Key Takeaways
- CREST certification provides independent assurance, but it shouldn’t be the only factor you consider.
- Ask who will conduct your test and whether they have relevant experience with your technology and environment.
- Understand how the provider combines manual testing with automated tools and which methodology it follows.
- Ask to see a redacted sample report to assess how clearly findings, business impact and remediation are communicated.
- Check the provider’s professional indemnity insurance and how it will handle sensitive data obtained during testing.
On this page
- Why Does CREST Certification Matter When Choosing a Penetration Testing Company?
- What Penetration Testing Experience Should a Provider Have?
- What Methodology Should a Penetration Testing Company Follow?
- What Should Be Included in a Penetration Testing Report?
- What Insurance Should a Penetration Testing Company Have?
- How Should a Penetration Testing Company Handle Your Data?
- What Questions Should You Ask a Penetration Testing Provider?
- Choose OmniCyber for Your Penetration Test
- Related Questions
How to Choose a Penetration Testing Company
Choosing a penetration testing company means looking beyond price and checking its accreditation, the experience of the testers assigned to your engagement, its methodology and the quality of its reporting. Recognised credentials such as CREST provide independent assurance, but you should also look for relevant technical experience, evidence of manual testing, appropriate insurance and clear processes for protecting sensitive data.
Why Does CREST Certification Matter When Choosing a Penetration Testing Company?
CREST certification provides independent assurance that penetration testing is being delivered to recognised professional and technical standards. However, CREST should be considered alongside the experience and qualifications of the individual testers who will conduct your assessment.
Ask who will carry out the testing and what relevant qualifications and experience they have. The important question isn’t simply which credentials appear on a provider’s website, but whether the people assigned to your engagement have the appropriate skills and experience for the environment being tested.
OmniCyber’s penetration testing services are delivered by CREST-certified ethical hackers, with team members holding CREST, OSCP and other offensive security qualifications.
What Penetration Testing Experience Should a Provider Have?
A penetration testing provider should have relevant experience with the type of assessment, technologies and environment being tested. When comparing companies, ask about both the provider’s previous work and the experience of the individual testers who will be assigned to your engagement.
Look for relevant experience including:
- The technologies and platforms in your environment
- The type of penetration test you require
- Similar applications, infrastructure or environments
- Identifying how multiple weaknesses can be chained into realistic attack paths
Relevant experience matters because penetration testing relies on technical judgement and problem-solving as well as knowledge of vulnerabilities. This becomes particularly important when individual weaknesses need to be investigated and combined to demonstrate their real-world impact.
For example, during an internal penetration test for a leisure-sector client, straightforward credential attacks had already been hardened against following previous testing. Rather than stopping there, our tester identified another route through the environment, chaining weaknesses involving VMware vCenter, authentication certificates and Active Directory to ultimately demonstrate domain compromise.
The value came from understanding how individual weaknesses could be combined to create a meaningful business risk rather than simply reporting each issue separately.
When evaluating a provider, ask for examples of previous engagements that demonstrate this kind of problem-solving, particularly in environments relevant to your own.
What Methodology Should a Penetration Testing Company Follow?
A penetration testing company should follow a recognised methodology appropriate to the type of assessment being performed. Depending on the engagement, this may draw on established frameworks, standards and testing guidance such as the OWASP Web Security Testing Guide (WSTG), the Penetration Testing Execution Standard (PTES) and CREST guidance.
When reviewing a provider’s methodology, ask:
- Which recognised standards or frameworks does the methodology align with?
- How are automated tools used during the assessment?
- Where does manual testing and investigation take place?
- How are potential attack paths investigated beyond individual vulnerabilities?
- How is the methodology adapted to the environment being tested?
Automated tools can help identify known weaknesses and provide coverage at scale, while expert manual testing allows testers to investigate vulnerabilities, attack paths and behaviours that require context and judgement.
For example, during one web application assessment, our testers noticed that an email template editor was rendering user-supplied variables in a way associated with server-side template injection. Manually investigating that behaviour confirmed a vulnerability that ultimately allowed remote code execution.
The finding depended on recognising the application’s behaviour and investigating it further rather than treating the assessment as a vulnerability scan.
What Should Be Included in a Penetration Testing Report?
A penetration testing report should explain what was found, what an attacker could realistically achieve, the business impact and what should be done to remediate each vulnerability. It should give technical teams enough detail to act while also making the overall risk understandable to non-technical stakeholders.
Before appointing a provider, ask to see a redacted sample report.
Look for whether findings clearly explain:
- What the vulnerability is
- How it was identified
- What an attacker could potentially achieve
- Which systems or data could be affected
- How the issue should be remediated
- Which issues should be prioritised
A useful report shouldn’t simply provide a list of findings and severity scores. Findings should be placed in context and prioritised according to risk so that your organisation can make informed remediation decisions.
What Insurance Should a Penetration Testing Company Have?
A penetration testing company should hold professional indemnity insurance appropriate to the work it carries out. There isn’t a single minimum level of cover that applies to every penetration test, so buyers should check that the provider’s policy and level of protection are appropriate for the scope, value and risk of their engagement.
When evaluating a provider, check:
- That professional indemnity insurance is current and valid
- The level of cover provided and whether it meets your organisation’s procurement requirements
- Whether the policy is appropriate for penetration testing and the services being provided
- Whether any exclusions or limitations could be relevant to your engagement
For higher-risk or more complex engagements, your procurement, legal or risk team may have specific insurance requirements that a provider will need to meet.
How Should a Penetration Testing Company Handle Your Data?
A penetration testing company should protect sensitive data throughout the engagement, including credentials, vulnerability details and configuration information obtained during testing. Before choosing a provider, understand where this information will be stored and processed, who can access it, how it will be transferred, how long it will be retained and how it will be securely disposed of afterwards.
Before appointing a provider, ask:
- How will information gathered during testing be stored and protected?
- Who will have access to testing data?
- How will credentials and other sensitive information be handled?
- How will reports and other sensitive files be transferred?
- How long will testing data be retained?
- How will it be securely disposed of when no longer required?
These controls matter because the information generated during a penetration test can itself provide sensitive detail about weaknesses within your environment.
The systems and data testers are authorised to access should be agreed separately during scoping. See How to Scope a Penetration Test for more on defining those boundaries.
What Questions Should You Ask a Penetration Testing Provider?
Before choosing a penetration testing provider, ask about its CREST credentials, the experience of the testers assigned to your engagement, its testing methodology, reporting, insurance and data-handling practices. Asking each shortlisted provider the same questions makes it easier to compare the quality and scope of the service rather than making a decision based on price alone.
Consider asking:
- Are your penetration testing services CREST-certified?
- Who will conduct our test, and what relevant experience and qualifications do they have?
- Have you tested technologies or environments similar to ours?
- How do you combine manual testing with automated tools?
- Can we see a redacted sample penetration testing report?
- How will our credentials, findings and other sensitive information be protected?
- What is included in the price, including any retesting?
- How will critical findings be communicated during the engagement?
Clear, specific answers to these questions make it easier to compare penetration testing providers on the substance of their service rather than relying on credentials, marketing claims or headline price alone.
Choose OmniCyber for Your Penetration Test
OmniCyber provides CREST-certified penetration testing services delivered by experienced ethical hackers with CREST, OSCP and other offensive security qualifications. Our team combines automated analysis with expert manual testing to simulate realistic attack techniques and understand how vulnerabilities could be exploited.
Our penetration testing approach includes risk-based reporting, clear remediation guidance, ongoing investment in tester training, and peer review and quality assurance of findings.
See our full range of Penetration Testing Services for more information about our approach.
Related Questions
How do I scope a penetration test before choosing a provider?
Your objectives, systems, access requirements and exclusions should be understood before comparing proposals. See How to Scope a Penetration Test for what to consider when defining the assessment.
How much does penetration testing cost in the UK?
Penetration testing costs vary according to scope, complexity and the amount of testing time required. See How Much Does Penetration Testing Cost in the UK? for indicative UK pricing and the factors that influence the final cost.
Does a cheaper penetration testing quote mean a worse test?
Not necessarily. Price alone doesn’t determine the quality of a penetration test. If one quote is significantly lower than others, compare the testing time, methodology, tester experience and what’s included before deciding whether it represents better value.
Ready to speak to a CREST-certified penetration tester? Request a Scoped Pen Test Quote to discuss your environment and testing requirements.
Jennifer Goulbourne
Jennifer is a Digital Marketing Executive at OmniCyber Security, where she's responsible for engaging the company's existing customer base across digital channels and creating helpful resources on threat intelligence and security operations for cybersecurity professionals and business leaders.