Free Targeted Retesting

All web application and external infrastructure penetration testing engagements now include complimentary retesting to verify that identified vulnerabilities have been successfully remediated.

We’ve compiled a list of 10 frequently asked questions (FAQ) about our Complimentary Targeted Retesting enhancement to our penetration testing services.

1. What qualifies for a free retest?

Free retests are available for web application and external infrastructure penetration tests where critical or high-severity findings were identified in your original test. The retest must be requested within two calendar months of when your test report was released.

Only critical and high-severity findings are eligible for free retesting. Medium, low, and informational findings are not included; however, retesting for these can be purchased upon request.

You must request your free retest within two calendar months from the date your penetration test report was released. Requests made after this timeframe will be subject to standard retest pricing and can be requested from your Blackfoot account manager.

Complimentary retesting applies to web applications and external infrastructure that were part of your original penetration test scope. Internal infrastructure testing and other testing types follow separate retest policies.

While we recommend addressing all identified vulnerabilities, free retesting will focus specifically on verifying remediation of the critical and high-severity findings you have fixed from your original report.

Using the retest function within our Sentry platform, request a retest and one of our friendly team will reach out to schedule your retest. We will ask which of the critical and high findings you would like retested.

Full retesting involves conducting a complete new penetration test of the entire scope, while targeted retesting (which is what our free service provides) focuses specifically on verifying that previously identified critical and high-severity vulnerabilities have been properly remediated. Full retesting, which ensures new vulnerabilities have not been introduced when fixes have been applied, can also be provided subject to commercials. Please speak with your Blackfoot account manager for further information.

Retest duration depends on the number and complexity of findings being verified, but typically takes a day or two. We will provide a timeline estimate when scheduling your retest.

Yes, you will receive the outcome of the retest and the status of each critical and high finding that was retested, we will provide the results via Sentry confirming whether vulnerabilities have been successfully remediated.

This is unlikely as targeted retesting only focuses on validating fixes for previously identified critical and high findings. The discovery of new vulnerabilities will require a separate engagement to fully assess and test the in-scope environment.

Should you have any further queries, please do not hesitate to contact us.

Share this Article:

Related Articles

Business logic
Case Studies

Why Business Logic Testing Matters: Preventing Free Checkout Exploits

Business logic vulnerabilities are often overlooked yet pose serious risks to modern applications. Rather than exploiting code flaws, attackers manipulate how systems are meant to function. At Blackfoot, our consultants specialise in identifying and addressing these vulnerabilities through rigorous manual testing.

Read More

Speak to an Expert

Call us on +44 (0) 203 393 7795

We value what our customers think of us

Get The Latest Industry News

We’ll keep you informed about potential risks and vulnerabilities that could impact your digital assets.