Skip to main content
EYCustomer feedback

Security professionals express skepticism about the technical depth of penetration test reports from EY and other Big 4 firms, viewing them as superficial, automated scans that indicate a vendor...

What happened

Security professionals express skepticism about the technical depth of penetration test reports from EY and other Big 4 firms, viewing them as superficial, automated scans that indicate a vendor has a budget rather than robust security testing.

Source

RedditAug 23, 2026By u/InspectionHot8781

r/AskNetsec

How are other CISOs grading vendor pentest credibility during TPRM reviews?

upvotes
17
comments
14

Post

Highlighted: the lines this signal was extracted from

I’m refining our vendor onboarding / TPRM process and evaluating how we score the credibility of third-party penetration test reports. We see everything from Big 4 firms (EY, KPMG, Deloitte) to specialized boutiques and automated scanner outputs. I’m curious about community consensus: - How much technical weight do you actually give to a Big 4 pentest report during vendor risk assessments? - Which boutique or specialized pentest shops make you feel confident a vendor’s application was truly poked at by skilled offensive pros? - Beyond the logo on the report, what specific details in the methodology or scope sections trigger immediate red flags for you? Would love to hear how other CISOs and SecOps teams grade these.

Also quoted as evidence

  • [comment u/Acceptable-Box-4400] Big 4 reports usually mean the vendor has budget, not that they got tested well. I’ve seen too many that were basically a nessus scan with a fancy cover page

  • [comment u/CyberOrbit-ai] The Big 4 reports I treat as heavy on procurement weight and light on technical weight. They're often scoped narrowly and delivered by rotating junior staff to a fixed method, so what you get is a CVSS list with a nice cover page.

reddit.com/r/AskNetsec/comments/1vw3klh/how_are_other_cisos_grading_v...Read the full source

Comments on the post

5 of 14 comments
  • “Big 4 reports usually mean the vendor has budget, not that they got tested well. I’ve seen too many that were basically a nessus scan with a fancy cover page The scope section is where I look first. If it’s vague about what was actually tested or says something like “performed automated vulnerability assessment” without manual exploitation details, I’m not giving it much weight Boutique shops”

    u/Acceptable-Box-440012 points · Aug 23, 2026View

  • “In our pentesting reports, we ensure transparency and traceability. For the scope we include all IP ranges, FQDN, etc. In the methodology section, we call out the frameworks that we actually used during test and map the findings to those frameworks. We include the team that did the test and their credentials. For the attack narrative, we show everything we’ve done so you can review step by step sp”

    u/DigitalQuinn13 points · Aug 23, 2026View

  • “Do they give you the scoping questionnaire? An unauthenticated test against an app whose whole surface sits behind login is not a test, and that one line kills more reports than the logo on the cover does. After that I read for chains, since twenty standalone findings and no business logic issue means it was run rather than performed.”

    u/AddendumWorking97562 points · Aug 23, 2026View

  • “Honestly, most people give the logo too much weight and the evidence too little, so that's where I'd start. The Big 4 reports I treat as heavy on procurement weight and light on technical weight. They're often scoped narrowly and delivered by rotating junior staff to a fixed method, so what you get is a CVSS list with a nice cover page. I don't dismiss them, I just give the evidence the weight r”

    u/CyberOrbit-ai2 points · Aug 24, 2026View

  • “Look at the methodology. Do they give findings? Or, to they give repeatable steps to validate those findings with the steps that led them to that conclusion.”

    u/strandjs1 points · Aug 23, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/AskNetsec

Companies

  • KPMGAlso named
  • DeloitteAlso named

The full record

From the Signal API record

Numbers

Mentions
1

Details

Timing
Ongoing state
Category
General
Virality
Somewhat high
Post kind
Text
Prominence
Core
Company's role
Vendor

Topics and mentions

Topics

  • penetration testing
  • cybersecurity
  • vendor risk management
  • compliance
  • tprm

Products named

  • penetration testing services

Extraction

Sentiment
Negative
Detected
Aug 23, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for EY and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at EY this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/58772c68-cf47-5898-a28a-8d3181d274c0 returns this record as JSON. POST /v1/companies/enrich returns every signal for ey.com.

{
  "signal_id": "58772c68-cf47-5898-a28a-8d3181d274c0",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-08-23T10:24:58+00:00",
  "company": {
    "name": "EY",
    "domain": "ey.com"
  },
  "data": {
    "nsfw": false,
    "stage": "none",
    "awards": 0,
    "timing": "ongoing_state",
    "topics": [
      "penetration testing",
      "cybersecurity",
      "vendor risk management",
      "tprm",
      "compliance"
    ],
    "post_id": "1vw3klh",
    "summary": "Security professionals express skepticism about the technical depth of penetration test reports from EY and other Big 4 firms, viewing them as superficial, automated scans that indicate a vendor has a budget rather than robust security testing.",
    "category": "general",
    "comments": [
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1vw3klh/comment/p5dszh7/",
        "depth": 0,
        "score": 12,
        "author": "Acceptable-Box-4400",
        "excerpt": "Big 4 reports usually mean the vendor has budget, not that they got tested well. I’ve seen too many that were basically a nessus scan with a fancy cover page\n\n The scope section is where I look first. If it’s vague about what was actually tested or says something like “performed automated vulnerability assessment” without manual exploitation details, I’m not giving it much weight\n\n Boutique shops",
        "posted_at": "2026-08-23T10:32:21.000Z",
        "author_url": "https://www.reddit.com/user/Acceptable-Box-4400/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1vw3klh/comment/p5eakwn/",
        "depth": 0,
        "score": 3,
        "author": "DigitalQuinn1",
        "excerpt": "In our pentesting reports, we ensure transparency and traceability. For the scope we include all IP ranges, FQDN, etc. In the methodology section, we call out the frameworks that we actually used during test and map the findings to those frameworks. We include the team that did the test and their credentials. For the attack narrative, we show everything we’ve done so you can review step by step sp",
        "posted_at": "2026-08-23T12:34:53.000Z",
        "author_url": "https://www.reddit.com/user/DigitalQuinn1/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1vw3klh/comment/p5f7g3s/",
        "depth": 0,
        "score": 2,
        "author": "AddendumWorking9756",
        "excerpt": "Do they give you the scoping questionnaire? An unauthenticated test against an app whose whole surface sits behind login is not a test, and that one line kills more reports than the logo on the cover does. After that I read for chains, since twenty standalone findings and no business logic issue means it was run rather than performed.",
        "posted_at": "2026-08-23T15:20:09.000Z",
        "author_url": "https://www.reddit.com/user/AddendumWorking9756/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1vw3klh/comment/p5juprm/",
        "depth": 0,
        "score": 2,
        "author": "CyberOrbit-ai",
        "excerpt": "Honestly, most people give the logo too much weight and the evidence too little, so that's where I'd start.\n\n The Big 4 reports I treat as heavy on procurement weight and light on technical weight. They're often scoped narrowly and delivered by rotating junior staff to a fixed method, so what you get is a CVSS list with a nice cover page. I don't dismiss them, I just give the evidence the weight r",
        "posted_at": "2026-08-24T06:20:34.000Z",
        "author_url": "https://www.reddit.com/user/CyberOrbit-ai/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1vw3klh/comment/p5e0bv6/",
        "depth": 0,
        "score": 1,
        "author": "strandjs",
        "excerpt": "Look at the methodology. Do they give findings? Or, to they give repeatable steps to validate those findings with the steps that led them to that conclusion.",
        "posted_at": "2026-08-23T11:28:09.000Z",
        "author_url": "https://www.reddit.com/user/strandjs/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1vw3klh/comment/p5f9tvc/",
        "depth": 0,
        "score": 1,
        "author": "MountainDadwBeard",
        "excerpt": "Most pen test reports are checkbox/useless. Some of them just check website headers are configured, and list nothing else.\n\n If you read the scope of the report, some of them will actually describe a more thorough pen test and those are the ones I evaluate positively with some mild skepticism still for if they just copy paste the same report accross all companies.",
        "posted_at": "2026-08-23T15:31:05.000Z",
        "author_url": "https://www.reddit.com/user/MountainDadwBeard/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1vw3klh/comment/p5fx7qd/",
        "depth": 0,
        "score": 1,
        "author": "AYamHah",
        "excerpt": "They aren't.\n\n You need a relationship with that team and a solid understanding of your own environment such that you know what to expect on these reports. If you're not consistently finding highs and criticals, and you know you have them (hint: you do), find another vendor.\n\n It's about the team, not the company. I've worked on Big 4 teams that were amazing, and some that were not. I've worked on",
        "posted_at": "2026-08-23T17:15:44.000Z",
        "author_url": "https://www.reddit.com/user/AYamHah/"
      },
      {
        "url": "https://www.reddit.com/r/AskNetsec/comments/1vw3klh/comment/p5muc3j/",
        "depth": 0,
        "score": 1,
        "author": "recovering-pentester",
        "excerpt": "Can tell a lot via transparency of methodology and for thorough the replication steps are.\n\n Logo in the report means nothing other than budget as others have said.",
        "posted_at": "2026-08-24T17:02:38.000Z",
        "author_url": "https://www.reddit.com/user/recovering-pentester/"
      }
    ],
    "evidence": [
      "[post] How much technical weight do you actually give to a Big 4 pentest report during vendor risk assessments?",
      "[comment u/Acceptable-Box-4400] Big 4 reports usually mean the vendor has budget, not that they got tested well. I’ve seen too many that were basically a nessus scan with a fancy cover page",
      "[comment u/CyberOrbit-ai] The Big 4 reports I treat as heavy on procurement weight and light on technical weight. They're often scoped narrowly and delivered by rotating junior staff to a fixed method, so what you get is a CVSS list with a nice cover page."
    ],
    "virality": "somewhat_high",
    "post_date": "2026-08-23T10:24:58.000Z",
    "post_kind": "text",
    "post_text": "I’m refining our vendor onboarding / TPRM process and evaluating how we score the credibility of third-party penetration test reports.\n\nWe see everything from Big 4 firms (EY, KPMG, Deloitte) to specialized boutiques and automated scanner outputs. I’m curious about community consensus:\n\n- How much technical weight do you actually give to a Big 4 pentest report during vendor risk assessments?\n\n- Which boutique or specialized pentest shops make you feel confident a vendor’s application was truly poked at by skilled offensive pros?\n\n- Beyond the logo on the report, what specific details in the methodology or scope sections trigger immediate red flags for you?\n\nWould love to hear how other CISOs and SecOps teams grade these.",
    "sentiment": "negative",
    "subreddit": "AskNetsec",
    "post_flair": [
      "Compliance"
    ],
    "post_title": "How are other CISOs grading vendor pentest credibility during TPRM reviews?",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/AskNetsec/comments/1vw3klh/how_are_other_cisos_grading_vendor_pentest/",
    "entity_role": "vendor",
    "post_author": "InspectionHot8781",
    "upvote_ratio": 0.9473684210526315,
    "mention_count": 1,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/AskNetsec/",
    "total_upvotes": 17,
    "comments_total": 14,
    "total_comments": 14,
    "other_companies": [
      {
        "name": "KPMG",
        "role": "competitor",
        "domain": "kpmg.com"
      },
      {
        "name": "Deloitte",
        "role": "competitor",
        "domain": "deloitte.com"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/InspectionHot8781/",
    "signal_category": "feedback",
    "comments_included": 9,
    "products_mentioned": [
      "penetration testing services"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.