Penetration testing is a purchase built on trust: you are inviting someone to attack your systems and then handing them the results. A handful of direct questions reliably separates the professionals from the rest.
Why it matters
Providers differ widely in depth and approach, and a procurement that compares on price alone can miss what matters most: how thoroughly the work is done and how clearly it is reported. The questions below let you compare on substance.
The questions worth asking
- Ask who will personally do the testing and which certifications those consultants hold
- Ask how findings are validated and evidenced, and request a sanitised sample report before committing
- Check the scope document is specific: named systems, defined rules, a written methodology
- Confirm every finding comes with evidence and a concrete fix, not just a severity rating
- Confirm how your data and report are protected, stored and eventually destroyed
- Check insurance, and for government work, that personnel clearances suit the environment
Where the work is done
For New Zealand and Australian organisations, and especially in public sector procurement, where testing is performed and where your data sits both matter. Ask whether the work is done locally, by whom, and under which agreements. A good provider answers each of these without hesitation.
Intelligence Group tests networks, applications, wireless and people across New Zealand and Australia, evidences every finding and retests once you have fixed it. See what we test or request a quote.

