Penetration testing for MSPs › When the findings are yours
You arranged the test. You scoped it, you got the signature, you gave the tester credentials, and the report has come back to you before it goes to the client. It contains seven findings. Two of them are about a configuration your team put in place, one is about a patching gap on a server you manage, and one is about a service that has been exposed to the internet since a project in 2022 that nobody closed off.
This is the moment that decides whether testing becomes a line in your catalogue or a thing you quietly stop offering. It is worth thinking about before it happens rather than at half past five on the day the report lands.
An estate with no findings is not being tested properly
Start here, because it reframes everything that follows. A competent test of a real estate that has been running for years produces findings. Not because the people who built it are bad at their jobs, but because an estate is a moving thing: software ages, vendors end support, a firewall rule is opened for a migration, a service account is created for an integration, a developer needs remote access for a fortnight in March.
A report with nothing in it means one of three things. The scope was drawn so tightly that nothing interesting was inside it. The testing was shallow, which usually means unauthenticated testing of something that needed authenticated testing. Or the deliverable was never a penetration test at all, which is what a day rate of £250 to £500 generally buys: automated scanning inside a report wrapper. The roughly £800 to £1,200 an accredited UK provider charges buys somebody actually looking.
So the clean report is the one to be suspicious of. If you are placing tests and never seeing findings, the problem is the test, and your client is paying for reassurance rather than information.
Read it before your client does
This is the single practical habit that separates partners who handle this well from partners who do not. On a white-labelled engagement the report comes to you first, so use that. An hour with the document before you release it lets you arrive at the client conversation with a plan instead of a reaction.
Sort the findings into three groups as you read. They need different handling and lumping them together is what makes the conversation feel like an accusation.
| Kind | Example | How it gets handled |
|---|---|---|
| Things the client declined | You quoted for it, they said no, it is now in a report | Show them the quote. This is the finding doing your selling for you, and it needs no defensiveness at all. |
| Things outside your contract | Application code, a third-party platform, a system a department bought directly | State the boundary plainly and offer to coordinate. Do not absorb work you were never paid for. |
| Things that are genuinely yours | A patching gap, a leftover rule, a default left in place | Own it in one sentence, then move to the remediation plan. Length of explanation is inversely proportional to credibility here. |
Most reports on a managed estate are mostly the first two groups. The third is usually smaller than it feels at nine in the morning when you have just read it.
Say it first
The framing that works is to raise the findings yourself, in your own words, before the client reads them. Something close to: the test found seven things, here are the three that matter, two of them are items we raised with you previously and have the quotes for, one is ours and here is what we are doing about it, and here is the plan and the timescale for all of them.
That conversation lands completely differently from the same facts discovered by a client reading a PDF alone on a Friday afternoon. It is not spin. You are the only party who can put each finding in context, and context is what turns a list of defects into a piece of work.
The instinct to soften the findings, delay the release, or argue with the severities is the one to resist. Severities in an accredited report are reasoned and reviewed by a second person before delivery, so arguing them rarely goes well and always reads badly. If you genuinely disagree with a rating, say so to the provider before release, with your reasoning, and let it be corrected or defended properly.
The value of independence, stated honestly
There is a real argument here and it does not require any positioning. Your client did not commission a test to find out that their MSP is good. They commissioned it because an insurer, a customer or a tender wanted independent evidence about their security. Independent evidence that contains nothing is worthless to them, and they would be right to distrust it.
The test finding things in your estate is the mechanism working. It is also the mechanism working for you, because there is no other way to demonstrate to a client that you have been asking for the right budget. A finding from a third party with no commercial interest in the outcome carries weight that four quarterly review slides never did.
That argument only holds if you actually act on the findings, which is the next part.
The commercial conversation
Three questions come up, and having positions on them in advance is worth more than handling each one fresh.
Who pays to fix it?
If it is inside your contracted scope and it is your error, fix it and do not bill for it. The cost of that is small and the cost of arguing about it is not. If it is work the client declined, work outside the contract, or a project rather than a maintenance item, it is quoted work, and the report is your justification. Decide which category each finding is in before the call, not during it.
What if the report makes us look bad to a client we are mid-renewal with?
Then the question is whether it makes you look worse than the alternative, which is a client discovering later that you never tested. An MSP that commissions independent testing, reads it, owns what is theirs and closes it out is demonstrating something most competitors cannot. The risk case is not the report. It is a report that sits unactioned for a year and then gets read by somebody after an incident.
Should we do the remediation ourselves?
Almost always, and it is the larger half of the engagement by value. The test produces a scoped, prioritised, externally justified list of work on an estate only you know properly. We sell no managed IT, no helpdesk, no hardware, no licensing, no monitoring and no projects, so none of that work is available to us even if we wanted it.
Close it, and evidence the closure
Findings that are fixed but not retested are, to an insurer or a customer, findings that are still open. A retest producing a document that states which findings were closed and which remain is what converts remediation into evidence, and it is what the party who asked for the test in the first place actually wanted. A retest against the same scope is £500 plus VAT on our fixed-fee tests.
Put a date on every accepted risk as well as every fix. Some findings will not be closed, because the client will not fund it or a vendor has not shipped a patch. Those should be written down as decisions with a named owner and a review date, not left to drift into next year’s report as a repeat finding, which is a much worse conversation than the first one was.
The one case where you should not place the test
If you know the estate has a serious problem that you have not raised with the client, do not commission a test to break the news for you. Raise it, deal with it, and test afterwards. Using an independent report as a way of avoiding a conversation you should have had is a position that is very hard to defend if the client later asks when you first knew. Fix first, then test, and let the test confirm rather than reveal.
Should we tell the client about findings in our own work before they read the report?
Yes, and it is the single thing that most changes how this goes. You are the only party who can put each finding in context: which were previously quoted and declined, which are outside your contract, and which are genuinely yours. Arriving with that breakdown and a remediation plan is a different conversation from a client reading a PDF unaided.
Our client’s report was clean. Is that good news?
Treat it as a question rather than a result. Check the scope, check whether testing was authenticated across the user roles, and check the day count. A real estate tested properly produces findings. A clean report usually means a narrow scope, shallow testing, or a scan sold as a test, and your client is paying for reassurance rather than information.
Do we have to fix findings for free if they are in our work?
Fix your own errors inside your contracted scope without billing, because the argument costs more than the work. Everything else is quoted: work the client previously declined, items outside the contract, and anything that is a project rather than a maintenance task. Decide which category each finding is in before the call rather than negotiating it live.
Will the tester comment on the quality of our work to the client?
No. Findings are described technically, against the target, without commentary on who configured it or who should be running the client’s IT. There is no managed services business here and so no reason to position for one. What the report will not do is omit a finding because it is awkward, which is the whole point of buying an independent one.
Independent findings, your remediation
We test and retest. We do not sell managed IT, helpdesk, licensing, monitoring or projects, so every piece of work a report generates is yours. Ask us about partner terms and how the retest is scheduled.