Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Can a Penetration Testing Firm Show Returning Clients How Their Findings Have Changed Since Last Year?
Problems We Solve

How Can a Penetration Testing Firm Show Returning Clients How Their Findings Have Changed Since Last Year?

Returning pen test clients want to know if things improved, but each report stands alone. We build findings history for pen test firms across a client's tests.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Each year's report is written as a standalone document, so comparing it with previous tests means a tester reading old PDFs and matching findings by eye. We build a findings history per client that links each finding to its earlier appearances, shows what is new, what recurred and what was fixed, and gives testers and account leads a ready comparison for the report and the board-level summary.

The question every returning client asks

A client has tested with you three years running. Their new head of IT has joined and, before this year's test, asks a reasonable question: are we getting better? Which issues keep coming back? Is the money we spend on remediation working?

Answering it means opening three reports written by two different testers, in slightly different formats, and matching findings by reading them. Some findings were renamed between years. One was split into two. A recurring issue was rated medium one year and high the next. The tester doing it spends most of a day and produces a table they are not fully confident in.

The next client asks the same question the following week.

It is also a question you want clients to ask. A returning client's history is something no competitor can offer, and it is one of the strongest reasons for them to stay with you. At the moment, that advantage sits unused in a folder of PDFs.

Why history is hard to see

  • Each report is a standalone document, not a set of records linked over time.
  • Findings are named and rated differently between years and testers.
  • Scope changes, so a finding missing this year may be fixed or may simply be out of scope.
  • Assets change names and addresses, which makes matching harder.
  • The data sits in PDFs, or in separate projects in the reporting platform with no link between them.

What that costs you

Missing viewResult
No year-on-year comparisonClient cannot see progress
Recurring findings not flaggedSame issue reported fresh each year
Comparison built by handTester time with no fee attached
History not used in salesReturning clients treated like new ones
Board summary missingClient's leadership sees only this year's list

There is a quality point too. When a finding recurs, the client deserves to know it has come back, and the report should say so. Reporting it fresh each year, as if new, misses the most useful thing the tester could tell them.

The findings history we build

  1. Past reports are loaded, from your reporting platform where it holds them or from report exports, and each finding becomes a record with its client, asset, date, severity and your findings library reference where one applies.
  2. Findings are linked across years by library reference, asset and description. An AI model can suggest likely matches where names changed, and a tester confirms them.
  3. Scope for each year is recorded, so a finding that disappeared because it was out of scope is shown differently from one that was fixed.
  4. For each client, the history shows new, recurring and resolved findings per year, with severity trends and time to fix where retests happened.
  5. A comparison section is generated for this year's report, and a one-page summary for the client's leadership, both for a tester to review and edit.
  6. From then on, each new report adds to the history automatically.

The history uses your own findings library and severity guidelines, so comparisons are consistent even when different testers wrote the reports.

What returning clients get

A clear picture of their progress: what was fixed, what recurs, and which areas need attention. Their leadership gets a one-page summary instead of a long list. Your tester spends their time on explaining the pattern, which is valuable, rather than building the table.

For your firm, the history becomes a reason for clients to return. A new firm can test the same systems, but it cannot tell the client how things have changed since three years ago.

A typical use looks like this. Before the scoping call for a repeat test, the account lead opens the client's history and sees a recurring configuration issue on their external estate and a cluster of application findings that were fixed after the last retest. The scoping conversation starts there, and the proposal suggests where testing time is best spent this year.

Is this a question you get?

  • Returning clients ask whether they are improving.
  • Year-on-year comparisons are built by reading old PDFs.
  • Recurring findings are reported as if they were new.
  • Reports are not linked across years.
  • Clients' leadership sees only this year's findings.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Can you load our old reports?

Yes, from your reporting platform or from exports. PDFs can be read too, with a tester checking the extracted findings.

How are findings matched across years?

By library reference, asset and description, with suggested matches confirmed by a tester.

What if scope changed between years?

Scope is recorded per year, so out-of-scope and fixed are shown separately.

Does this replace our reporting platform?

No. It works alongside it, holding the history and producing the comparison.

Keep reading

More on Problems We Solve

Start here

Tell us where the admin slows your security practice down

Describe how engagements run today, from scoping call to final report and retest: the reporting tool, the calendars, the trackers and the email threads. We will tell you what we would build and what we would leave alone, and if your existing tools can already do it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →