Scope Expansion 1-pager
A penetration test reflects a point-in-time environment. As your product, infrastructure, or attack surface evolves, your testing scope should evolve with it. Below are four signs it's time to expand your security testing, and what to add when they apply.
Download document
Key Takeaways
- New AI features (LLM, agents, RAG, MCP servers) open attack paths a standard web pentest doesn't cover.
- A mobile launch carries attack surface, like local storage and device permissions, that a web app pentest doesn't reach.
- Enterprise vendor security reviews often expect testing well beyond your original scope.
- Mergers and acquisitions leave overlapping credentials, identities, and permissions that widen risk across environments.



