
How to Scope a Penetration Test Properly
A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.
Cyber risk is now a board-level business risk. NAZZTEC secures the full attack surface — identity, endpoint, network, application, cloud, data and OT — with a single accountable partner.
Our consultants have delivered security programmes for banks, insurers, government entities, telecom operators and large enterprises. Every engagement is anchored to recognised standards — NIST CSF, ISO/IEC 27001, SOC 2, PCI DSS and GDPR — and delivered with clear scope, fixed timelines and evidence you can present to your regulator, auditor or board.
The full capability list is published deliberately — it is what your procurement team needs to see, and what captures the long-tail searches your peers actually type.
We find what attackers would find — before they do. Every test is manual-led, mapped to OWASP, PTES and MITRE ATT&CK, and closed out with a re-test that proves the fix worked.
24x7 eyes on your estate, with engineering behind the alerts. We build, co-manage or fully operate your detection and response capability.
Identity is the new perimeter. We design identity programmes that cut standing privilege, satisfy auditors and remove friction for users.
Security that moves at the speed of your release pipeline — built into the platform and the SDLC, not bolted on afterwards.
Hardened foundations across perimeter, core and edge — designed for hybrid work and multi-cloud connectivity.
Know where your data is, who touches it, and prove it. We turn privacy obligations into working technical controls.
Specialist coverage for environments where availability and safety outrank everything else.
Senior security leadership without the senior headcount — and a workforce that stops being your weakest link.
A free 45-minute discovery call with a senior consultant to understand the business driver, the constraints and the deadline — before any solution is proposed.
A written scope with deliverables, assumptions, exclusions, timeline, team composition and fixed pricing wherever the scope allows. No unpriced obligations.
A named engagement lead, a named delivery team and a kick-off that confirms access, stakeholders and reporting cadence.
Execution with weekly progress reporting, visible artefacts, and early escalation of anything that could affect timeline or cost.
Documented, auditable deliverables — findings registers, control mappings, runbooks, architecture documents and test evidence written to withstand scrutiny.
Handover and knowledge transfer, or managed operations under agreed SLAs — so the outcome holds after we leave.
Cybersecurity Services covers the expertise and delivery. If you are evaluating the platforms themselves — what we deploy, which vendors we work with and how we select between them — see Cybersecurity Solutions.
ISO 27001, SOC 2, PCI DSS, NIST CSF and GDPR programmes, automated on a modern GRC platform.
ExploreCloud strategy, landing zones, migration, Kubernetes, CI/CD, DevSecOps and FinOps across Azure, AWS, GCP and OCI.
ExploreAI and machine learning, data platforms, Power BI analytics, automation and digital workplace — with measurable outcomes.
ExploreCustom web and mobile applications, APIs, microservices, UI/UX, low-code and QA automation, built and supported end to end.
Explore
A poorly scoped test produces a clean report and a false sense of security. Here is how to define objectives, assets, approach and rules so the results mean something.

The new Govern function, a broader audience, stronger supply chain expectations — and a practical method for turning the framework into a programme your board can follow.

The honest maths of 24x7 staffing, what a SOC really needs beyond a SIEM, and a framework for choosing between in-house, managed and co-managed security operations.
Describe what you are dealing with — a regulatory deadline, an audit finding, an incident, a migration or a capability gap. A senior consultant will respond within one business day.
We respond to every enquiry within one business day.