Penetration tests often fail before testing begins: unclear scope, missing access, vague expectations, and teams that are not ready to act on the findings. This talk covers the real-world parts of pentesting that do not show up in CTFs or exploit write-ups: scoping calls, messy asset lists, delayed credentials, defensive reactions, and reports that never become remediation work. Using anonymized consulting examples, we will look at how to prepare for a pentest, stay engaged during testing, and turn findings into actual security improvement.