Hacker News new | ask | show | jobs
by kradroy 1005 days ago
That sounds like a very reasonable course of action. However... given the circumstances the author is in, I don't think his director is the type to schedule a pen test and then wait for all the violations to be resolved in order to get the contract. (I assume the client, as a government entity, is legally required to obtain a minimum number of bids for contracts and make a decision in a timely manner.)

Lying and fraud aren't the same, which is the author's concern. Lying incurs a social cost. Fraud incurs both social and legal costs.