Web application penetration testing is deep, complex, and always changing. On the other hand, it is also essential and of high value to all businesses deploying web applications these days (that is, all businesses). It is for these reasons that we must be ready to help our customers tackle their application's security and avoid becoming front-page news. Remember, we're not only testing the platform, but we are often clients of other applications, and I would hope that the web applications I am using are being tested rigorously and that the findings are being treated with proper care.
In this chapter, we took a step back from the testing itself and discussed how we can present the findings to move our customers one step closer to that most noble of goals, being secure. We saw how not only our reports and communications can help, but the establishment of a security...