What determines cost
Scope is the strongest driver: applications, APIs, external and internal assets, cloud accounts, mobile platforms, authentication roles and environments all change effort. Complexity, testing depth, reporting, retesting and compliance evidence also matter.
Two tests with the same asset count can differ because business logic, integrations, privilege levels and production constraints change the manual work and specialist expertise required.
- Defined assets and exclusions
- Testing depth and credentials
- Rules of engagement and production constraints
- Technical and executive reporting
- Remediation review and retesting
Automated scanning is not a pentest
Scanning finds known patterns at scale. A professional pentest combines tools with human reasoning, controlled exploitation and attack-path analysis. It tests whether weaknesses can be combined and what a realistic compromise could mean.
- Web application — application flaws and business logic
- External network — internet-facing attack surface
- Internal network — lateral movement and internal exposure
- API — authentication, authorization, data and logic
- Cloud — identities, configuration and attack paths
How to compare proposals
A professional quote should define methodology, scope, assumptions, tester effort, evidence handling, severity model, deliverables, communication and retesting. The cheapest quote may omit the depth needed for the decision, while an expensive quote is not automatically better.
OyaCyber scopes testing around material risk, business context and the outcome the client must defend—not a generic package.
Questions leaders ask
Can OyaCyber quote without scope?
We can discuss a range, but a defensible proposal requires enough discovery to understand assets, complexity and constraints.
Is retesting always included?
It varies. The proposal should state whether retesting is included, its window and which findings are eligible.
