An external auditor, a major customer or your cyber insurer has asked for your latest penetration test results. The report contains a map of your weaknesses: hostnames, vulnerable services, sometimes screenshots of credentials or sensitive data the testers reached. Someone suggests just emailing the PDF. Someone else says never share it at all. What is the sensible middle ground?
The practical answer: share the minimum needed to satisfy the requester’s purpose, in the most controlled way available. Most customers and many auditors are satisfied by an executive summary or attestation letter from the testing firm, plus evidence that findings were remediated. When the full report is genuinely required, share it through a secure portal or data room with access limited to named people, expiry dates, watermarking and no download where possible, under a confidentiality agreement, and after removing anything that would directly help an attacker.
Match what you share to why they are asking
| Requester | What they usually need | What to offer first |
|---|---|---|
| Customer security questionnaire | Evidence you test regularly and fix issues | Attestation letter or executive summary with remediation status |
| Cyber insurer | Assurance of testing and control maturity | Summary, date, scope and high-level results |
| Compliance auditor (SOC 2, ISO 27001, PCI) | Evidence the control operated and findings were tracked | Report access in a controlled session or portal, plus remediation tickets |
| Regulator or incident investigator | Full detail | Full report via secure channel, often with legal counsel involved |
Why email is a poor default
- Attachments get forwarded, stored in personal mailboxes and kept indefinitely.
- You lose control of who reads them once sent.
- A compromised recipient mailbox exposes your weaknesses to attackers.
- Encryption alone does not solve forwarding or retention.
A safer way to share
- Ask the testing firm for a shareable version: an attestation letter or executive summary stating scope, dates, methodology and overall results.
- Redact sensitive details from any fuller version: credentials, internal IP addresses, exploit steps and screenshots of sensitive data.
- Use a secure portal or data room with named access, multifactor authentication, view-only mode, watermarking and automatic expiry.
- Sign a confidentiality agreement covering use, storage and deletion.
- Label the sensitivity. The Traffic Light Protocol (TLP 2.0), maintained by FIRST, gives a common language: TLP:RED limits information to named recipients only, while TLP:AMBER+STRICT restricts sharing to the recipient’s organisation.
- Include remediation evidence showing what was fixed and retested; this is often what the requester really wants.
- Log access and revoke it when the review ends.
Handling old findings that are not yet fixed
Requesters understand that not every finding is fixed immediately. Show a remediation plan with owners, timelines and compensating controls for open items. Hiding unresolved high-risk findings usually causes more trouble in audits than disclosing them with a credible plan.
Plan for sharing before the test
When you scope the next penetration test, ask the firm to produce two deliverables: a detailed technical report for your team and a customer-facing summary or attestation. It is cheaper to write both at the time than to redact later. Our guide on how to buy a penetration test and not an automated scan covers other scoping questions, and how to read CVSS and risk ratings in pen test reports helps you explain severity to outsiders.
A hypothetical example: a B2B SaaS company receives three customer requests for its pen test in a quarter. It provides a signed attestation letter and remediation summary via its trust portal to all three, and gives its SOC 2 auditor time-limited, view-only access to the full report. Nobody receives a PDF by email.
Pen testing with sharing built in
A penetration test should strengthen trust with customers and auditors, not create a new data leak. AB7 Solutions’ cybersecurity team delivers vulnerability assessment and penetration testing (VAPT) with a detailed technical report, a customer-shareable executive summary or attestation letter, remediation tracking and retest confirmation. We can also help you set up a controlled process for sharing security evidence. If a summary will satisfy your requester, we will recommend that over sharing the full report.
Tell us who is asking for your pen test results and why, and we will suggest what to share and how.
Email: ab@ab7solutions.com | director@ab7solutions.com
Phone: +91 9878067778 | +1 321 341 7733
Website: www.ab7solutions.com
Sources: FIRST, Traffic Light Protocol (TLP) 2.0.