Complete It Online
The guided online questionnaire adapts to the services you select and walks through the information we need to prepare an accurate scope.
Good scoping makes for better testing, fewer surprises, and a more accurate proposal. Whether you are planning penetration testing or a focused security assessment, you do not need every technical detail before you begin. Estimates are fine, and unknowns can be confirmed later.
Choose whichever option is easiest for your team. Complete the questionnaire online, or download a copy to circulate internally and return when you are ready.
Submitting scoping information does not authorize testing. Scope, schedule, rules of engagement, and written authorization are finalized before testing begins.
Use the online form if you already have the information handy. Use the downloadable questionnaire if several people need to contribute, you want to work through it offline, or you need to circulate it internally first.
The guided online questionnaire adapts to the services you select and walks through the information we need to prepare an accurate scope.
Use the PDF version when you want to review the questions first, gather details from multiple teams, or work through the scope before sending it back to us.
The questionnaire begins with the project objectives and general constraints, then collects only the details relevant to the assessment types you want to scope.
Internet-facing address space, domains, active systems, public applications, and whether the goal is discovery, validation, or deeper exploitation.
Network size, active systems, approximate device breakdown, starting access, and whether multiple locations or segments are involved.
Wireless networks, physical locations, and whether the same network design and configuration is shared across sites.
Application count, size, purpose, user roles, testing environment, workflows, and approximate API coverage.
External and internal address counts, connection requirements, scanning windows, and whether authenticated scanning should be included.
Cloud platforms such as Microsoft Azure and Microsoft 365, Amazon Web Services (AWS), or Google Cloud Platform (GCP), along with environment size and the Center for Internet Security (CIS) or Cybersecurity and Infrastructure Security Agency (CISA) guidance being evaluated.
Specific cloud services, identity policies, storage settings, network controls, rule sets, or other configurations where a narrower review is needed instead of a full benchmark assessment.
Participant estimates, target groups, scenario themes, controlled sign-in behavior, exercise restrictions, and whether open-source intelligence (OSINT) should support scenario development.
Scoping is meant to establish the approximate level of effort, not require a complete inventory before we can talk.
An Edge Assessment focuses on discovering and mapping internet-facing assets, then identifying known vulnerabilities, outdated software, and common configuration issues.
An External Penetration Test goes further. It includes deeper hands-on testing and controlled exploitation to determine whether identified weaknesses can be used to compromise the environment.
Edge tells you where exposure exists. External penetration testing determines whether that exposure can be used to compromise the environment.
You do not have to choose the service before talking with us. Tell us what prompted the project and what you are trying to understand, and we will help determine the right approach.