Offensive security delivery glossary

Stable, plain-language definitions for the leadership and delivery concepts used throughout Conversec’s articles.

This glossary defines Conversec’s use of recurring terms. The definitions describe delivery and leadership concepts rather than technical testing techniques, and make the intended meaning explicit when a term is cited outside its original article.

Client friction

Avoidable clarification, challenge, delay, or rework caused by unclear scope, evidence, decisions, expectations, or ownership during a penetration testing engagement.

#

Consulting maturity

The repeatable ability to connect technical testing evidence with context, judgement, clear communication, and practical client decisions.

#

Delivery flow

The movement of an engagement from qualified scope through access, testing, review, reporting, debrief, and closure, including time spent blocked or waiting.

#

Evidence chain

The traceable connection between the test performed, the observation recorded, the technical conclusion, the severity rationale, and the recommendation given to the client.

#

Fractional offensive security leadership

Part-time senior ownership of an offensive security function’s delivery system, including quality, capacity, escalation, consultant development, and improvement priorities.

#

Key-person dependency

Operational reliance on one or a few experienced people to rescue delivery, approve decisions, retain client knowledge, or maintain quality that the wider system cannot reproduce.

#

Pentest quality assurance

A review control that tests technical accuracy, evidence sufficiency, severity logic, limitations, recommendations, and client usability—not merely spelling and formatting.

#

Pentest team performance

The ability to produce reliable client outcomes with consistent quality, controlled delivery flow, proportionate senior involvement, and sustainable use of team capacity.

#

Report rework

Material revision required because a finding’s evidence, reasoning, severity, recommendation, or explanation was not ready for client delivery at the expected review point.

#

Senior dependency

The share of routine delivery that needs unplanned intervention from senior practitioners to resolve scope, evidence, reporting, or client communication issues.

#

Severity dispute

A structured review triggered when a client or reviewer challenges a vulnerability rating, requiring the team to revisit evidence, technical characteristics, threat, environmental context, and assumptions.

#

Unbilled delivery load

Necessary engagement work that consumes team capacity but is not captured in planned effort, such as repeated clarification, report rewriting, avoidable escalation, or access-related recovery.

#

Definitions are useful when they lead to better operating decisions.

Use the topic guides to connect each term to practical frameworks and detailed articles.