Published: October 15, 2025
15
29
104

When should you NOT do a pen test? Sounds weird from a pentester, I know lol… but if you want real value, thinking about that question matters... I see pentesting as the "final exam." 🧵 It's something you should study for. Hear me out...

Before a pentest, get the basics right... - Asset inventory, who owns what - Patch management that actually patches - Vulnerability scanning that runs, reports, and gets acted on If you do not have bandwidth to remediate, you are about to buy an expensive PDF. Plan time and

Not ready for a pentest but want to do something? - GRC based assessments like: NIST, PCI, HIPAA, CIS, etc. - Vulnerability assessments (internal and/or external) - Targeted reviews, segmentation testing, endpoint evaluation, M365/Entra cloud config assessment Compliance can be

Common external pentest blockers: - Unknown public footprint - Out of date sites/services you did not know you owned - No clear owner to patch WordPress, VPN, or edge devices, etc. Fix those first, then do the pentest.

For internal pentests, do this first - Audit AD permissions, especially Tier 0 - Eliminate local admin on workstations - Search file shares and SharePoint for creds and juicy data These three issues are why we get DA by 9 a.m. on Monday...

For web apps, "shift left": - Have a staging or test environment, full stop... please don't test in prod -.- - Integrate DAST and SAST in dev cycles - Define security requirements just as you would define business requirements Catching mistakes via pentesting is great, but many

Choose the right assessment by mapping to your goal: - Improve hygiene? Risk/vuln assessment - Validate detection and response? Purple team - Mature program with strong SOC? Assume breach/Internal Pentest

Real story, we sometimes tell prospects, you do not need a pentest yet. You need inventory, patching, risk assessments, program development first. Do the right thing for your maturity, you will get more value and better results

Security is a lifecycle, not one and done. Tech changes, people change… the process repeats. Stack small wins, then validate with a pentest when you are ready.

Finally, if you've read this far, thank you so much! The best way you can thank me, is by reposting ♻ the original tweet for this thread. You rock! 🤘

@techspence How about "your admins can already tell you what is broken and risky"?

@alexanderjaeger Its usually, the IT admins have been telling leadership but they won't listen then the pentester comes in and says the same things then they listen :D

@techspence Thanks, do you mind if I use some of this at work with credit? There's some useful mirrors that people should look in!

@timinbrum Heck yeah, I’d be honored to be printed out framed and hung on the wall 😆

@techspence Bonus points: Regardless of test type, ensure you've reviewed sample reports especially if choosing timeboxed tests. Compare reports from 20 & 40 hour tests. Choose testers that offer free retests. Check whether they can integrate findings directly into your task mgmt system too

Share this thread

Read on Twitter

View original thread

Navigate thread

1/15