Free guide

How to buy a penetration test without getting sold a scan.

A practical guide to scoping, comparing and commissioning security testing — written for the person who has to defend the budget, not for other security people.

Most buyers are comparing quotes that are not comparable.

Two proposals arrive. One is a third of the price. Nothing in either document tells you whether they cover the same work, because the terms are used loosely across the industry and almost nobody defines them in writing. "Penetration test" is used to describe everything from a fully manual engagement to an automated scan with a logo on the front.

This guide exists to close that gap. It sets out what actually drives cost, which questions expose a scan being sold as a test, and how to write a scope that gets you comparable numbers from every firm you approach — including firms that are not us.

What's inside

Six sections, no filler

01

Know what you're actually buying

The difference between a vulnerability scan, an automated pentest and a manual engagement — and how to tell which one a proposal is describing, regardless of what it's called.

02

Define scope before you ask for pricing

What a tester needs to know to quote accurately: application count, user roles, API surface, IP ranges, environments and testing model. Vague scope produces vague numbers.

03

Understand what drives the price

Why tester-days, not features, determine cost — and which scoping decisions genuinely move the number versus which ones just make the proposal longer.

04

Questions that separate real testing from theatre

A short list to put to any vendor, including the ones whose answers are hard to fake: who tests, what proportion is manual, what happens when they find something critical mid-engagement.

05

Read the report before you buy it

What a good report contains, why a sample matters more than a brochure, and the warning signs of output generated by a tool rather than written by an operator.

06

Plan what happens after

Re-testing, remediation support and cadence — the parts that decide whether the engagement changes anything, and the questions to settle before you sign.

Use this before you read the guide

Five things a proposal says — and what they usually mean

You can apply these to a quote sitting in your inbox right now. None of them prove a firm is bad; all of them are worth a follow-up question before you sign.

Watch for

"Automated and manual testing"

Ask for the ratio. Nearly every proposal claims both. The honest answer is a rough percentage of tester-days spent by hand, and a firm that can't give one probably isn't spending many.

Watch for

Priced per IP or per application

Effort doesn't scale by asset count. One application with fifteen user roles takes far longer than five brochure sites. Unit pricing usually means a tool is doing the work.

Watch for

No named tester or CV offered

You are buying someone's judgement and time. If nobody will tell you whose, ask who actually runs the engagement and what else they're assigned to that fortnight.

Watch for

Re-test charged as a new engagement

Verifying a fix is a fraction of the original effort. Paying full price again to confirm you closed something is a strong signal about how the relationship will run.

Watch for

A sample report you can't see

The report is the deliverable. Any firm can redact one and show you. Refusing usually means the output is a tool export with a cover page on it.

Watch for

Findings counted, not explained

"We found 47 issues" tells you about the scanner's sensitivity, not your risk. Ask how many were manually validated and how many could actually be chained together.

Applying these properly will sometimes lead you to a different firm, and that is fine by us. A buyer who understands what they're purchasing scopes better, negotiates better, and is far less likely to be disappointed by what a test can realistically deliver. The full guide goes further on each of these, plus scoping and pricing.

The full guide · free · PDF

Take the whole thing with you

Everything summarised above, in full — plus the scoping worksheet and the vendor question list, formatted to bring into a meeting or forward to whoever signs off the budget.

Thanks — the guide is on its way to your inbox. If it hasn't arrived in a few minutes, check your spam folder, then email us and we'll send it directly.
That didn't go through. Please check the fields above and try again — or email us and we'll send the guide over manually.

One email with the guide attached, and that's the whole obligation. Company and phone are optional — they only help us answer sensibly if you write back with a scoping question. No drip sequence, no sales calls you didn't ask for, and unsubscribe works from the first message.