratings are decided. This lets you prioritise: which issues to fix now, which to plan for, and which are routine hygiene.

The findings

Each finding states the risk rating and CVSS score, the affected hosts and ports, what was tested and confirmed, the business impact, and a step-by-step remediation. Evidence is included as command output so the issue can be verified and reproduced, and the fix can be handed straight to the team that will carry it out.

The retest

After you have remediated, we retest and update the report to mark each finding Remediated, Partially remediated or Still open, with the retest recorded above the original finding. Fixes are tested for any new issue they may have introduced, not simply checked off. A retest is included free at one day for every five days of consultancy, taken within 90 days of the report.

Clean-up and annexes

The report closes with a record of the clean-up carried out at the end of testing, and annexes covering the glossary and the full host inventory, so nothing in the body relies on knowledge the reader does not already have.

What you actually get

The report is the deliverable, and it is written to be used rather than filed. Every engagement is carried out by a named consultant who scoped the work, the executive summary is in plain English, the evidence is enough to reproduce each issue, and the remediation is specific to your systems rather than generic advice. Critical and high-risk issues are raised with you as soon as they are confirmed, not held back for the written report.

About this example

The company in the example, Imaginary Ltd, is fictitious, and every host, address and name in it is invented. We use a worked example rather than a real client report so that nothing confidential is ever exposed. Your own report follows the same structure; its length depends on the size and type of the engagement.

Common questions

Will my report look like this?

Yes. The structure, the severity model and the retest approach are the same for every engagement. The number of findings and the overall length vary with the size and type of the test.

How quickly do I get the report?

Within 5 working days of testing, as standard. Critical and high-risk findings are raised with you immediately, before the written report.

Can I share the report with customers, auditors or insurers?

Yes. Reports are classified Commercial in Confidence and are yours to share with the people who need to see them, such as an auditor, a customer’s security team or an insurer.

Is the retest included?

Yes. A retest is included free at one day for every five days of consultancy, taken within 90 days of the report, and the report is updated to show what has been resolved.

To talk through a test, see how we test or get in touch. Every test is scoped by an active penetration tester, so the scope is accurate and nothing is oversold.

Ready to scope a test?

Book a call. Our sales team will set it up and handle the proposal; an active penetration tester agrees the scope with you. No obligation.