The people that sign off on the training first have to believe that a pen test will provide value to your organization. They need to learn that a trusted person finding an issue is way better than a bad guy. Once they realize that a pen test can help secure your organization you are only a small hop away from convincing them that training you is cheaper than spending all the money on someone else (of course a 3rd party look from a seasoned veteran is never bad).
Here is a good post on the value of a pen test and how to answer those tough questions.
http://howisthatassuranceevidence.blogs ... at-is.html