At cons and on twitter, I hear about bad "pentests" all the time. This talk will be about going above and beyond on a vulnerability assessment. From VA to fixing what you know, and perfecting your org, so that when a real pentester comes, you can gain max profit.