A pentest report is not the end of an engagement. It is the interface between offensive assessment and the people who must decide, fix, and verify.

Separate observation from impact

The observation describes the behavior precisely. Impact explains what an attacker can achieve in the business context. Mixing them produces either alarmist language or technical detail with no priority.

Evidence should be minimal, reproducible, and stripped of unnecessary secrets. It shows the preconditions, request or action, and the relevant result.

Explain the root cause

Fixing one parameter or blocking one route is insufficient when the same rule is missing elsewhere. Connect the symptom to the design decision: client-side enforcement, scattered authorization, an overlong secret lifetime, or an implicit trust boundary.

This helps the team search for variants instead of closing a single ticket.

Make priority defensible

Technical severity is one signal. Priority should include exposure, required privileges, exploit reliability, data sensitivity, and compensating controls.

Document assumptions. If impact depends on an unknown configuration or volume, state that explicitly.

Offer a remediation path

A useful recommendation distinguishes:

  1. The immediate measure that reduces exposure.
  2. The durable correction for the root cause.
  3. The tests or controls that prevent regression.

It describes the security objective without forcing an implementation that conflicts with the team’s architecture.

Define the retest before closure

A retest checks the original scenario, likely variants, and obvious functional regressions. “Fixed” requires evidence; “accepted risk” requires an owner and rationale.

Preserve the timeline: tested version, date, reproduced behavior, observed fix, and retest limitations. This turns the report into a decision history.

Minimum finding structure

  • Risk-oriented title
  • Affected asset and component
  • Preconditions and attack scenario
  • Reproducible, sanitized evidence
  • Technical and business impact
  • Root cause
  • Severity and assumptions
  • Immediate and durable recommendations
  • Retest criteria

The report’s value is measured less by page count than by whether teams can decide and demonstrate that risk was reduced.