“Just Send Me a Quote and We’ll See” – Why I Don’t Work That Way
“Come on, send me a quote and we’ll see what happens,” a prospective client said to me.
I asked him: “what exactly do you want tested? What does each system do? And how big is each one?”
“The site, the app, the customer-facing interface too… whatever you can do.”
“What we can do is not the point,” I answered. “What do you want a quote for? Which system needs to be in scope?”
There was a silence. And then came the sentence that always makes me stop: “forget it, just give me a price, we’ll go with the flow.”
I don’t go with the flow
Not when it comes to security testing.
A number without a scope is not a quote, it is a guess – and the person who pays for the guess is always the client. Either the price is padded to cover the unknown, or the scope quietly shrinks until it fits the price, and the parts nobody agreed to drop are the parts that never get tested.
The questions I ask before quoting are not bureaucracy. What each system does, who its users are, which roles exist, how big it is, what it connects to – those answers are the test. They determine whether we are testing authorization between tenants or a marketing site, whether there are three user roles or thirty, whether there is one API or an integration surface with six external services behind it.
“Whatever you can do” is not a scope. It is an invitation to test the easy parts, produce a clean report, and leave the hard ones alone – which is exactly the kind of engagement that lets everyone feel good and protects nobody.
I first shared a version of this as a LinkedIn post on 2025-03-19. It is republished here, lightly edited, so it is easier to find and reference. — Erez Metula
