Logo
Cybersecurity

What CISOs Should Ask Before Choosing a Penetration Testing Provider in 2026

ITSEC Asia, Indonesia's leading cybersecurity company, breaks down the questions CISOs should ask before choosing a penetration testing provider in 2026, and why the answers matter more than the price on the quote.

ITSEC AsiaITSEC Asia
|
Jul 17, 2026
What CISOs Should Ask Before Choosing a Penetration Testing Provider in 2026

Introduction

What percentage of your last penetration test report was actually proven exploitable, and what percentage was a list of things a scanner flagged and nobody validated? Most CISOs cannot answer that question with confidence, and that is exactly the problem. Buyers guides published this year point to a pattern worth sitting with. If a quoted penetration test comes in at four to five thousand dollars or less, it is very likely an automated vulnerability scan wearing a pen test label, not manual work performed by a skilled tester. That gap between what is sold as a penetration test and what is actually delivered is why the selection conversation matters so much more than most procurement teams treat it. ITSEC Asia, Indonesia's leading cybersecurity company, works with organizations across Indonesia, Singapore, Australia, and the UAE that have gone through this exact evaluation, and the questions that separate a genuinely useful engagement from an expensive checkbox exercise are more specific than most RFPs ever ask.

Source: Six Questions to Ask a Penetration Testing Vendor

The Question That Actually Separates Real Testing From a Repackaged Scan

Before a CISO asks about cost or timeline, the first question worth asking is how much of the engagement is manual testing performed by a person, and how much is automated tooling running in the background. A provider who cannot answer that specifically, or who deflects to a list of tool names instead of describing what a tester actually does with those results, is usually scanner heavy underneath a nicer report template.

  • Scanners work by matching what they see against known signatures, so they catch outdated software versions or exposed endpoints reliably, but they cannot reason through a multi-step attack path the way a human attacker would, such as testing whether one authenticated user can quietly access another user's data.

  • A serious provider should be able to describe how their testers form a hypothesis about a weakness, chain it with another finding, and then attempt controlled exploitation to confirm the risk is real rather than theoretical.

  • Asking which specific testers will be assigned to the engagement, and what certifications they individually hold rather than a generic reference to a certified team, tends to reveal a lot in a single answer.

  • A company that is ISO 27001 certified at the corporate level does not guarantee that the individual assigned to a project can find a real SQL injection or a broken access control chain, and a provider confident in its people will name them without hesitation.

The gap between a scanner flagging an anomaly and a tester actually proving it exploitable is what decides whether a pentest report is genuinely actionable, or just a checklist that looks convincing on paper.

Source: Why Automated Scanners Miss Real Vulnerabilities · Autonomous AI Agents for Penetration Testing: A Complete Guide

What a Credible Provider Should Be Able to Prove

Once methodology is settled, the conversation should move to proof rather than promises. A useful test is to request a sample report before signing anything, since the report format reveals more about testing quality than any sales call ever will.

  • A strong sample includes proof of concept evidence for every finding, screenshots showing the access that was actually achieved, and a clear narrative of how findings were chained into a realistic attack path rather than a flat list graded by a generic severity score.

  • Scoping is another area where the answers diverge sharply between serious providers and price generators; a quote produced without a short scoping call, one that asks how many applications, user roles, and APIs are actually in play, is essentially a guess.

  • A quote without proper scoping usually means either the provider is padding for unknowns, or a change request is coming midway through the engagement.

  • It is worth asking directly what happens between report delivery and retesting, since quality providers typically build in thirty to ninety days of remediation support, while a red flag looks like a report sent by email with no debrief and no path back to the tester who found the issue.

None of these questions require deep technical fluency to ask, they simply require treating the evaluation as a scorecard applied consistently across every provider on the shortlist, rather than trusting the reassurance printed on a homepage.

Source: 10 Questions to Ask Before Hiring a Penetration Testing Provider · Six Questions to Ask a Penetration Testing Vendor

Why This Decision Carries More Weight in Indonesia's Compliance Climate

For organizations operating in Indonesia, this selection process is no longer just good practice, it sits inside a tightening regulatory picture. UU PDP, the country's Personal Data Protection Law, has moved past its transition period and now carries real enforcement exposure, and its provisions expect organizations to regularly identify and remediate vulnerabilities rather than treat a security assessment as an annual formality. Sector regulators add another layer on top of that baseline, with OJK requiring scenario based cybersecurity testing at least annually for commercial banks, and expecting audit grade evidence of testing from payment system and digital financial asset providers. Indonesia's exposure is also simply larger than it used to be, with internet users climbing from roughly 221.6 million in 2024 to about 229.4 million in 2025 according to APJII, which widens the attack surface every regulator and board member is now asking questions about. Choosing a provider who can produce audit ready, timestamped documentation of what was found and what was actually fixed is quickly becoming the difference between passing a regulatory review and scrambling to explain a gap in evidence after the fact.

Source: Top Penetration Testing Companies in Indonesia 2026 · From Policy to Practice: How Indonesia's UU PDP 2022 Shapes Cybersecurity Readiness in 2025

Choose the Provider Whose Answers You Can Verify

The right penetration testing provider is not the one with the most confident sales pitch, it is the one whose claims about methodology, testers, and validation hold up when you actually check them. ITSEC Asia has spent more than a decade working alongside organizations across Indonesia, Singapore, Australia, and the UAE on exactly this kind of evaluation, and Bronyx, ITSEC Asia's AI powered continuous penetration testing platform, was built around the same principle this article keeps circling back to: findings should be validated before they are reported, not after a client asks why an incident happened despite a clean scan.

Visit bronyx.ai to see how continuous, AI-powered penetration testing works, or reach the ITSEC Asia team directly at itsec.asia/contact to talk through what a real evaluation should look like for your organization.

Share this post

You may also like

The Security Gap Indonesian Financial Institutions Can't Afford to Ignore
Cybersecurity

The Security Gap Indonesian Financial Institutions Can't Afford to Ignore

INTRODUCTION Between late 2024 and 2025, Indonesia's Financial Services Authority (OJK) and the Indonesia Anti-Scam Center (IASC) recorded approximately 274,000 fraud cases with total public losses exceeding IDR 6 trillion [https://www.itbeat.id/en/penipuan-berbasis-ai-ancam-sektor-keuangan-indonesia-ojk-catat-kerugian-rp6-triliun/]. That number does not include the operational disruption and reputational fallout from high-profile breaches like the 2024 BI-Fast cyber incident, which prompted OJK to launch emergency inspections of regional banks across the country. Indonesia's financial sector is not fighting a periodic threat. It is fighting one that operates around the clock, and treating security validation as a once-a-year checkbox is one of the most dangerous assumptions a bank or fintech company can make right now. Annual penetration tests are the industry norm, and for a long time they were considered sufficient. The logic was reasonable: test the system before it goes into production, document the findings, remediate the critical ones, and revisit in twelve months. That model made sense when environments were relatively static, when APIs were not the backbone of every product integration, and when attackers were not running automated

ITSEC AsiaITSEC Asia
|
Jun 30, 2026 7 minutes read
API Security Testing: Why APIs Have Become a Prime Target for Attackers
Cybersecurity

API Security Testing: Why APIs Have Become a Prime Target for Attackers

Modern applications rarely operate in isolation. From mobile apps and cloud platforms to payment gateways and third-party integrations, APIs (Application Programming Interfaces) have become the invisible backbone of digital services. Organizations rely on APIs to connect systems, exchange data and accelerate innovation. Unfortunately, attackers rely on them too. As API adoption continues to grow, APIs have emerged as one of the fastest-growing attack surfaces in cybersecurity. Misconfigured or vulnerable APIs can expose sensitive information, disrupt business operations and provide attackers with a direct path into critical systems. This is why API Security Testing has become an essential part of modern application security. WHAT IS API SECURITY TESTING? API Security Testing is the process of identifying and validating vulnerabilities within APIs before they can be exploited by malicious actors. Unlike traditional web application testing, API security assessments focus on how applications communicate with each other and whether those interactions can be manipulated or abused. The objective is not simply to find vulnerabilities but to understand how weaknesses within APIs could impact business operations and data security. WHY

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 5 minutes read
How AI Helps Reduce False Positives in Security Assessments
Cybersecurity

How AI Helps Reduce False Positives in Security Assessments

Modern security teams are drowning in alerts. Vulnerability scanners, SIEM platforms, threat detection tools and security assessments generate thousands of findings every day. While visibility is essential, not every finding represents a genuine threat. Many turn out to be false positives. As organizations expand their attack surfaces and adopt increasingly complex environments, managing false positives has become one of the biggest operational challenges in cybersecurity. Because ultimately, cybersecurity is not about generating more alerts. It is about identifying the risks that truly matter. WHAT ARE FALSE POSITIVES IN CYBERSECURITY? A false positive occurs when a security tool or assessment identifies something as a vulnerability or threat, even though it poses little or no actual risk. In other words, a finding appears dangerous but cannot realistically be exploited or does not have meaningful impact. False positives can originate from: * Vulnerability scanners. * Automated security assessments. * Threat detection systems. * SIEM platforms. * Security monitoring tools. * Misconfigured rules and signatures. Although these tools are designed to maximize detection, excessive false positives

ITSEC AsiaITSEC Asia
|
Jun 15, 2026 5 minutes read

Receive weekly
updates on new posts

Subscribe