Scoping a pentest without wasting money
Narrow the crown jewels. Write rules of engagement. Budget the retest. Everything else is theatre.
ITSIGN Administrator · February 12, 2025 · 2 min read
List the systems that would stop invoicing, payroll, or production. Those are in. The old wiki nobody uses is out.
Write what testers may not do: denial of service, touching a live PLC without a window, phishing staff if HR has not signed off.
Price signals
If the quote is far below the others, read the exclusions. If there is no retest, add one. If the tester will not name who holds the keyboard, walk away.
We scope penetration testing on a call, not a form.
Related reading
When a pentest is really for the insurance form
Be honest about the audience. Then still do the work so the form is not the only thing you get.
2 min read
Why the retest is the part you should not skip
A finding list without a retest is homework you never marked. Insurers and customers notice.
2 min read
Pentest vs vulnerability scan: stop mixing them up
Scans are continuous. Pentests are point-in-time and manual. You need both, and they answer different questions.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
