Insights ·

Explaining our scoping call process

By Nanorisk

Explaining our scoping call process

A question we get regularly: how do you scope a penetration test if you're not sure what you need?

The honest answer is that figuring out what you need is exactly what the scoping call is for. We go through your environment in detail, ask about the things that concern you, and often surface gaps or areas worth including that hadn't been on your radar. It's not a form-filling exercise, and we're not working from a fixed pricing matrix.

Because we scope to fit what you actually require rather than defaulting to a broad, catch-all engagement, our quotes tend to come in lower than clients expect. That surprises people, but it shouldn't - it's just what happens when the conversation is about your needs rather than our margin.

If you're thinking about commissioning an assessment and want to understand what's involved before you commit to anything, the scoping call is the right place to start.

Concerned this affects you?

We can assess your exposure and tell you plainly where you stand.

← All insights