---
title: "How penetration testing firms can win scoped leads from AI search"
description: "By being the firm AI names when a buyer describes their audit, scope and deadline, with credentials, methods and pricing logic others can verify."
canonical: "https://underneath.agency/resources/pentest-firms-leads-ai-search"
published: 2026-10-07
updated: 2026-10-08
publisher: "Underneath (https://underneath.agency/agent)"
entity: "https://underneath.agency/.well-known/entity.json"
---
Guide · AI search

# How can a penetration testing firm win more scoped leads from AI search?

By being the firm an AI assistant names when a buyer describes their audit, their systems and their deadline, and by publishing the credentials, methods and pricing logic that let the buyer check that answer. Penetration testing is bought under pressure from auditors, customers and insurers, so most buyers arrive with a scope already in mind. The assistant can match that scope to a firm before the first call, though no study yet measures how often pentest buyers ask one.

## The short version

1. Enterprises spend real money on testing: in [Pentera’s 2025 survey](https://itbrief.co.uk/story/survey-shows-enterprises-shift-towards-software-driven-pentesting) of 500 CISOs, US enterprises spent $187,000 a year on pentesting on average, about 10.5% to 11% of a security budget averaging $1.77 million.
2. Demand is set by rules and customers: PCI DSS requires internal and external tests [“at least once every 12 months”](https://strike.sh/learn/pci-dss-penetration-testing) and after significant changes, and [Cobalt](https://securitybrief.news/story/cobalt-report-reveals-gaps-in-critical-vulnerability-fixes) found 82% of organizations must give customers or regulators software security assurance.
3. Testing lags change: [Pentera’s 2024 survey](https://msspalert.com/news/pentesting-study-exposes-security-gaps-signals-mssp-prospects) found 73% of organizations change their IT at least quarterly but only 40% pentest that often.
4. Many smaller buyers have never bought a test: only 12% of UK businesses did penetration testing in the past year, in the [UK government’s 2025 breaches survey](https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025) of 2,180 businesses.
5. The pages AI cites are not neutral: in [our study of self-ranking lists](https://underneath.agency/research/self-promoting-best-lists-study), 24.2% of 269 cited “best X” lists ranked their own publisher first, the pattern behind many “best pentest companies” pages.

## Who buys penetration testing, and what is an engagement worth?

Security leaders, compliance owners and IT managers who need independent proof, usually by a fixed date.

Four buyers account for most of the work:

- **Enterprise CISOs** running a yearly testing program across networks, applications and cloud, often with several firms.
- **Compliance owners** at payment, software and health businesses who need a test report for an audit or a customer. A dental software maker is one such business: its group practice buyers ask about security before they choose, as [what dental groups ask technology vendors](https://underneath.agency/resources/dental-technology-ai-search) shows.
- **Public sector and critical infrastructure buyers.** In the UK, the NCSC, the government’s cybersecurity agency, runs the [CHECK scheme](https://www.ncsc.gov.uk/information/check-penetration-testing), which sets the standard for “authorised penetration tests of public sector and CNI systems and networks.”
- **Small and mid-size firms** with no in-house testers. In the UK survey, small and medium businesses that ran vulnerability audits were the most likely to use outside contractors only (38% each).

Spend varies with scope. Pentera’s figure of $187,000 a year describes large US enterprises, and more than half of its CISOs planned to raise pentest budgets. Platform contracts give a second view. On [Vendr’s purchase data](https://www.vendr.com/marketplace/synack), the median Synack buyer pays $105,600 a year, in a range from $79,215 to $140,150. [HackerOne’s](https://www.vendr.com/marketplace/hackerone) median is $41,500 across 316 purchases, for a mix of testing and bug bounty programs. A boutique firm’s single web application test sits well below these figures, but the account is worth more than the first test: PCI DSS requires repeat testing to verify fixes, and the cycle repeats every year.

## Why do companies buy more testing now?

Because audits, customers and insurers ask for proof, while systems change faster than yearly tests can cover.

**Rules set a floor.** PCI DSS Requirement 11.4, as quoted by Strike, calls for testing “By a qualified internal resource or qualified external third-party” with “Organizational independence of the tester,” and it is “not required to be a QSA or ASV.” Service providers must test segmentation controls “At least once every six months.” Buyers often ask an assistant to explain exactly these points before they ask who to hire.

**Customers ask for evidence.** Cobalt’s 2025 report, built on tests across more than 2,700 organizations, found 82% are required to give customers or regulators software security assurance. A pentest report is often that evidence.

**Insurers push controls.** In Pentera’s 2025 survey, 59% of organizations had implemented at least one security solution at their insurer’s request. Training vendors answer to the same insurers, as [how security awareness training vendors win buyers](https://underneath.agency/resources/security-awareness-training-customers-ai-search) shows.

**Systems change faster than tests.** Pentera’s 2024 survey found 60% of organizations pentest twice a year at most. Cobalt found 95% had pentested AI applications in the past year, and 32% of those tests found serious flaws. New AI features are a new reason to call a tester.

**Software competes for the budget.** In Pentera’s 2025 survey, 55% of organizations use software-based pentesting platforms. Pentera sells such software, so read its survey as one input. Buyers now ask which kind of testing they need, not only which firm.

## Where does AI search sit in the pentest buying journey?

At the research and shortlisting step, after a trigger and before scoping calls, though no survey isolates pentest buyers.

The journey, as we understand it:

1. **Trigger.** An audit date, a customer security questionnaire, an insurer’s request, a major release or a breach.
2. **Learning.** What does PCI DSS 11.4 require? What is the difference between a pentest, a vulnerability scan and a red team exercise?
3. **Shortlist.** Peers, past suppliers, search results and, increasingly, an AI assistant.
4. **Scoping call and proposal.** Number of applications, IP ranges, cloud accounts and test days set the price.
5. **Test, report and retest.** Then the same decision next year, or after the next significant change.

Across B2B purchases, [Gartner’s 2026 survey](https://www.gartner.com/en/newsroom/press-releases/2026-05-20-gartner-survey-finds-sixty-nine-percent-of-b-two-b-buyers-turn-to-sales-reps-to-validate-ai-generated-insights) of 645 buyers found 45% used generative AI in a recent purchase, mainly to gather information on vendors and products. For a pentest, we infer that much of this happens at steps 2 and 3, where an assistant can both explain a requirement and name firms that meet it.

## Which questions do pentest buyers ask AI assistants?

Questions about requirements, scope, credentials, price and test type. We drafted the sample prompts below in the voice of a CISO or compliance lead; they are examples, not logged queries.

| Buyer | Illustrative prompt |
|---|---|
| Payment business | “Penetration testing firm for PCI DSS 11.4 that can also test our segmentation every six months?” |
| UK public sector | “Which CHECK-approved companies test for NHS trusts?” |
| Software company | “Pentest firm that gives a report we can share with enterprise customers before a sale?” |
| Mid-size firm, first test | “How much does an external network penetration test cost for 50 IP addresses?” |
| AI product team | “Who tests AI chat features for prompt injection and data leaks?” |
| Enterprise CISO | “Manual pentest firm, PTaaS platform or automated validation: which fits a quarterly release cycle?” |
| Regional buyer | “Penetration testing companies in Texas with OSCP-certified testers?” |

The way the question is framed changes the answer. In [our phrasing study](https://underneath.agency/research/ai-prompt-phrasing-study), adding “on a tight budget” kept the original first brand only 15.3% of the time, against 68.0% when the same question was asked again. Price-conscious buyers may see a different set of firms, we infer.

## How does AI visibility become a scoped pentest lead?

When the assistant has matched your firm to the buyer’s standard, systems and deadline, the first call starts at scoping.

A good pentest lead has four facts settled: what must be tested, which requirement drives it, when the report is due and who will accept it (an auditor, a customer, an insurer). A buyer who asked for a firm that handles PCI DSS segmentation testing and AI application testing has already filtered on two of them. The likely path:

1. **AI answer.** A short list of firms, with reasons drawn from their pages and from what others write about them.
2. **Checking.** The buyer reads the firm’s methodology, sample report, tester credentials and reviews.
3. **Scoping call.** The buyer arrives with systems listed and a date in mind.
4. **Statement of work.** Test days, retest and reporting format are priced.
5. **Renewal and expansion.** Yearly retests, extra applications, segmentation tests and new AI features.

The reverse also holds. If an assistant describes your firm as network-only when you test cloud and AI applications, it filters out buyers who would have fit. Most of this happens without a click you can see in analytics; see [what lost clicks mean for pipeline](https://underneath.agency/resources/ai-answers-pipeline-revenue).

## What decides whether an assistant names a penetration testing firm?

No platform documents how it chooses security firms; studies show assistants look for rankings, reviews and prices.

**Documented by the platforms.** Google says AI Overviews and AI Mode [may use a “query fan-out” technique](https://developers.google.com/search/docs/appearance/ai-features), issuing several related searches for one question. Neither Google nor any other platform explains how a pentest firm ends up named.

**Observed in our studies.** In [our hidden-searches study](https://underneath.agency/research/ai-hidden-searches-study), ChatGPT ran a search aimed at a named publication, ranking or award in 43.8% of its answers, looked for reviews in 46.2% and looked for prices in 23.8%. Lists matter, and many “best penetration testing companies” pages are written by firms that rank themselves first. Our self-ranking study found 24.2% of cited numbered lists did that, though such lists were only 1.1% of all citations. And names move between runs: in [our consistency study](https://underneath.agency/research/ai-recommendation-consistency-study), only 25.2% of the brands ChatGPT named appeared in all five runs of the same question.

**What pentest buyers check.** The NCSC’s [penetration testing guidance](https://www.ncsc.gov.uk/guidance/penetration-testing) says third-party tests “should be performed by qualified and experienced staff only” and that “the quality of a penetration test is closely linked to the abilities of the penetration testers involved.” Buyers therefore look for named schemes (CHECK, CREST), individual certifications, a clear methodology and evidence of research.

**Our inference.** A reasonable expectation is that a firm whose accreditations, methods, sample deliverables and retest policy are stated plainly, and confirmed by independent sources, gives an assistant more to repeat accurately. No study has tested this for testing firms.

## What does it cost a pentest firm to be left out?

Mostly lost scoping calls on recurring work, though no study has measured that loss for testing firms.

- **The work recurs.** A buyer lost at the first test is often lost for the yearly retest, the post-change test and the next application too.
- **The market is shifting.** With 55% of large organizations using software-based testing, a consultancy missing from “which kind of testing do I need?” answers loses the argument before the comparison starts, we infer.
- **Resellers compete for the same buyer.** [MSSP Alert](https://msspalert.com/news/pentesting-study-exposes-security-gaps-signals-mssp-prospects) reports that 63% of managed security providers already offer their own pen testing as a service.
- **Wrong facts filter buyers out.** An assistant that omits your CHECK status or says you do not test AI applications sends those buyers elsewhere. The steps for correcting it are in [our guide to fixing wrong brand information in AI answers](https://underneath.agency/resources/fix-wrong-brand-information-in-ai-answers).

## How does GEO work for a penetration testing firm?

It makes your scope, credentials and proof easy for assistants and buyers to find and check. Nobody can promise a recommendation.

1. **Map your services to the requirements buyers name.** One clear page each for PCI DSS 11.4 testing (including segmentation), customer-assurance reports, CHECK or CREST work, cloud, and AI application testing.
2. **Explain how scope sets price.** Assistants answer pricing questions, and ChatGPT searched for prices in 23.8% of answers in our study. State what drives cost, even without a rate card.
3. **Show who tests.** Tester certifications, scheme memberships, years of experience and published research.
4. **Publish a sample report and retest policy.** These answer the questions compliance owners ask before a call.
5. **Earn independent coverage.** Vulnerability disclosures, conference talks, security press and analyst mentions carry more weight than your own list of top firms; see [how brands build authority for AI search](https://underneath.agency/resources/how-brands-build-authority-for-ai-search) and [which pages AI engines cite](https://underneath.agency/resources/best-of-lists-ai-recommendations).
6. **Keep reviews current** on the platforms buyers read. When [our reputation study](https://underneath.agency/research/is-it-legit-ai-reputation-study) asked assistants whether brands were legit, 88.0% of the answers cited a review or complaint platform.
7. **Measure with real buyer wording.** Test requirement, region, budget and test-type prompts across ChatGPT, Google AI Overviews and AI Mode, Gemini, Perplexity, Copilot and Claude, several runs each.

## What is still unproven about how pentest buyers use AI?

How many pentest buyers use AI assistants, and whether being named leads to signed statements of work. No published study answers either.

- **No survey of pentest buyers.** Gartner’s figures cover B2B purchases across industries.
- **Vendors fund much of the data.** Pentera and Cobalt sell testing; their surveys show the market’s direction, not neutral measurement.
- **Vendr is a sample.** Its medians reflect purchases on one platform, mostly for platforms rather than boutique consultancies.
- **Lead quality is unmeasured.** In [Martinez’s](https://arxiv.org/abs/2607.14035) review of research on AI search optimization, traffic and conversions had the weakest evidence.

## Where should a penetration testing firm start?

With the 20 to 30 questions your best-fit buyers ask before they call, and a record of who gets named.

Write prompts for each buyer type: PCI, customer assurance, public sector, AI applications, first-time buyers, with region and budget wording. Ask each major assistant several times. Note which firms are named, which lists and review sites are cited, and whether your credentials and services are described correctly. Firms that also sell security products can compare notes with [how cybersecurity software companies earn revenue from AI search](https://underneath.agency/resources/cybersecurity-software-revenue-from-ai-search) and [how MDR providers win leads](https://underneath.agency/resources/mdr-providers-qualified-leads-ai-search).

To see how your firm looks from the buyer’s side, [talk to our team](https://underneath.agency/contact). We will show which scoping-stage questions name your firm, which send buyers to competitors and platforms, and which gaps in your public proof are most likely costing you scoping calls and statements of work. Our [generative engine optimization service](https://underneath.agency/services/generative-engine-optimization) page sets out how we help testing firms publish requirement-mapped services, tester credentials and sample reports, then track the scoping questions over time.

## Frequently asked questions

### Does a pentest firm need to be a PCI QSA to do PCI DSS testing?

No. PCI DSS 11.4 asks for a qualified, organizationally independent tester, “not required to be a QSA or ASV.” Saying so plainly helps buyers and assistants.

### Should we publish penetration testing prices?

Explain what drives the price, at least. ChatGPT looked for prices in 23.8% of answers in our hidden-searches study, so price-free pages leave the answer to others.

### Do “best pentest companies” lists help AI visibility?

Independent ones may. Self-published lists are common: 24.2% of cited numbered lists in our study ranked their own publisher first.

### Is automated pentesting replacing consultancies?

Not replacing, but competing: 55% of large organizations in Pentera’s 2025 survey use software-based pentesting, often alongside manual testing.

### How often do companies run penetration tests?

Often less than they change their systems. In Pentera’s 2024 survey, 60% pentested twice a year at most.

## Sources

- Pentera, via IT Brief UK (2025-05-08), [Survey shows enterprises shift towards software-driven pentesting](https://itbrief.co.uk/story/survey-shows-enterprises-shift-towards-software-driven-pentesting)
- Pentera, via MSSP Alert (2024-04-22), [Pentesting infrequency leaves security gaps](https://msspalert.com/news/pentesting-study-exposes-security-gaps-signals-mssp-prospects)
- Cobalt, via SecurityBrief US (2025-04-17), [Cobalt report reveals gaps in critical vulnerability fixes](https://securitybrief.news/story/cobalt-report-reveals-gaps-in-critical-vulnerability-fixes)
- Strike (2026), [PCI DSS penetration testing: what Requirement 11.4 asks for](https://strike.sh/learn/pci-dss-penetration-testing)
- UK Department for Science, Innovation and Technology (2025-04-09), [Cyber security breaches survey 2025](https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025)
- UK NCSC, [CHECK penetration testing](https://www.ncsc.gov.uk/information/check-penetration-testing)
- UK NCSC, [Penetration testing](https://www.ncsc.gov.uk/guidance/penetration-testing)
- Vendr (2026), [Synack software pricing and plans](https://www.vendr.com/marketplace/synack)
- Vendr (2026), [HackerOne software pricing and plans](https://www.vendr.com/marketplace/hackerone)
- Gartner (2026-05-20), [Gartner survey finds 69% of B2B buyers turn to sales reps to validate AI-generated insights](https://www.gartner.com/en/newsroom/press-releases/2026-05-20-gartner-survey-finds-sixty-nine-percent-of-b-two-b-buyers-turn-to-sales-reps-to-validate-ai-generated-insights)
- Google Search Central (2025), [AI features and your website](https://developers.google.com/search/docs/appearance/ai-features)
- Martinez (2026), [Optimizing Visibility in Generative Engines: A Critical Survey of Generative Engine Optimization (2023-2026)](https://arxiv.org/abs/2607.14035), arXiv:2607.14035.
- Underneath (2026), [How many “best of” lists cited by AI rank their own brand first?](https://underneath.agency/research/self-promoting-best-lists-study)
- Underneath (2026), [The hidden searches AI assistants run before they answer](https://underneath.agency/research/ai-hidden-searches-study)
- Underneath (2026), [Does rewording a question change AI brand recommendations?](https://underneath.agency/research/ai-prompt-phrasing-study)
- Underneath (2026), [Ask an AI the same question 5 times: do the brands change?](https://underneath.agency/research/ai-recommendation-consistency-study)
- Underneath (2026), [“Is this brand legit?” How AI assistants build a reputation](https://underneath.agency/research/is-it-legit-ai-reputation-study)

---

This is the Markdown twin of https://underneath.agency/resources/pentest-firms-leads-ai-search. The HTML page is canonical. Publisher: Underneath, https://underneath.agency/agent. Site index: https://underneath.agency/llms.txt.
