Advisory
6 min
How to buy security testing without wasting the budget
The scoping conversation determines the value of the engagement more than the testing does.
Two organisations buy the same number of testing days. One receives a document that gets filed. The other closes a class of issues and can prove it to a customer. The difference is almost always established before any testing begins.
Scope by objective, not by asset count. 'Test these forty hosts' produces coverage. 'Establish whether an external attacker can reach customer data, and how' produces a decision. The second framing costs the same and is worth considerably more.
Insist on knowing who does the work. In much of the industry the person who scopes the engagement is not the person who delivers it, and quality varies accordingly. Ask directly, and ask what happens if the tester finds something outside scope.
Finally, buy the retest. An engagement that ends at the report leaves you with an opinion. An engagement that ends at verified closure leaves you with evidence: and evidence is the thing your customers, auditors and regulators are actually asking for.