| Can confirm a 2 day engagement is unusual, and 50% of time writing the report is possible but very much an outlier for standard pen tests. Some interesting exceptions include: * Some regions have a much shorter average engagement time. North America is usually pretty generous, where markets in other countries will only bear half or a third of the time. * If you are a junior or less skilled you are perhaps more likely to get the small jobs while you are learning. * External inf can be short on testing time and long in reporting if you find lots of issues, but automation helps the reporting in that regard. * Some pentests are very documentation intense for specific reasons, such as M&A due diligence, or clients who want threat models and design reviews incuded. Still isn't 50% though. And others. But in general what Thomas describes has been my experience over the years. Disclaimer: I work for NCC, but nothing related to former Matasano and I don't know Thomas. Opinions are my own. |
But as I said in another comment, depending on what people consider to include as "report writing" I can definitely see some engagements needing 50% time there. So maybe this person did just get unlucky.