Actually had similar experience pen-testing a large financial institution. Was plotted up in their training room and was circa late 90's and I had a boot floppy distro (TRINUX iirc) which had the tools I wanted (tcpdump, nmap...). So quickly turned a training PC into my terminal of choice and mapping the network out and came across an AS/400. Quickly dug out my notes upon such beasts and turned out that the shipping…
> We did the report and that whole aspect got swept under the carpet and I was never asked back to that clients site ever again. You should have pushed for the opposite, doing the ocassional pentest to the client for life, in exchange for being mum about it.
If you had a back bone as a consultant your period 2 report would start with “unresolved issues from last time”, so you would very quickly have to resign due to your ethical baseline not being met. Therefore same outcome.