Qubit Technologies

Published on 25 July 2026 · by Qubit Technologies

How to buy a security audit without getting a scan in disguise

Most companies do not fully know what they are buying when they ask for an audit, so they end up paying for an automated scan sold as one. Here is how to choose well, the questions that expose a weak provider and what a report worth its price has to include.

Almost no company fully knows what it is buying when it asks for a security audit. It knows it needs one, it has a budget and it looks for someone to do it. The trouble comes afterwards, when a report arrives and there is no way to tell whether real work was done or whether the output of an automated tool got handed over with the provider’s logo on the cover.

That difference is worth a lot of money. A scan costs a fraction of what a real audit costs, so sometimes the first gets sold under the name and the price of the second. Here is how not to fall for it, told from the side of the people who run the audits.

Before you ask for a quote, know what you want to protect

The first mistake happens before you talk to anyone. Many companies ask for “an audit” without having decided what they want to test. That makes it impossible to compare two proposals, because each provider will understand something different. Reviewing a public facing website is not the same as the internal network where your staff work or the application you invoice with.

Spend some time on the boring part before asking for a price. Which systems really matter to you, what would happen if each one fell, what you cannot afford to lose. With that clear the conversation changes completely. You no longer ask for “security” in the abstract, you ask someone to try to break into what would hurt you most to lose.

The scope is the first signal

When the proposal arrives, the first thing that tells you whether you are dealing with someone serious is how the scope is defined. A good proposal is specific. It makes clear which systems are in and which are out, where the testing is launched from, whether there will be credentials or it starts blind, how many days of work sit behind it and what profile will spend them.

A vague proposal is a warning sign. If the document talks about a “comprehensive security analysis” without saying of what, or if the price is the same whether you look at one website or the whole company, there is almost certainly a tool behind it that gets pointed the same way at anything. Manual work is priced by time and by scope. A flat price that depends on nothing is usually the price of pressing a button.

The questions that expose a weak provider

There is a handful of questions that cost nothing and say a great deal. Ask whether the test is manual or automated and who exactly runs it, with what experience behind them. Ask whether they will exploit the flaws they find or only list them, because exploiting is what separates an audit from an inventory of suspicions.

Ask to see a sample report, even an anonymised one. In two minutes you can see whether they deliver worked findings or the dump of a tool. Ask as well about the retest afterwards. A serious provider tries again against what you have fixed to confirm it was properly closed, it does not leave you with a to-do list and disappear.

What the report has to include

The report is the only thing you are left with when the work ends, so it is where you really see what you paid for. A good one has two layers. On one side, a summary for whoever decides, explaining in plain language how you stand and what real risk you carry. On the other, a technical detail for whoever has to fix it.

Each finding should come with three things, how to reproduce it step by step, what real impact it has on your business and a concrete remediation guide. That impact measured against what is yours, not against a colour scale that fits anyone.

If the report is a very long table of vulnerabilities sorted by a coloured number, with no narrative and with no one having checked which ones are real, what you have in front of you is the output of a scanner. A real report prioritises, discards the false positives and tells you where to start on Monday morning.

What the price tells you

The price lies less than it seems. A manual audit is the work of qualified people over days. That has a floor below which something does not add up.

If a quote is strikingly cheaper than the rest, it is not a bargain, it is something else. It almost always means that what should be manual has been automated, that the real scope is far smaller than you think or that whoever does it does not have the experience the work calls for.

Being expensive does not guarantee anything on its own either. That is why the questions and the sample report matter more than the figure. The price tells you where to be suspicious, not where to decide.

The scan in disguise, the mistake they want to slip past you

In the end all of this comes down to not confusing two things that look alike on the invoice and look alike in nothing else. An automated scan gives you a list. An audit gives you someone who has actually tried to get in and tells you how far they reached.

It is the same trap we wrote about in pentest, red team or vulnerability scan, which one do you actually need. The cheap thing sold as the expensive one reassures just as well as the expensive one, until the day someone gets in where the scanner never looked. The way to avoid that day is to know what you are asking before you sign.


If you are about to ask for an audit quote and want a second opinion on what you are being offered, write to us at [email protected].

Want a serious test of your security?

If after reading this article you want to put the real security of your organisation to the test, write to us and we will outline a scope tailored to your context.

Get in touch