// frequently asked questions
Questions, answered straight.
The things clients ask before starting an engagement. Anything missing — ask directly.
How long does a penetration test take?
Most web application or API tests run five to ten working days depending on scope. You receive a realistic estimate after a short scoping call, and the timeline is fixed in writing before the engagement starts.
Do you sign NDAs?
Yes. A mutual NDA can be signed before any technical detail is shared. Confidential handling of client data is standard on every engagement, not an add-on.
What do we receive at the end?
Two deliverables: an executive summary written for leadership, and a technical annex with every finding, evidence, reproduction steps, severity, and remediation guidance — plus a live debrief call and a free retest of fixed issues within the agreed window.
Can you test production systems safely?
Yes. Rules of engagement define safe testing windows, excluded actions, and emergency contacts. Destructive testing is never performed without explicit written approval.
Which standards do you test against?
Web and API testing is mapped to OWASP WSTG and the OWASP API Security Top 10; infrastructure work follows PTES and NIST SP 800-115; compliance gap work covers ISO 27001, SOC 2, PCI DSS, and NIST CSF.
Do you work with international clients?
Yes — engagements run remotely worldwide, with on-site available where required. Time-zone overlap with the UK, EU, and Gulf is native; US hours are covered by arrangement.
How is pricing structured?
Fixed-price per engagement, agreed after scoping. No hourly surprises. Retests of fixed findings within the agreed window are included.
What makes ABZSECURE different from a big firm?
You work directly with a CISSP/CEH-certified consultant — the person who scopes the work is the person who tests and writes the report. No juniors, no hand-offs, no diluted findings.
Questions to ask ANY penetration tester before you hire them
Use these to evaluate anyone — including me. A good tester welcomes them.
- 1Will the person who scopes the work also do the testing, or is it handed to juniors?
- 2Is this manual testing, or mostly an automated scan with a report wrapped around it?
- 3Can I see a sample report showing real exploit evidence, not just a vulnerability list?
- 4Is a retest of fixed findings included, or billed as an extra?
- 5What standards do you test against (OWASP, PTES, NIST)?
- 6How do you handle sensitive data and rules of engagement?