September 2026 Midwest Cyber Security Alliance Meeting | The Pentest Report Looks Clean. What’s Hiding in the Details?
The penetration test (pentest) is recent. The audit team was satisfied. The high findings were remediated. Maybe you’re reviewing it as part of an acquisition, the CISO is presenting it as the organization is secure, or you’re using it as evidence as part of a controls assessment.
How much confidence should that report give you?
Get the answer at the next Midwest Cyber Security Alliance meeting on Monday, September 14, where sponsor Final Frontier Security and its panel will walk through a merger & acquisition (M&A) scenario, where a buyer has to decide what the target company’s pentest and other technical evidence really tell them, what they don’t, and when the buyer needs to test for itself.
Not every pentest is designed to answer the same question:
- Scope may have been narrowed to control cost, meet a compliance requirement, or avoid testing systems the organization wasn’t prepared to remediate.
- The scope may leave out exactly the systems that matter most. A clean network pentest says very little about applications, cloud networks, or how much critical data and processes are in SaaS platforms.
- The engagement may rely heavily on scanning tools, AI automation, or junior testers, all of which tend to find individual vulnerabilities but miss the deeper problems when a real attacker starts chaining weaknesses together.
Drawing on collective experience building and leading pentesting teams, testing Fortune 100 environments, and going through acquisitions from the buyer’s perspective, panelists will analyze the evidence provided in the scenario to determine what to trust, what to question, and what warrants deeper testing.
Questions explored during the discussion will include:
- The target hands you a clean pentest. How much should you trust it? What can the scope, methodology, tester experience, automation, and depth of testing tell you about the confidence that report deserves?
- What important risks might never have been tested? Was this just a network pentest? What about applications and APIs, cloud environments, mobile applications, or other places a real attacker could reach?
- The high findings were remediated. Are you done? Was the underlying risk fixed, mitigated with a compensating control, or simply accepted? And what can a retest prove if fixing the first vulnerability prevents the rest of an attack chain from being tested again?
- When does the buyer need its own evidence? If the existing penetration test doesn’t answer the questions that matter, what additional evidence is needed, what should be tested, and how deeply should the buyer test before becoming comfortable with the risk?
Please join us at Foley & Lardner’s Milwaukee office on September 14. While there is no cost to attend, advance registration is required. To register, click the “Register Now” button.
Presenters:
- Andre Robitaille,VP of Strategy, Final Frontier Security
- Michael Butler,Founder & Senior Penetration Tester, Final Frontier Security
- Jon Allan, Director, IT Security, TTM Technologies
- Jennifer Urban, CIPP/US, Partner, Foley & Lardner LLP
Continuing Privacy Education (CPE)
This program may be eligible for continuing privacy education (CPE) credit toward CISA, CISM, CGEIT, and/or CRISC certifications and maintenance. Please visit the ISACA website to review the specific CPE requirements for your certification and verify whether the topic(s) addressed in this program align with one or more of your certification’s job practice areas: CISA, CISM, CGEIT, and CRISC. An ISACA Verification of Attendance form will be made available for self-reporting purposes.