Offensive Security · Filed · Singapore · 6 min read

How to Scope a Penetration Test: A Buyer's Guide

Scope determines whether a penetration test finds exploitable risk or generates a scanner report. A guide to targets, rules of engagement, methodology, and reporting.

By Cyber Inspect Editorial Board

Scope is the deliverable-in-waiting

A vague scope produces a vague report. Every commercially useful penetration test starts with a written risk hypothesis and a stated business impact.

Six variables to codify in the SoW

  • Targets: hosts, applications, cloud accounts, network ranges.
  • Depth: black, grey, or white box.
  • Authentication: what credentials the tester receives.
  • Rules of engagement: destructive tests, DoS, social engineering.
  • Timing: business hours, blackout windows, customer notification.
  • Reporting: executive summary, technical report, retest inclusion.