Earlier quoted context omitted.
> The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. As much as I admire people who show the courtesy to the trash bin that will eat their report, before any human reading it, of not feeding it "bad" reports: The OPs point of "sense of false security" unfortunately already sets in once someone is hired t…
One of the most important aspects of a long report is the prioritization of the contents.
I personally organized my report into three sections, which seemed to work well. Clients seemed to enjoy the formatting:
1. Executive - Summarize everything in one page at a high level. You could skim it fast if you chose to. Highlight potential negative business impact of each finding.
2. Management - A little more detailed. 2-3 pages max. Most severe findings at the top and recommended action for remediation.
3. Narrative - This is the bulk 80-90% of the report detailing your step by step process including screenshots so that if someone wanted to duplicate your findings they could.