What is penetration testing?
Penetration testing (pentesting) is an authorized, simulated attack on a system to find exploitable weaknesses. It is performed by skilled testers, usually from an independent firm, and goes beyond automated scanning. The result is a report of findings ranked by severity.
What the buyer is really asking
Buyers want three facts: how often, by whom, and what happened to the findings. An annual test by a named independent firm is the common expectation. Offer a summary letter instead of the full report.
Other ways buyers ask it
Every one of these wants the same answer:
- “Do you conduct penetration testing? How often and by whom?”
- “Can you share your latest penetration test report?”
- “Are all critical and high pentest findings remediated?”
Evidence to have ready
- A penetration test summary or attestation letter
- Remediation status for the findings
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.