r/AskNetsec
How are other CISOs grading vendor pentest credibility during TPRM reviews?
- upvotes
- 17
- comments
- 14
Post
Highlighted: the lines this signal was extracted from
I’m refining our vendor onboarding / TPRM process and evaluating how we score the credibility of third-party penetration test reports. We see everything from Big 4 firms (EY, KPMG, Deloitte) to specialized boutiques and automated scanner outputs. I’m curious about community consensus: - How much technical weight do you actually give to a Big 4 pentest report during vendor risk assessments? - Which boutique or specialized pentest shops make you feel confident a vendor’s application was truly poked at by skilled offensive pros? - Beyond the logo on the report, what specific details in the methodology or scope sections trigger immediate red flags for you? Would love to hear how other CISOs and SecOps teams grade these.
Also quoted as evidence
[comment u/Acceptable-Box-4400] Big 4 reports usually mean the vendor has budget, not that they got tested well. I’ve seen too many that were basically a nessus scan with a fancy cover page
[comment u/CyberOrbit-ai] The Big 4 reports I treat as heavy on procurement weight and light on technical weight. They're often scoped narrowly and delivered by rotating junior staff to a fixed method, so what you get is a CVSS list with a nice cover page.