This document discusses the differences between penetration testing and vulnerability assessments, and identifies issues with how both clients and consultants typically approach penetration testing. It notes that penetration tests are meant to be deeply interactive and aim to achieve specific goals by exploiting vulnerabilities, while vulnerability assessments only identify issues without attempting exploitation. Both clients and consultants are seen as contributing to unsatisfactory penetration tests when clients lack understanding of the purpose and proper scope of tests, and when consultants perform superficial assessments rather than fully interactive tests. The document provides recommendations for improving penetration testing quality, such as clarifying objectives, evaluating consultant qualifications, and considering alternative payment models.