what if you find nothing?
you get the report saying so, with the scope and methods documented, which is exactly what you hand a client or insurer who asked. it happens, and it's a good outcome, not a wasted fee.
a clean report still has plenty in it. it documents what was in scope, which areas were tested and how, what the tester tried against each of them, and the date. that's a different document from "we ran a scanner and it came back green", and anyone who reads these for a living can tell the two apart.
what you can do with it
- answer the questionnaire row. "date of last penetration test" and "attach the report" are the two lines a client security questionnaire always has. a clean report with the scope documented answers both.
- satisfy the insurer. insurers ask the same question, and a report with the methods named is what they're looking for.
- set the baseline. next year's test, or the one after your next big release, has something to compare against.
when it happens
it's more likely on a retest, or on a system built with the pre-launch checklist already worked through, than on a first look at something nobody has tested. when it does happen, the money you spent building things properly did what it was supposed to, and now you have a document that says so.
what we won't do is pad the report with low-severity noise to make the fee feel earned. if the finding is that your version headers are exposed, it's in there as a low, with the ten-minute fix, and nothing more.