Skip to content
Back to the guide

Pentest and audit

How to prepare for a pentest so you do not overpay

Five things done before the start that save days of work.

3 min read

A pentest is paid for by time. The more precisely the scope is defined and the faster we get access, the more hours go into searching rather than organising.

  • Define the scope: which domains, applications and networks are in and which are out. Production or staging.
  • Prepare access in advance: test accounts for different roles, VPN, API documentation.
  • Warn the team and the hosting provider, so the defences do not block us in the first hour and admins do not start "fighting a fire".
  • Make a backup and check that it restores. We are careful, but this is the rule for any work.
  • Assign one contact person who can answer questions quickly during the work.

What is not needed

Fixing everything known before the pentest "so it is not embarrassing". The opposite: we will see the real state and help set priorities.

Articles