July 29, 2026
Finding Vulnerabilities Is Easy. Reporting Them Well Is the Real Skill.
One of the biggest misconceptions about cybersecurity is that finding vulnerabilities is the hard part.

By Jevon Davis
2 min read
It certainly requires technical skill, persistence, and experience. But after years of working in offensive security, I've come to believe that discovering a vulnerability is only the beginning.
The real challenge starts when it's time to explain it.
A security assessment isn't judged by the number of findings it uncovers. It's judged by whether the organization understands the risk well enough to make better decisions.
That's a very different skill.
A Finding Isn't the Finish Line
I've seen penetration tests end with dozens of findings and little meaningful change.
I've also seen assessments with only a handful of issues lead to significant improvements because the risks were communicated clearly, understood by stakeholders, and acted upon.
The difference wasn't technical ability.
It was communication.
Too often, we treat the report as the final deliverable.
In reality, the report is simply the bridge between technical discovery and business decision-making.
If that bridge isn't built well, even the best technical work loses much of its value.
Every Finding Deserves Evidence
One lesson I've learned over the years is that confidence should come from evidence, not conviction.
As security professionals, it's easy to become attached to our conclusions. We've invested hours investigating an issue, validating attack paths, and understanding the environment.
But a good report shouldn't ask the reader to trust the assessor.
It should allow the evidence to speak for itself.
Clear screenshots.
Reproducible steps.
Accurate descriptions.
Business context.
When those pieces are present, conversations become more productive because the discussion shifts away from opinions and toward facts.
Not Everything Needs to Be Critical
This is probably one of the most important lessons I've learned.
Severity isn't a competition.
Inflating risk doesn't make a report stronger.
It weakens credibility.
Organizations rely on security professionals to provide objective assessments, not alarming headlines. Every vulnerability should be assessed on its own merits, taking into account exploitability, business impact, existing controls, and the environment in which it exists.
Sometimes a finding is Critical. Other times, it's Medium.
A well-supported Medium finding is more valuable than an overstated Critical one.
Recommendations Should Solve Problems
I've read recommendations that were technically correct but practically impossible.
Telling an organization to redesign its entire infrastructure may be valid in theory, but it isn't always useful.
Good recommendations acknowledge reality.
They provide achievable next steps while still moving the organization toward a stronger security posture.
Security should enable progress, not simply describe perfection.
Expect Your Findings to Be Challenged
One of the healthiest parts of any assessment is the discussion that follows.
Clients ask questions.
Engineers provide additional context.
Architects explain design decisions.
Sometimes new information changes the understanding of a finding.
That isn't a failure of the assessment.
It's part of the process.
As security professionals, we should be prepared to explain our reasoning, defend our conclusions with evidence, and remain open to information that improves the accuracy of the final report.
The goal has never been to "win" an argument.
The goal is to ensure the organization understands its risk as accurately as possible.
Our Responsibility Extends Beyond Discovery
Finding vulnerabilities demonstrates technical competence.
Reporting them fairly, accurately, and in a way that enables better decisions demonstrates professional maturity.
Organizations don't benefit from the longest reports.
They benefit from reports they can trust.
Reports that distinguish between high risk and high noise.
Reports that are technically rigorous without becoming sensational.
Reports that encourage action rather than simply documenting problems.
In the end, our responsibility isn't just to identify weaknesses.
It's to communicate them in a way that helps organizations become stronger.
Because finding vulnerabilities is only half the job.
Reporting them well is the real skill.