Points to examine
Use these points when reviewing the work
- Delivery flow: lead time, blocked time, and report turnaround.
- Quality: review cycles, material defects, and evidence completeness.
- Client friction: clarification, escalation, and disputed decisions.
- Capacity resilience: senior dependency and avoidable unbilled work.
- Development: demonstrated progression in judgement and client ownership.
Recommended reading
Articles in this guide
How to measure penetration testing team performance
Measure pentest team performance using project and QA records alongside utilisation. Define each measure consistently and read related results together, allowing for engagement complexity and staffing changes. Start with a delivery problem the team needs to resolve, select measures that help explain it and review whether an agreed change improves the work.
Read articleHow poor client communication erodes pentest margin
Poor client communication adds cost when people have to clarify an agreed scope, reconstruct findings or revisit decisions after delivery. On a fixed-price engagement, extra work reduces margin unless additional fees cover it. Record the time against the project and examine its cause before deciding whether the response belongs in scoping, reporting or account management.
Read articleHow poor scoping damages penetration testing delivery
A usable pentest scope describes the work to be done and the conditions needed to do it. Asset counts help estimate effort, but they leave important questions about access and application complexity unanswered. Record those assumptions before booking, confirm readiness and agree how unmet prerequisites will affect coverage or delivery dates.
Read article