Frequently asked questions
The questions we hear most before an engagement - scoping, timelines, deliverables, compliance and how we work. Service-specific questions live on each service page.
Services & engagements
Penetration testing across web, API, mobile, network and wireless, secure code review, threat modeling, social engineering, cloud and IT systems security, AI and LLM red teaming, incident response and digital forensics, vulnerability management, and governance and compliance services including vCISO. See the full services overview.
You book a call or send an enquiry, we hold a short scoping conversation about your systems and goals, and you receive a fixed proposal with timeline and deliverables. No obligation at any point before the proposal is signed.
It depends on scope. As reference points: basic network validation runs about 5-7 business days, a comprehensive assessment around 10-14 days, and complex or critical-infrastructure scopes can span 2-3 weeks. Scoping fixes the timeline before work starts, so there are no surprises.
A report with an executive summary for leadership and full technical detail for your engineers: risk-classified findings, proof-of-concept evidence, developer-ready remediation guidance, and compliance mapping references suitable for auditors.
Yes. Remediation validation is part of how we work - we retest the reported findings and update the report so you have evidence that issues are closed, not just identified.
Compliance frameworks
NIS2, DORA, ISO 27001, GDPR, PCI DSS and SWIFT CSP. We map technical security work to the regulatory outcome you need - see the compliance overview for how controls map to each framework.
NIS2 applies to organizations above the medium-enterprise thresholds (50+ employees or over 10 million euro annual turnover) operating in covered sectors such as energy, finance, healthcare, digital infrastructure and manufacturing. Some critical providers are in scope regardless of size, including DNS, trust service and public communications providers.
Yes. Reports include the documentation auditors expect - risk classifications, proof-of-concept evidence, remediation records and compliance mapping - aligned with ISO 27001, DORA and NIS2 documentation standards.
Yes - that is a normal starting point. We map your obligations before any engagement begins, so you know which frameworks apply and what the gap actually is before committing to anything.
Working with SoCyber
Senior consultants only - no juniors on engagements. The team holds 50+ security certifications including OSCP, OSWE and CREST, and has delivered 400+ projects for 150+ organizations. Meet them on the team page.
Under NDA as standard, with findings shared only with the contacts you designate. Much of our client base is in banking and fintech, so confidential handling of engagement data is the default, not an add-on.
Across Europe, with delivery in English. Most work is performed remotely; on-site delivery is available where the engagement calls for it, such as internal network testing or physical social engineering.
Per engagement, based on scope - the systems in play, depth of testing and reporting requirements. After a short scoping call you receive a fixed quote, so costs are known before work begins.
Book a call or email office@so-cyber.com. We usually respond within one business day.
Didn't find your answer?
Ask us directly - a short call is the fastest way to scope your situation and get a straight answer.