Finding the right penetration testing company requires asking difficult questions. To show you what a strong answer looks like, we put these questions to ourselves. However, this is a mock interview with 7ASecurity, so answers will vary by provider. Use this as a guide for your conversations and what to listen for.

Ask five different penetration testing companies the same question and you'll get five different answers. Some dodge. Some bury you in acronyms. A few will give you a straight answer. The tricky part is knowing which is which before you sign anything.
Unfortunately, many buyers walk into a pentest conversation without a clear sense of what a strong answer sounds like. This makes it difficult to tell a confident, well-run security service provider from one that's just confident.
So we put ourselves in the seat first. Below are the questions we'd want any pentest company to answer clearly and how we'd answer them ourselves.
But remember, it's a mock interview, not a transcript of a real client call. Use this as a guide on what to listen out for in your conversations, not a stencil that every provider will answer the same way we do.
11 Questions Any Penetration Testing Company Should Answer
How Much of Your Testing Is Manual Versus Automated?
We prioritise manual testing. An automated scanner can flag basic issues, like an exposed login form, and check it against a list of known flaws.
What it can't do is notice that chaining a small, low-severity access issue with a second, unrelated one lets an ordinary user reach admin-only data. It can't spot a workflow that behaves perfectly for every standard input except the manipulated one a real attacker would use.
Those are the findings our researchers hunt for; they're the ones cybercriminals would use.
Red Flag
- A pentest provider who talks about "manual testing" but doesn't provide a specific example of what that looks like in practice is a warning sign.
- If a provider can't explain what their testers did by hand versus what a tool did for them, that's telling. They're probably leaning on automated scans dressed up as a full test.
- If a provider leans heavily on automated scanners or calls a vulnerability scan a penetration test, look elsewhere.
What Happens if Testers Find an Issue Outside the Agreed Scope?
We’ll tell you. Scope defines what we're actively testing, not what we're allowed to notice.
If something turns up outside the agreed boundary, especially anything serious, we’ll document it and reach out to our point of contact. You can then decide how we proceed: expand the engagement, note it for later, or pass it to your team.
We’ll never attempt to exploit an out-of-scope system without your direct, written approval. But we won't quietly sit on it either.
There’s no single mandatory global certification for security companies. However, look for indicators of operational maturity.
What exists instead is a cluster of recognised credentials
- OSCP and OSCE for offensive testing
- CISSP for broader security management
- Various GIAC certifications for specialised areas
Company-level accreditations like ISO 27001 and SOC 2 work differently. Those apply to the business as a whole. Be cautious of anyone who points to one badge as the whole answer.
Who's Doing the Pentesting, and What Are Their Qualifications?
Ask for names, not job titles. We don't put interns or recent graduates on paying engagements. Everyone assigned to a test has already worked as a security professional and goes through our strict internal vetting before they're allowed near a client's systems.
Our testers also hold a series of security certifications, including OSCP, OSCE, CISSP, and a clutch of GIAC credentials, plus more.
Red Flag
- A pentest service provider who shares vague descriptions or won't name who's on your specific engagement.
- Or one who leans on company-wide certifications in marketing without confirming the individual tester holds current, relevant ones.
- Providers citing legacy IT certifications (like a 20-year-old database credential) to build authority. Relevant offensive security credentials matter.
What Certifications or Accreditations Does 7ASecurity Hold?
That's a different question from what our testers hold individually and should be asked separately.
As a penetration testing provider, we hold ISO 27001 and SOC 2 certifications, and Lloyd's Insurance Company insures all our engagements. This shows that we meet international standards for data security and operational accountability.
Red Flag
- Testing complex systems carries risk. A vendor without liability insurance leaves your business exposed to unnecessary financial danger.
- If a security service provider can't name independently audited standards like these, ask a more basic question. Who's liable if something goes wrong during testing, and is that backed by anything beyond a promise?
Can We See a Sample Report or Your Public Work?
Yes. We publish real pentest reports rather than describing our process in the abstract. Alongside them are public-interest security disclosures like the flaws we found in Hong Kong's COVID contact-tracing app and the CloudPets toys pulled from shelves after we flagged them.
Worth Knowing
Penetration testing service providers, us included, tend to publish reports once the highest-severity issues are already resolved, often after more than one round of testing. So a public report usually sounds calmer than whatever we caught on the first pass. That's not the report hiding anything. It's what happens after a fix.
Can We Request References or Speak to a Past Client?
This isn't always the case, but it isn't automatically a bad sign. Most engagements are covered by an NDA, so plenty of penetration testing companies, us included, can't hand over a client list on request.
What we can do is describe the type of work in general terms and point to the reports we're allowed to publish under our name. In many cases, published reports and documented public-interest work are a more reliable way to judge depth than a reference call alone.
Red Flag
- A provider who treats every past engagement as entirely confidential, with nothing they can point to even in general terms. Normal client confidentiality and total opacity aren't the same thing.
- If a provider can't provide descriptions of past work or share public work, that's worth asking about directly.
How Is Pricing Determined?
We determine pricing based on a thorough scoping call, not a rate card. We can't quote a fair price without understanding what we're testing, how big it is, and what matters most to you.
Red Flag
- A fixed number with no scoping conversation usually means the pentest company is guessing at the scope. Someone ends up paying for that gap, either you in change requests or the tester in cut corners.
- Getting a number before anyone's asked about your scope is usually a sign of a templated test, not one built around what you're protecting.
- Providers who offer flat-rate pricing without looking at your specific technical architecture first could mean you’re dealing with vulnerability scans and not manual penetration tests.
Do We Need an NDA in Place Before the Scoping Call?
Generally, not for the first conversation. A scoping call is usually just us asking what you want us to test and what worries you most; nothing that needs paperwork first. Once we're past that and into specifics, architecture details, access requirements, or anything sensitive, an NDA goes in place.
However, mutual NDAs are standard practice. So, you can request one during a scoping call, especially if you share sensitive details about your network architecture, application logic, or cloud infrastructure. Any professional penetration testing company will willingly sign an NDA or provide their own template before discussing any confidential information.
Red Flag
If a pentester wants deep technical detail or live credentials before an NDA exists, that's worth slowing down for.
What Happens if We Need to Retest After Fixing Issues?
For up to a year after receiving our report, we retest your team's bug patches for free.
Once your team has patched what we found, we’ll verify the fix, flag anything still exploitable, and confirm the bypass hasn't just moved the problem somewhere else. That's part of our quality guarantee, not a follow-up invoice.
Red Flag
‘Zero vulnerability’ guarantees. Cybersecurity is an ongoing process. No reputable pentester can or will guarantee that your system is completely hack-proof.
Can a Penetration Testing Company Test if We Don't Have a Staging Environment?
Yes, we can test your production environment. However, we strongly advise testing in a staging environment that mirrors production to eliminate the risk of live disruptions.
Without staging, how the test runs changes. We're testing production, which means agreeing upfront on timing, how contained any disruption would be, and what happens if something breaks mid-test.
Testing production isn't automatically unsafe. It just needs a proper conversation about risk tolerance before we start.
Red Flag
A pentest service provider happy to test production without ever raising that conversation is the real concern, not the missing staging environment.
What Happens to Our Data During and After the Engagement?
We treat your data with the highest level of care. Access credentials and sensitive materials are handled under EU, GDPR-aware practices throughout and permanently deleted as soon as the project ends.
Red Flag
Avoid providers without clear data deletion policies. A credible partner, especially one operating within the EU, will explicitly state their GDPR compliance and data destruction procedures.
What Quality Penetration Testing Providers Will Ask You
A good provider doesn't just answer your questions. They ask their own before they send a proposal. If a pentest company skips straight to a quote without asking any of the below, that's worth pausing on.
- What are the hard boundaries of the scope? Not just which systems, but which actions are off-limits (destructive testing, certain data types, live customer records).
- Are we testing on a staging or production environment? And if it's production, what's the tolerance for anything that might cause disruption?
- What's driving your deadline? A compliance requirement, a launch date, or a recent incident all change how a test should be prioritised and scoped.
- What access will you provide our team and by when? Credentials, network access, or documentation should be agreed on before testing starts.
- What's your risk tolerance for test impact? Some organisations want testers to push hard and accept some risk of disruption. Others want a lighter touch. A quality penetration tester asks rather than assumes.
- Do you have a previous report to benchmark against? A past report tells a new tester what's already been checked and what's changed since, which sharpens the scope of the new engagement.
None of this is paperwork for its own sake. It's how a penetration testing company works out where the real risk sits before they start poking at it. A provider who skips these questions is testing blind, and you're the one carrying that risk.
Ready to Ask Us Your Questions?
You've seen general answers. The next step is asking us these questions in a real conversation about your systems, scope, and timeline.
Want to Read More?
- Don't let a flat-rate number fool you; learn how to weigh your options in our guide on how to compare pentest quotes.
- Make sure you’re asking for the right pentesting services by understanding the core differences between the various types of penetration testing.
- Learn how to define what a provider should and shouldn't test by reading our breakdown of penetration testing scopes.