BoundaryProof Blog
Scope creep: how we keep assessments useful
Tight scope protects budgets and quality. How we handle the “while you’re there” problem.
Scope creep kills useful security work. It turns a focused Web assessment into an accidental everything-test, blows budgets, and produces findings nobody owns. Here is how we keep engagements finishable.
Start with one biggest concern
The site starter paths exist for a reason. Portal worry → Web. Unknown internet exposure → External Infrastructure. Public data worry → OSINT. Messy rules → Firewall. You can combine services later. Starting with one usually yields faster fixes and cleaner decisions.
Write the edges down
The scope and prerequisites call is where we name assets, environments, testing windows and exclusions. “While you are there, can you also…” belongs in a change request, not a silent expansion mid-test. Authorisation must cover what we touch. Third-party systems without permission stay out.
Park good ideas without losing them
During testing, we may notice adjacent issues. The professional move is to record them as recommendations or proposed follow-up, not to silently widen intrusive testing. That keeps trust intact and reporting honest.
Retest is not a backdoor to new scope
Retest validates remediation on agreed findings. New systems need new authorisation and a new conversation. That discipline is how founder-led delivery stays accountable.
If you have been burned by vague security projects before, bring that history to the free intro call. We will design a first engagement that finishes. Services remain Web, External Infrastructure, OSINT and Firewall — no CE+, no “any company” fishing, no theatre.
Commercial clarity helps technical clarity
When commercials match scope — one service, clear assets, clear deliverables — technical work stays cleaner. Creep often starts as unpaid kindness and ends as resentment on both sides. We would rather price a follow-up properly than quietly overextend. That is part of treating SME budgets with respect.
If your internal stakeholders are famous for expanding requests mid-flight, invite them to the scope call. Alignment up front is cheaper than rework later. Tight scope is not inflexibility; it is how useful work gets finished.
Examples of creep we push back on
“While you are in the portal, can you also check our entire cloud estate?” without new authorisation and time. “Can you quickly look at our supplier too?” without permission. “Can you turn this into a full pentest mid-week?” without replanning. Each may be a valid separate engagement. None should silently mutate the current one.
Pushback is protective. It keeps your budget honest and your report coherent. A muddled scope produces muddled remediation ownership, which is how findings linger.
The healthy pattern is: finish the agreed Web, Infra, OSINT or Firewall review; debrief; decide the next slice; authorise it; schedule it. That is how SMEs make steady progress without drowning.
How to brief stakeholders against creep
Before work starts, tell internal stakeholders the engagement is intentionally narrow. Share the asset list. Share what is out of scope. Invite them to propose follow-ups as a separate decision after the debrief. That social contract prevents mid-test ambushes that put the assessor in an impossible position.
If someone senior insists on expanding mid-flight, we pause and re-scope rather than pretend nothing changed. Pausing is cheaper than producing a report that answers three different questions poorly. Focused Web, External Infrastructure, OSINT and Firewall work only stays valuable when the edges stay real.
Ready to talk it through?
Book a free intro call to see whether a focused Web, External Infrastructure, OSINT or Firewall review is the right first step. Authorised scope only.