KobReySec Logo
Assessment Scoping

Scope the Work.
Start With the Right Information.

Good scoping makes for better testing, fewer surprises, and a more accurate proposal. You do not need every technical detail before you begin. Estimates are fine, and unknowns can be confirmed later.

Choose whichever option is easiest for your team. Complete the questionnaire online, or download a copy to circulate internally and return when you are ready.

Submitting scoping information does not authorize testing. Scope, schedule, rules of engagement, and written authorization are finalized before testing begins.

1
Tell Us What You NeedChoose the services you want to scope and describe the objectives, concerns, or requirements driving the project.
2
Estimate the EnvironmentProvide approximate address counts, applications, locations, users, systems, or configurations. Exact values can come later.
3
We Review the DetailsWe review the information, identify any follow-up questions, confirm scope, and determine the effort required.
4
We Build the ProposalOnce the scope is clear, we prepare the approach, schedule, and proposal around the work required.
Choose How You Want to Scope It

Two Ways to Get Us the Same Information

Use the online form if you already have the information handy. Use the downloadable questionnaire if several people need to contribute, you want to work through it offline, or you need to circulate it internally first.

Complete It Online

The guided online questionnaire adapts to the services you select and walks through the information we need to prepare an accurate scope.

Best for: a single point of contact, straightforward environments, or anyone who wants to submit the information directly.
Start Online Scoping

Download the Questionnaire

Use the PDF version when you want to review the questions first, gather details from multiple teams, or work through the scope before sending it back to us.

Best for: larger environments, reseller or partner-led projects, internal coordination, or anyone who prefers an offline working document.
Download the Questionnaire
What the Questionnaire Covers

One Questionnaire. Multiple Assessment Types.

The questionnaire begins with the project objectives and general constraints, then collects only the details relevant to the assessment types you want to scope.

External Testing & Edge

Internet-facing address space, domains, active systems, public applications, and whether the goal is discovery, validation, or deeper exploitation.

Internal Testing

Network size, active systems, approximate device breakdown, starting access, and whether multiple locations or segments are involved.

Wireless Testing

Wireless networks, physical locations, and whether the same network design and configuration is shared across sites.

Web Applications & APIs

Application count, size, purpose, user roles, testing environment, workflows, and approximate API coverage.

Vulnerability Assessments

External and internal address counts, connection requirements, scanning windows, and whether authenticated scanning should be included.

Security Benchmarking

Platforms such as Microsoft 365, Entra ID, Azure, AWS, Windows, or Linux, along with environment size and preferred guidance.

Configuration Reviews

The technology being reviewed, the number of devices or independently managed configurations, and approximate rules or settings.

Social Engineering

Authorized simulation types, scenario development, participant estimates, target groups, business themes, and exercise restrictions.

What You Need Before You Start

You Do Not Need a Perfect Inventory

Scoping is meant to establish the approximate level of effort, not require a complete inventory before we can talk.

  • Approximate counts are acceptable when exact ranges or inventories are not yet available.
  • You can enter “Not sure” or “Unknown” where the answer still needs to be confirmed.
  • Do not include passwords, employee contact lists, sign-in information, or sensitive data in the scoping form.
  • If third-party systems are involved, we may need written authorization before they can be tested.
  • Fixed deadlines, blackout periods, special handling requirements, and reporting obligations are useful to identify early.
A Common Question

Edge Assessment or External Penetration Test?

An Edge Assessment focuses on discovering and mapping internet-facing assets, then identifying known vulnerabilities, outdated software, and common configuration issues.

An External Penetration Test goes further. It includes deeper hands-on testing and controlled exploitation to determine whether identified weaknesses can be used to compromise the environment.

The simple distinction

Edge tells you where exposure exists. External penetration testing determines whether that exposure can be used to compromise the environment.

Not Sure What You Need?

You do not have to choose the service before talking with us. Tell us what prompted the project and what you are trying to understand, and we will help determine the right approach.