Contents
- What is consultant-led penetration testing?
- Automated vs consultant-led penetration testing: what’s the difference?
- Why does scoping a penetration test matter?
- What questions should a penetration testing provider ask you?
- How to choose a penetration testing provider
- How to get the most value from a penetration test
- Frequently asked questions
- Is consultant-led penetration testing worth the higher cost?
- How long does a consultant-led penetration test take?
- What qualifications should a penetration testing consultant have?
- Do I still need automated scanning if I use consultant-led penetration testing?
- How can I tell whether a provider is genuinely consultant-led?
Don’t be concerned if this isn’t you, but most people who buy a penetration test already know what they want. They have a system to check and a deadline to hit, often with a compliance requirement attached.
Now, the reason we say not to be concerned is that the test you ask for isn’t always the one that tells you the most about your security, and certainly isn’t always the test you should get.
The fundamentals of consultant-led penetration testing are built around that very idea.
A good provider treats your request as the start of a conversation, not the final word, and someone who’s truly conscious about their cybersecurity will lean on that experience to get the best value for their money.
What is consultant-led penetration testing?
Consultant-led penetration testing is a security test in which a qualified human tester helps you decide what to test and why before testing begins, then carries out and interprets the work.
When you pay for consultant-led penetration testing, you’re paying for the tester’s experience and judgement, which shapes the engagement to improve your security posture as much as possible and deliver better ROI per test.
A good consultant treats your initial request as the start of a conversation rather than a fixed order, and draws on their experience to determine what would tell you most about your security. If your original plan is right, they confirm it, and where a different assessment would give you more for the same budget, they say so and explain their reasoning, so that the final decision stays yours, but is far better informed.
This is also where the contrast with automated testing comes in, which we’ll cover in more detail shortly. Automated testing offers little to no consultative analysis before it runs, acting as a basic point-and-shoot type of security test, compared to a well-thought-out and deliberate consultant-led penetration test.
Automated vs consultant-led penetration testing: what’s the difference?
| Automated Testing | Consultant-led Testing | |
| Consultative analysis before the test | Little to none (point-and-shoot) | Central to the engagement |
| Speed | Fast | Slower, but more precise |
| Cost | Lower | Higher |
| Understands context | No | Yes |
| Best suited for | Regular coverage of a largeestate, or quick checks between deeper tests | Understanding our real exposure and deciding what to test |
The consultative gap we’ve just described carries through into the test itself. Automated testing uses scanners and pre-built scripts to check a target against a list of known weaknesses. It runs quickly, costs a lot less and covers a lot of ground, which makes it a sensible choice for regular coverage of a large estate, or for a quick check between deeper, more thorough assessments.
One thing an automated test cannot do, however, is think. An automated scanner will not ask why a particular server is exposed, and it will not notice that two minor findings combine into something serious, because it has no understanding of context. A consultant does exactly those things, both when scoping the work and while carrying it out, which is why the two approaches suit very different jobs rather than competing directly.
We have compared the two in far more detail, including where each one earns its place and how they work together in practice, in our guide to automated vs. manual penetration testing. This article stays focused on what the consultant themselves brings to the engagement.
Why does scoping a penetration test matter?
Scope decides what gets tested and what gets left alone, and if you get it wrong, you can pass a test while your real risk sits untouched. This is the cybersecurity equivalent of going in circles, and it can be very dangerous.
Let’s say you ask for an external infrastructure test. That is a clear, sensible request, and a good provider will respect it, but they will still want to understand the reasoning behind it.
What are you protecting? What keeps you up at night? Has anything changed since your last assessment?
Sometimes those answers confirm your original plan, and other times, they reveal that an internal test, or a web application assessment, would give you far more for the same budget. If you want to understand how the direction of a test changes what it finds, our piece on external vs. internal penetration testing is a useful companion to this one.
What questions should a penetration testing provider ask you?
A provider that nods along to everything is easy to work with, but they are rarely doing you any favours.
Before an engagement at Fortifi, expect questions such as:
- What are you actually trying to find out?
- Which systems would hurt the most if they were breached?
- Are you testing to meet a standard, to reassure a customer, or to genuinely reduce risk?
- What did your last test cover, and what did it miss?
The aim is never to talk you out of what you asked for. On the contrary, it’s to ensure the test is as valuable as possible.
How to choose a penetration testing provider
Price and turnaround are easy to compare, but the harder question is whether a provider will challenge you when it counts.
Look for a few signs:
- They ask about your business before they quote.
- They are willing to recommend a different test from the one you came in for.
- They explain findings by impact, not just by severity score.
- They will tell you when a cheaper, automated option would serve you just as well.
A supplier who pushes back can feel like a lot of hard work, but in practice, they’re protecting your budget and your security at the same time, which makes them the best partner you could ask for.
Rather than repeat the detail here, we have set out the full list of questions to put to any provider before you sign, covering named testers, methodology, data residency and remediation support in what you’re actually paying for when you buy a penetration test. The questions were written with schools in mind, but they apply just as well to any sector.
How to get the most value from a penetration test
A penetration test is only as useful as the thinking behind it. Automation has earned its place, and the right provider will tell you that to your face, but when the goal is to understand your real exposure, a consultant who asks “why” before they start will give you far more bang for your buck.
At Fortifi, that conversation is where every engagement begins. If you would like to talk through what you should be testing, rather than simply what you planned to test, we are happy to start there. Get a quote today.
Frequently asked questions
Is consultant-led penetration testing worth the higher cost?
For most businesses trying to understand their real exposure, yes. The higher price pays for a qualified person to scope the test properly and interpret what they find in the context of your business, which is where most of the value actually sits.
If all you need is routine coverage of a large estate, automated scanning may be the more sensible spend, and a good consultant will say so rather than sell you more than you need. An important note here is that automated tests do not replace the need for consultant-led penetration testing.
How long does a consultant-led penetration test take?
It depends on the scope, but a typical engagement runs from a few days to a couple of weeks, which includes the scoping conversation beforehand and the reporting afterwards.
The testing itself is only one part of that because a consultant also needs time to plan the right approach and to write up findings in a way you can actually act on.
What qualifications should a penetration testing consultant have?
In the UK, look for CHECK, which is the NCSC scheme, or CREST membership at the company level, alongside recognised individual qualifications such as OSCP.
A reputable provider with name the tester who will carry out the work and share their certifications without hesitation. If you cannot get a straight answer, treat that as a warning sign.
Do I still need automated scanning if I use consultant-led penetration testing?
The two work best together rather than as alternatives. Automated scanning is well suited to continuous monitoring between tests, catching missing patches, and newly disclosed weaknesses across a large estate cheaply and often.
Consultant-led penetration testing then gives you ther deeper, context-aware assessement that a scanner cannot, which is why many businesses run both.
How can I tell whether a provider is genuinely consultant-led?
The clearest signal is whether they ask about your business before they quote, and whether they are willing to recommend a different test from the one you came in for.
A genuine consultant also explains their findings by the impact rather than by a severity score alone. Our guide to what you’re actually pay for when you buy a penetration test sets out the full list of questions to ask before you sign.