Penetration Test Deliverable Breakdown | Lorikeet Security Canada Skip to main content
Back to Blog

What a Penetration Testing Deliverable Actually Looks Like: Dissecting an Executive Attestation vs Vulnerability Dump

Lorikeet Security Canada Technical Team Sep 7, 2026 8 min read 1,420 views

TL;DR: Direct answer: A legitimate penetration testing deliverable consists of three core components: an Executive Summary explaining business impact for board and commercial buyers; an Attestation Letter suitable for sharing with clients and auditors; and a detailed Technical Findings section with CVSS v3.1 scoring, step-by-step developer reproduction curl commands, and remediation validation.

The Three Core Components of a Real Deliverable

First-time penetration test buyers are often uncertain about what will actually be delivered once fieldwork wraps up. Will you receive a raw CSV spreadsheet? A 100-page automated tool export? Or a strategic, board-ready asset?

At Lorikeet Security Canada, our deliverables are engineered to satisfy two very different audiences simultaneously: the executive leadership team (and their enterprise prospective clients) who need a clear commercial risk assessment, and the software engineering team who must fix the identified vulnerabilities immediately.

A complete deliverable package consists of three integrated documents:

  • The Comprehensive Assessment Report: The primary confidential document detailing the kill chain, attack narratives, and technical reproduction steps.
  • The Executive Letter of Attestation: The public-facing, audit-ready document designed to be shared with enterprise buyers, insurance brokers, and CPA auditors.
  • Remediation Retest Verification: The updated attestation certifying that identified vulnerabilities were re-evaluated and confirmed resolved.

Section 1: The Executive Summary and Risk Profile

The first section of our comprehensive report is written for non-technical leadership: CEOs, CTOs, legal counsel, and board members. It translates technical vulnerability data into actionable business risk context.

Rather than simply tallying CVE numbers, the executive summary answers the core operational questions:

  • Could an unauthenticated attacker gain access to customer databases or personal information?
  • Were testers able to cross organizational boundaries in our multi-tenant SaaS architecture?
  • Did internal telemetry or monitoring alert the engineering team when attacks were launched?
  • What are the top three strategic remediation investments that will deliver the highest risk reduction?

Red Flag: If an executive summary consists merely of an automated pie chart displaying "5 High, 12 Medium, 20 Low" without narrative context, your testing firm utilized automated reporting software rather than manual offensive analysis.


Section 2: The Letter of Attestation

The Letter of Attestation is the commercial engine of the deliverable. It is deliberately separated from the confidential technical report so your sales and compliance teams can provide it to prospective customers, CPA auditors, and cyber insurers without hesitation.

It explicitly states:

  • The independent testing organization (Lorikeet Security Canada).
  • The precise scope tested (domains, web apps, APIs, cloud environments, and user role levels).
  • The testing framework adhered to (OWASP Web Security Testing Guide, PTES, NIST).
  • The fieldwork dates and final retest completion date.
  • A formal statement that identified high-risk vulnerabilities have been remediated and verified closed.

Section 3: Technical Findings & Reproducible Proofs

For your engineering team, our report provides an exhaustive, developer-ready breakdown for every finding. We follow a strict documentation standard that eliminates guesswork:

Finding Field What Lorikeet Security Canada Provides Why Developers Value It
CVSS v3.1 Score Full vector string (Base, Temporal, Environmental) with severity rating. Enables objective prioritization against internal SLAs.
Proof of Concept (PoC) Exact, copy-pasteable curl commands with request headers, parameters, and bodies. Developers reproduce the vulnerability locally in under 60 seconds.
Root Cause Analysis Explains the architectural failure (e.g., missing middleware authorization check). Prevents recurring regressions across related API endpoints.
Remediation Guidance Framework-specific code examples (Node.js, Python, PHP, Go, AWS IAM). Saves hours of developer research with concrete implementation patterns.

How to Inspect Our Specimen Demo Report

We believe in total transparency before you sign an engagement. You can review our complete, specimen penetration testing deliverable directly on our website.

Our sample report showcases real-world attack scenarios, including broken object-level authorization (BOLA) exploitation, SQL injection parameter chaining, cross-site scripting (XSS), and privilege escalation paths, formatted to enterprise audit standards.

Frequently Asked Questions

In what formats do you deliver the final penetration test report?

We deliver an encrypted, professionally styled PDF report, along with an official executive Letter of Attestation. We can also provide a structured JSON or CSV export of findings for direct import into Jira, Linear, or vulnerability management platforms.

Can we request a readout call with our engineering team?

Yes. Every engagement includes a 45-minute technical readout call where our lead offensive tester walks your developers through each finding, demonstrates the exploit live, and answers architectural remediation questions.

How soon after fieldwork concludes do we receive the report?

Draft reports are delivered within 2 to 3 business days following the completion of active fieldwork.

Want to inspect our authentic specimen report?

Download our complete demo penetration test report to review our reporting methodology, exploit proofs, and attestation letter format.

1,420 views
Link copied!
Lorikeet Security Canada

Lorikeet Security Canada Technical Team

Penetration Testing & Compliance Consulting

Lorikeet Security Canada helps Canadian organizations and high-growth engineering teams in Calgary, Toronto, and nationwide assess risk, satisfy enterprise procurement questionnaires, and close security gaps with certified penetration testing and compliance readiness.