Scheduling and scope creep


Provide a detailed schedule of the pentesting phases with planned days with the budget. Generally, pentests are scheduled during any of the following timeframes:

  • During work hours

  • After work hours

  • On weekends

Make sure the emergency contacts are available during the pentesting hours.

Scope creep

An important discussion to have during the planning and scoping phase of the penetration test is how to handle scope creep. Scope creep occurs when the size of the project changes or grows as the project runs.

Be very clear at the start that the cost is for the targets that have been defined within the scope of the project and that any newly discovered targets that arise while the penetration test is occurring will be an additional cost.