Good question on “What does pentesting cost” Scott Goodwin comes back with “you must scope the pentest to decide what we can try to break and not break”