Skip to content
Knowledge base Updated: February 5, 2026

Communication During Penetration Tests: How to Collaborate with Clients

Even the best pentest can be wasted by poor communication. Learn how to build an effective collaboration model, when and what to report, and how to manage expectations.

Penetration testing isn’t just about technical hacking skills. It’s also a project requiring collaboration between pentester and client. Poor communication can ruin the value of even the best tests – results won’t be understood, remediation delayed, and business relationships damaged.

Communication Phases in a Pentest Project

Phase 1: Pre-engagement

Communication goals:

  • Agree on scope and expectations
  • Identify stakeholders
  • Establish communication channels
  • Define escalation procedures

Key agreements:

  1. Main point of contact

    • Who on the client side is responsible for the project?
    • How do we communicate (email, Slack, phone)?
    • What are availability hours?
  2. Technical contact

    • Who can answer technical questions?
    • Who can provide access, credentials?
    • Who monitors systems during testing?
  3. Escalation

    • Who do we call for critical vulnerabilities?
    • Who makes decisions about stopping tests?
    • How do we contact outside business hours?

Documents to agree:

  • Scope of Work (SOW)
  • Rules of Engagement (ROE)
  • NDA
  • Testing authorization

Phase 2: Kick-off Meeting

Participants:

  • Pentester(s)
  • Client project manager
  • Technical team
  • Optionally: CISO, security team

Agenda:

  1. Team introduction (5 min)

    • Who will be testing
    • Who is backup contact
  2. Scope confirmation (15 min)

    • SOW review
    • Clarify questions
    • Final confirmation of in-scope/out-of-scope
  3. Technical matters (20 min)

    • Access and credentials
    • Test environment vs production
    • Known limitations
    • Client-side monitoring and alerting
  4. Communication and schedule (10 min)

    • Communication channels
    • Status update frequency
    • Key milestones
    • Escalation procedure
  5. Q&A (10 min)

Kick-off output:

  • Confirmed scope
  • List of access to obtain
  • Testing schedule
  • Contact list

Phase 3: During Testing

Regular status updates:

For typical project (1-2 weeks):

  • Daily – brief update: “Testing module X, no critical findings”
  • Midpoint – first half summary, preliminary findings
  • End of testing – notification of active testing completion

Daily update format:

Subject: [Project X] Status Day 2

Good morning,

STATUS: Testing in progress per plan

TESTED TODAY:
- Authorization module
- API endpoints /users/*

FINDINGS (preliminary):
- 1 x Medium: Missing rate limiting on /login
- 2 x Low: Information disclosure in error messages

BLOCKERS: None

PLAN FOR TOMORROW:
- Payments module
- API endpoints /payments/*

Available for questions.

Best regards,
[Pentester]

Critical findings escalation:

When to escalate immediately:

  • Vulnerability actively exploited (compromise evidence)
  • Critical vulnerability enabling full takeover
  • Production data leak
  • Issue affecting production availability

How to escalate:

  1. Phone call – don’t wait for email response
  2. Clear message – “I found a critical vulnerability requiring immediate attention”
  3. Context – what it is, what impact, how urgent
  4. Recommendation – what to do now (disable, patch, monitor)
  5. Documentation – follow-up email with details

Managing blockers:

Typical blockers:

  • No access to environment
  • Credentials don’t work
  • Environment unavailable
  • Firewall blocking tests

Response:

  1. Immediately inform client
  2. Document downtime
  3. Propose solutions
  4. Set new schedule if needed

Phase 4: Reporting

Before delivering report:

  • Heads-up on main findings
  • Agree on presentation date
  • Set presentation participants

Draft vs final report:

  • Draft allows feedback and corrections
  • Time for client fact verification
  • Opportunity to add business context

Results presentation:

For management (Executive Briefing):

  • 30-45 minutes
  • Focus on risk and impact
  • Business language, not technical
  • Strategic recommendations
  • Q&A

For technical team (Technical Debrief):

  • 1-2 hours
  • Details of each vulnerability
  • Exploitation demo (if safe)
  • Remediation discussion
  • Technical Q&A

Phase 5: Post-engagement

Follow-up support:

  • Availability for questions (typically 2-4 weeks)
  • Report clarifications
  • Remediation planning support
  • Retest planning

Feedback:

  • Satisfaction survey
  • Lessons learned
  • Future proposals

📚 Read the complete guide: IAM / Zero Trust: Zarządzanie tożsamością i dostępem - od podstaw do Zero Trust

Common Communication Problems

Problem 1: Radio Silence

Symptom: Pentester disappears for a week, client doesn’t know what’s happening.

Solution:

  • Establish communication rhythm at kick-off
  • Daily/weekly updates even if “nothing is happening”
  • Proactive progress information

Problem 2: Information Overload

Symptom: Dozens of emails daily, client overwhelmed.

Solution:

  • Aggregate information in regular updates
  • Escalate only critical issues separately
  • Use clear subject lines with category

Problem 3: Lost in Translation

Symptom: Technical findings incomprehensible to business.

Solution:

  • Two communication levels: technical + executive
  • Business impact for each vulnerability
  • Analogies and examples from business world

Problem 4: Scope Disputes

Symptom: “That was supposed to be in scope” / “That wasn’t agreed”

Solution:

  • Precise SOW before starting
  • Document all changes
  • Confirm agreements by email

Problem 5: Finding Surprises

Symptom: Client learns about critical vulnerability from final report.

Solution:

  • Immediate escalation of critical findings
  • Midpoint summary with preliminary results
  • Pre-report heads-up

Communication Best Practices

For Pentesters

  1. Be proactive – don’t wait for questions
  2. Document everything – “what’s not recorded doesn’t exist”
  3. Adjust language – different for technicians, different for management
  4. Manage expectations – don’t promise more than you’ll deliver
  5. Be responsive – respond in reasonable time

For Clients

  1. Designate SPOC – one main point of contact
  2. Be available – pentester needs quick answers
  3. Prepare the team – SOC/IT must know about tests
  4. Give feedback – if something doesn’t work, say so
  5. Engage – it’s your security

Communication Templates

Template: Testing Start

Subject: [Project X] Penetration Testing Commencement

Team,

I'm informing about the start of penetration testing as agreed.

TEST PERIOD: [start date] - [end date]
SCOPE: [brief scope description]
CONTACT: [email] / [phone]

Please:
- Confirm test environment activity
- Inform about planned infrastructure changes
- Report security alerts related to testing

Contact me with questions or incidents.

Best regards,
[Pentester]

Template: Critical Escalation

Subject: [URGENT] [Project X] Critical vulnerability requires immediate attention

[Name],

During testing I identified a CRITICAL vulnerability requiring
immediate attention.

VULNERABILITY: [name/type]
IMPACT: [brief impact description]
PRIORITY: Immediate

RECOMMENDED ACTION:
[What to do now]

Please contact me by phone within 1 hour.
My number: [phone]

Detailed description attached.

[Pentester]

Template: Testing Completion

Subject: [Project X] Testing Phase Completion

Team,

I'm informing about completion of the active penetration testing phase.

SUMMARY:
- Test period: [dates]
- Status: Completed per plan
- Preliminary findings count: [X Critical, Y High, Z Medium, W Low]

NEXT STEPS:
1. Report preparation: by [date]
2. Results presentation: [proposed dates]
3. Final report: by [date]

Detailed findings will be presented in the report.
Critical vulnerabilities have already been communicated.

Available for questions.

Best regards,
[Pentester]

Summary

Communication isn’t an add-on to penetration testing – it’s an integral part. Key principles:

  1. Establish rules at the beginning – kick-off is the foundation
  2. Be regular – predictability builds trust
  3. Escalate quickly – critical issues don’t wait
  4. Adjust the message – different recipients, different language
  5. Document everything – in case of disputes

A well-communicated project means satisfied clients, effective remediation, and long-term business relationships.


Looking for a penetration testing partner that values communication? Contact us – transparency is our standard.

Learn key terms related to this article in our cybersecurity glossary:


Learn More

Explore related articles in our knowledge base:


Explore Our Services

Need cybersecurity support? Check out:

Explore Our Products

Solutions mentioned in this article that can help protect your organization:

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist