
Back to the guide
Pentest and audit
How to prepare for a pentest so you do not overpay
Five things done before the start that save days of work.
3 min read
A pentest is paid for by time. The more precisely the scope is defined and the faster we get access, the more hours go into searching rather than organising.
- Define the scope: which domains, applications and networks are in and which are out. Production or staging.
- Prepare access in advance: test accounts for different roles, VPN, API documentation.
- Warn the team and the hosting provider, so the defences do not block us in the first hour and admins do not start "fighting a fire".
- Make a backup and check that it restores. We are careful, but this is the rule for any work.
- Assign one contact person who can answer questions quickly during the work.
What is not needed
Fixing everything known before the pentest "so it is not embarrassing". The opposite: we will see the real state and help set priorities.
Articles

Pentest and audit
What a pentest is and how it differs from a vulnerability scanner
A scanner finds known holes from a list. A pentester thinks like an attacker and chains small things into a real breach.
4 min read
Pentest and audit
Types of pentest: web, API, mobile apps, infrastructure, cloud, people
Each type checks its own layer. Together they give the picture, separately only a fragment.
5 min read