Offensive security delivery glossary

The terms used in our articles and guidance on running penetration testing teams.

This glossary explains how Conversec uses each term. Refer to these definitions when reading the articles or applying the performance framework.

Client friction

Avoidable clarification, challenge, delay, or rework caused by unclear scope, evidence, decisions, expectations, or ownership during a penetration testing engagement.

#

Consulting maturity

The ability to apply technical knowledge consistently during client work. This includes checking evidence against the client context and explaining conclusions that support a practical decision.

#

Delivery flow

The movement of an engagement from qualified scope through access, testing, review, reporting, debrief, and closure, including time spent blocked or waiting.

#

Evidence chain

The traceable connection between the test performed, the observation recorded, the technical conclusion, the severity rationale, and the recommendation given to the client.

#

Fractional offensive security leadership

Part-time senior responsibility for an offensive security function's delivery. The agreed work can cover quality and capacity decisions, escalations, consultant development and priorities for improvement.

#

Key-person dependency

Reliance on one or a few people for work the wider team cannot carry out to the required standard. This can include delivery decisions or client knowledge held by a single consultant.

#

Pentest quality assurance

A review of the technical accuracy and evidence supporting a report. It also checks the severity reasoning, stated limitations, recommendations and whether the client can use the findings.

#

Pentest team performance

The ability to produce reliable client outcomes with consistent quality, controlled delivery flow, proportionate senior involvement, and sustainable use of team capacity.

#

Report rework

Material revision required because a finding’s evidence, reasoning, severity, recommendation, or explanation was not ready for client delivery at the expected review point.

#

Senior dependency

The share of routine delivery that needs unplanned intervention from senior practitioners to resolve scope, evidence, reporting, or client communication issues.

#

Severity dispute

A structured review triggered when a client or reviewer challenges a vulnerability rating, requiring the team to revisit evidence, technical characteristics, threat, environmental context, and assumptions.

#

Unbilled delivery load

Necessary engagement work that consumes team capacity but is not captured in planned effort, such as repeated clarification, report rewriting, avoidable escalation, or access-related recovery.

#

Read examples of these terms in use.

The articles explain delivery decisions, and the performance framework defines the measures used to review them.