Scoping Guides

Understand what each cybersecurity service involves, what it costs, and how to evaluate providers.

These guides help you understand what each cybersecurity service involves, what it costs, and how to evaluate providers. Written for business leaders and IT directors who are buying these services for the first time or looking to improve their vendor selection process.

External Penetration Testing

What It Is

An external pen test simulates an attacker on the internet trying to break into your publicly accessible systems. Testers probe your firewalls, web servers, email servers, VPNs, and cloud infrastructure for weaknesses that could allow unauthorized access.

What to Expect

Timeline
1 to 3 weeks depending on scope. Most engagements for small to midsize companies finish in 5 to 10 business days of active testing.
Process
You provide a list of IP addresses and domains in scope. Testers perform reconnaissance, vulnerability scanning, and manual exploitation attempts. You receive a detailed report at the end.
Deliverables
A written report including an executive summary, technical findings ranked by severity (Critical/High/Medium/Low/Informational), proof of exploitation where applicable, and remediation recommendations.

Typical Price Ranges

$5,000 to $30,000 for most small and midsize businesses. Enterprise environments with hundreds of external IPs can exceed $50,000.

Key Questions to Ask Providers

  • 1.Do you perform manual testing or only automated scanning?
  • 2.What methodology do you follow (PTES, OWASP, OSSTMM)?
  • 3.Will the report include proof-of-concept evidence for each finding?
  • 4.Do you offer a free retest after remediation?
  • 5.What certifications do your testers hold (OSCP, GPEN, CREST)?

Red Flags

  • Provider relies solely on automated scanners (Nessus/Qualys) without manual testing
  • No clearly defined scope or rules of engagement before starting
  • Refusing to share sample reports
  • Pricing that seems too low (under $3,000 for a meaningful scope)
  • No communication plan for critical findings discovered mid-engagement

Internal Penetration Testing

What It Is

An internal pen test simulates a threat actor who already has a foothold inside your network. This could be a malicious employee, a compromised workstation, or an attacker who bypassed perimeter defenses. Testers attempt to escalate privileges, move laterally, and access sensitive data.

What to Expect

Timeline
1 to 3 weeks. Testing can be performed on-site or remotely via VPN/jump box. Remote testing is now standard for most providers.
Process
Testers connect to your internal network with standard user-level access. They enumerate the environment, identify misconfigurations, exploit vulnerabilities, and attempt to reach crown-jewel assets like domain admin, databases, or financial systems.
Deliverables
A narrative report showing the attack path from initial access to objective, plus individual findings with remediation steps. Many providers include an attack path diagram.

Typical Price Ranges

$10,000 to $40,000 depending on network size and complexity. Active Directory environments with multiple domains are on the higher end.

Key Questions to Ask Providers

  • 1.How will testers connect to the internal network?
  • 2.Will you test Active Directory specifically (Kerberoasting, delegation attacks, GPO abuse)?
  • 3.Do you simulate different attacker starting points?
  • 4.How do you handle situations where you gain domain admin quickly versus slowly?
  • 5.Will you test segmentation between network zones?

Red Flags

  • Provider only runs an internal vulnerability scan and calls it a pen test
  • No testing of Active Directory attack paths
  • Unwilling to sign an NDA before receiving network details
  • No deconfliction process for distinguishing test activity from real attacks

Web Application Security Testing

What It Is

A web app pen test targets your custom applications, APIs, and web portals. Testers look for vulnerabilities like SQL injection, authentication bypasses, access control flaws, and business logic errors that automated scanners routinely miss.

What to Expect

Timeline
1 to 4 weeks per application depending on complexity. A simple marketing site might take 3 days. A complex SaaS platform with many roles and workflows could take 3 or more weeks.
Process
You provide access credentials for different user roles. Testers map the application, identify input points, and systematically test for the OWASP Top 10 and beyond. Business logic testing is manual and tailored to your specific application.
Deliverables
A report organized by vulnerability type with reproduction steps, screenshots, affected endpoints, risk ratings, and remediation guidance specific to your tech stack.

Typical Price Ranges

$8,000 to $50,000 per application. APIs with extensive endpoints and multi-role SaaS platforms are at the higher end. Simple informational sites are at the lower end.

Key Questions to Ask Providers

  • 1.Do you test business logic flaws or only technical vulnerabilities?
  • 2.How many user roles will you test across?
  • 3.Do you test the API independently or only through the UI?
  • 4.Will you test authentication flows (password reset, MFA bypass, session management)?
  • 5.Do you perform source code review as part of the engagement, or is that separate?

Red Flags

  • Only using automated tools like Burp Suite scanner without manual verification
  • Not asking about user roles, workflows, or business context
  • No discussion of testing environment (production vs staging)
  • Delivering a report that is clearly just exported scanner output

Compliance Testing and Auditing

What It Is

Compliance testing evaluates whether your security controls meet the requirements of a specific regulatory framework. This is not the same as a pen test. It is a structured assessment against a checklist of controls, often required for certification or regulatory reporting.

What to Expect

Timeline
2 to 8 weeks depending on the framework and your organization's readiness. A PCI DSS SAQ might take 2 weeks. A full SOC 2 Type II observation period is 3 to 12 months.
Process
An assessor reviews your policies, interviews staff, examines technical configurations, and collects evidence. You will need to provide documentation, demonstrate controls, and potentially remediate gaps identified during the assessment.
Deliverables
A formal compliance report or certificate (depending on framework), a gap analysis if you are not yet compliant, and remediation recommendations for any deficiencies.

Typical Price Ranges

$10,000 to $100,000+ depending on framework and scope. PCI DSS SAQ validation might be $10,000 to $25,000. Full SOC 2 audits range from $20,000 to $80,000. ISO 27001 certification from $15,000 to $50,000.

Key Questions to Ask Providers

  • 1.Are you accredited or certified to issue reports for this framework?
  • 2.Do you offer a readiness assessment before the formal audit?
  • 3.What evidence and documentation will you need from us?
  • 4.How do you handle findings discovered during the assessment?
  • 5.What is included in the final deliverable, and who is the intended audience?

Red Flags

  • Provider is not actually accredited for the framework they are assessing (e.g., not a QSA for PCI DSS)
  • Guaranteeing a pass before reviewing your environment
  • No clear explanation of what happens if you fail
  • Pricing that is dramatically lower than competitors (may indicate a superficial assessment)

Cloud Security Assessment

What It Is

A cloud security assessment reviews your AWS, Azure, or GCP environment for misconfigurations, excessive permissions, insecure defaults, and architecture weaknesses. Cloud environments are complex and fast-moving, making them a frequent source of data breaches.

What to Expect

Timeline
1 to 3 weeks for most environments. Larger multi-account architectures may take longer.
Process
You grant read-only access to your cloud accounts. Assessors review IAM policies, network configurations, storage permissions, logging, encryption settings, and architecture against cloud security benchmarks (CIS Benchmarks, cloud provider best practices).
Deliverables
A detailed findings report with screenshots of misconfigurations, risk-ranked issues, specific remediation commands or IaC changes, and an architecture review summary.

Typical Price Ranges

$10,000 to $40,000 for most assessments. Multi-cloud or very large environments (50+ accounts) can exceed $60,000.

Key Questions to Ask Providers

  • 1.Which cloud platforms do you specialize in?
  • 2.Do you review infrastructure-as-code (Terraform, CloudFormation) or only runtime configuration?
  • 3.Will you assess IAM and permission boundaries specifically?
  • 4.Do you benchmark against CIS or another recognized standard?
  • 5.How do you handle multi-account or multi-subscription architectures?

Red Flags

  • Only running an automated tool (Prowler, ScoutSuite) without manual review
  • No experience with your specific cloud provider
  • Not asking about your architecture, workloads, or data classification
  • Delivering a 200-page automated report with no prioritization or context

Virtual CISO (vCISO)

What It Is

A vCISO is a fractional Chief Information Security Officer who provides strategic security leadership on a part-time or retainer basis. They help you build a security program, manage compliance, respond to board-level questions, and make risk decisions without the cost of a full-time executive.

What to Expect

Timeline
Ongoing engagement, typically month-to-month or annual contract. Initial onboarding and assessment takes 2 to 4 weeks. Ongoing support is usually 10 to 40 hours per month.
Process
The vCISO assesses your current security posture, develops a roadmap, helps prioritize initiatives, attends leadership meetings, and provides guidance on vendor selection, incident response, and compliance.
Deliverables
Security roadmap, policy documents, risk assessments, board-ready presentations, vendor evaluations, and ongoing advisory support.

Typical Price Ranges

$3,000 to $15,000 per month depending on hours and seniority. Some providers offer project-based pricing for initial program development ($20,000 to $50,000).

Key Questions to Ask Providers

  • 1.What is your background? Have you been a full-time CISO before?
  • 2.How many clients do you support concurrently?
  • 3.How do you prioritize my organization's needs?
  • 4.Will you attend board meetings and present to leadership?
  • 5.What does the transition look like if we eventually hire a full-time CISO?

Red Flags

  • vCISO has no actual CISO experience (only consulting background)
  • Supporting too many clients to give meaningful attention
  • No clear deliverables or milestones defined in the contract
  • Pushing specific vendor products without evaluating alternatives
  • Not willing to be available during security incidents

Incident Response

What It Is

Incident response services help you contain, investigate, and recover from an active security breach. This includes identifying what happened, stopping the attacker, preserving forensic evidence, understanding the impact, and helping you return to normal operations.

What to Expect

Timeline
Engagement starts immediately (within hours of a breach). Active containment typically happens in the first 24 to 72 hours. Full investigation can take 2 to 8 weeks depending on complexity.
Process
The IR team deploys tools to your environment, contains the threat, performs forensic analysis, identifies the root cause, determines what data was accessed, and provides a full incident report. They may also help with legal and regulatory notification requirements.
Deliverables
An incident report documenting the timeline of the attack, root cause, scope of compromise, data impacted, containment actions taken, and recommendations to prevent recurrence.

Typical Price Ranges

$25,000 to $200,000+ depending on severity and duration. Many IR firms offer retainer agreements ($5,000 to $15,000/month) that guarantee response times and reduce hourly rates during an incident. Hourly rates without a retainer range from $300 to $600/hour.

Key Questions to Ask Providers

  • 1.What is your guaranteed response time?
  • 2.Do you offer retainer agreements?
  • 3.Can you deploy forensic tools remotely, or do you need on-site access?
  • 4.Do you have experience with our type of environment (cloud, on-prem, hybrid)?
  • 5.Will your report be suitable for legal proceedings and regulatory notifications?
  • 6.Do you coordinate with law enforcement if needed?

Red Flags

  • No guaranteed response time SLA
  • Wanting to wipe and rebuild before performing forensic analysis
  • Not discussing chain of custody for forensic evidence
  • No experience with your regulatory notification requirements
  • Requiring long-term contracts during an active emergency
BreachBench | Find the Right Cybersecurity Provider