The question every returning client asks
A client has tested with you three years running. Their new head of IT has joined and, before this year's test, asks a reasonable question: are we getting better? Which issues keep coming back? Is the money we spend on remediation working?
Answering it means opening three reports written by two different testers, in slightly different formats, and matching findings by reading them. Some findings were renamed between years. One was split into two. A recurring issue was rated medium one year and high the next. The tester doing it spends most of a day and produces a table they are not fully confident in.
The next client asks the same question the following week.
It is also a question you want clients to ask. A returning client's history is something no competitor can offer, and it is one of the strongest reasons for them to stay with you. At the moment, that advantage sits unused in a folder of PDFs.
Why history is hard to see
- Each report is a standalone document, not a set of records linked over time.
- Findings are named and rated differently between years and testers.
- Scope changes, so a finding missing this year may be fixed or may simply be out of scope.
- Assets change names and addresses, which makes matching harder.
- The data sits in PDFs, or in separate projects in the reporting platform with no link between them.
What that costs you
| Missing view | Result |
|---|---|
| No year-on-year comparison | Client cannot see progress |
| Recurring findings not flagged | Same issue reported fresh each year |
| Comparison built by hand | Tester time with no fee attached |
| History not used in sales | Returning clients treated like new ones |
| Board summary missing | Client's leadership sees only this year's list |
There is a quality point too. When a finding recurs, the client deserves to know it has come back, and the report should say so. Reporting it fresh each year, as if new, misses the most useful thing the tester could tell them.
The findings history we build
- Past reports are loaded, from your reporting platform where it holds them or from report exports, and each finding becomes a record with its client, asset, date, severity and your findings library reference where one applies.
- Findings are linked across years by library reference, asset and description. An AI model can suggest likely matches where names changed, and a tester confirms them.
- Scope for each year is recorded, so a finding that disappeared because it was out of scope is shown differently from one that was fixed.
- For each client, the history shows new, recurring and resolved findings per year, with severity trends and time to fix where retests happened.
- A comparison section is generated for this year's report, and a one-page summary for the client's leadership, both for a tester to review and edit.
- From then on, each new report adds to the history automatically.
The history uses your own findings library and severity guidelines, so comparisons are consistent even when different testers wrote the reports.
What returning clients get
A clear picture of their progress: what was fixed, what recurs, and which areas need attention. Their leadership gets a one-page summary instead of a long list. Your tester spends their time on explaining the pattern, which is valuable, rather than building the table.
For your firm, the history becomes a reason for clients to return. A new firm can test the same systems, but it cannot tell the client how things have changed since three years ago.
A typical use looks like this. Before the scoping call for a repeat test, the account lead opens the client's history and sees a recurring configuration issue on their external estate and a cluster of application findings that were fixed after the last retest. The scoping conversation starts there, and the proposal suggests where testing time is best spent this year.
Is this a question you get?
- Returning clients ask whether they are improving.
- Year-on-year comparisons are built by reading old PDFs.
- Recurring findings are reported as if they were new.
- Reports are not linked across years.
- Clients' leadership sees only this year's findings.