Skip to content
    August 16, 2026| Top Floor Team| 10 min read

    7 Red Flags When Hiring a Security Consulting Firm

    Seven warning signs reliably predict a bad security consulting engagement: a guaranteed certification or guaranteed pass, a price quoted before any scoping conversation, refusal to share a sanitized sample deliverable, a statement of work that names no individual practitioners, no methodology named anywhere, a pitch that leads with fear instead of scope, and fees that only appear after signing. Each one has a mechanism behind it rather than being a matter of taste, and the mechanism is what makes them predictive. Any one is a reason to slow down. Two or more is a reason to walk.

    We wrote this from the rescue side. Almost every engagement we are asked to take over from another firm carried at least two of these at proposal stage, and the client could see them in hindsight.

    Key takeaways

    • Seven signs predict a bad engagement: a guaranteed certification, a price before scoping, no sanitized sample deliverable, no named practitioners in the statement of work, no methodology named anywhere, a pitch that leads with fear, and fees that appear after signing.
    • A guaranteed pass is structurally impossible. The outcome belongs to an independent CPA firm, certification body or assessor the consultant does not control.
    • Two requests separate firms faster than any other question, because both are trivial for a serious firm and awkward for the others: a redacted sample deliverable, and the named individuals who would staff your engagement.
    • If you have already signed, most of it is recoverable. Ask for the names in writing, request the sample retroactively, set acceptance criteria at the first milestone, and get the exclusions written down before the second invoice.
    • Two things look like red flags and are not: being small, and declining to guarantee an outcome.

    1. A guaranteed certification, or a guaranteed pass

    This is the only flag on the list that is structurally impossible rather than merely unwise.

    A SOC 2 report is an attestation issued by an independent licensed CPA firm. An ISO 27001 certificate is issued by an accredited certification body. A CMMC certification assessment is performed by an authorized third-party assessor organization. In every case, the outcome belongs to an independent party that the consultant does not control and, by design, cannot control. A consultant guaranteeing the result is either claiming influence over an independent opinion, which would be a serious problem for the opinion, or making a promise that will be renegotiated when it comes due.

    What a firm can legitimately promise is its own work: a defined scope, named deliverables, remediation support until the controls are in place, and often a commitment to keep working at no additional fee if a finding traces to its own analysis. Notice the difference. One is a promise about the consultant's performance. The other is a promise about someone else's judgment.

    2. A price before any scoping conversation

    Compliance and testing costs are functions of scope: how many systems, how many entities, which criteria, how much evidence exists, what the environment looks like. A firm that can price you from a website form has either priced a generic package that may not fit, or intends to discover the real scope after you have signed.

    The tell is not that the number is low. It is that the number arrived before anyone asked what you run. When we quote before a scoping call, we are guessing, and so is everyone else.

    3. No sanitized sample deliverable

    Ask any firm for a redacted example of the report you are buying. This is a routine request and a routine thing to provide.

    What a sample tells you is whether findings are specific enough to act on, whether recommendations name an owner and a mechanism, and whether the prose was written for your kind of environment or assembled from a template. A firm that refuses entirely is asking you to buy an unseen product. Watch for the softer version too: a marketing sample that shows the cover, the table of contents, and one page of methodology, but no actual finding.

    4. A statement of work that names no individual practitioners

    Consulting quality is a property of people rather than of firms, and the gap between the best and the average person at any given firm is wide. A statement of work that commits only to "a qualified team" has reserved the right to staff you with whoever is available.

    The pattern to watch for is a senior team selling and a junior team delivering. It is the failure mode we see most often when we are asked to review someone else's work, and it is prevented by one sentence in the contract. Ask for the names. A firm with depth will not mind, and will usually offer an alternate.

    5. No methodology named anywhere

    Testing and assessment work should name what it follows. For penetration testing, that means the OWASP Web Security Testing Guide, the Penetration Testing Execution Standard, or NIST SP 800-115. For compliance work, it means the framework and the assessment guidance that goes with it, such as NIST SP 800-171A for the assessment objectives behind CMMC Level 2.

    A named methodology is not a magic word. It is a commitment to a set of steps someone else wrote down, which means your deliverable can be checked against something. "Our proprietary approach" is not checkable, and in testing it very often resolves to a scanner. Penetration test versus vulnerability scan covers how to tell the difference from the artifacts.

    6. A pitch that leads with fear rather than scope

    Breach statistics in the first three slides, followed by a proposal, is a sales structure rather than an analysis. It is not that the statistics are wrong. It is that they are the same for every prospect, which means they contain no information about you.

    A pitch that starts with your environment, your customers' requirements, your contractual obligations, and what you already have, is a firm doing the work of understanding your problem before pricing it. The fear-first pitch tends to correlate with the generic-package problem in flag 2, because both come from a sales motion that treats scoping as a cost.

    7. Fees that appear only after signing

    The common ones: retesting billed separately when the proposal implied it was included, evidence collection charged as extra hours, travel and expenses uncapped, a project-management percentage layered on, and platform or tooling subscriptions bundled in a way that makes it hard to see whose margin it is.

    None of these is illegitimate on its own. All of them are legitimate to disclose. The flag is not the existence of an extra fee, it is finding out about it after commitment. In testing engagements the retest is the one that catches people most often, which is why is a cheap pentest worth it treats it as a pre-signature question rather than a detail.

    What to do if you have already signed

    Most people read a list like this with a contract already in place. The situation is recoverable more often than it feels.

    Ask for the names now, in writing. A firm that would have named practitioners at proposal stage will name them at kickoff. Getting a written answer costs nothing and changes the staffing conversation.

    Request the sample deliverable retroactively. Ask to see a redacted example of what you will receive before the fieldwork ends rather than after. If the format is wrong for your purpose, the cheap moment to say so is now.

    Set acceptance criteria at the first milestone. Even without them in the contract, agreeing in an email what a complete finding looks like gives you something to point at. Severity, affected asset, reproduction steps, recommended remediation. Most firms will agree readily, because it is what a competent deliverable contains anyway.

    Ask for the exclusions in writing before the second invoice. If the scope boundary was never drawn, draw it while goodwill is intact rather than during a dispute.

    And the harder judgment: if the deliverable arrives and it is a template with your name in the header, the sunk cost is usually smaller than the cost of building a program on top of a bad assessment. We have taken over engagements where the honest advice was to discard the prior findings entirely and start the analysis again, and the clients who did that spent less overall than the ones who tried to salvage the document.

    Two things that look like red flags and are not

    Being small is not a red flag. Specialist firms staffed by senior practitioners are a normal and often better structure than a large firm's leverage model, and firm size is not a proxy for the quality of the person doing your work.

    Declining to guarantee an outcome is the opposite of a red flag. A firm that says plainly that the opinion belongs to an independent auditor, and that its job is to make the failure unlikely rather than impossible, is telling you the truth about how the system works.

    And one thing worth naming against our own interest: if a firm tells you that you do not need it yet, take that seriously rather than reading it as a lack of enthusiasm. We say it several times a year, usually to companies who could run their first year with a platform and one committed owner.

    Where Top Floor fits

    We do not guarantee outcomes, we do not quote before a scoping call, and our statements of work name practitioners. That is not a differentiator so much as a description of what a defensible engagement looks like, and you should hold every firm on your shortlist to it, including us.

    Our compliance as a service and penetration testing work names its methodology, and our SOC 2 readiness work is deliberately separate from the CPA firm that issues your report. The reasoning behind the model is in why Top Floor.

    How to decide this week

    Take every proposal on your desk and check it against the seven flags in order. Score them.

    Then ask each firm for two things in writing: a sanitized sample deliverable, and the named individuals who would staff your engagement. Those two requests separate firms faster than any other question, because both are trivial for a serious firm and awkward for the others.

    If a proposal carries a guaranteed outcome, you can stop there. That one is not a preference.

    Frequently asked questions

    Can a consultant guarantee I will pass my SOC 2?

    No. A SOC 2 report is an attestation issued by an independent licensed CPA firm, and no consultant controls that firm's opinion. What a consultant can legitimately commit to is its own scope, deliverables, and remediation support, and some firms commit to continuing work at no extra fee if a finding traces to their own analysis. Treat a guaranteed result as a claim about someone else's independent judgment, which is a reason to be more careful rather than less.

    Is it a red flag if a security firm will not give me a price up front?

    Usually the opposite. Testing and compliance costs are driven by scope, so a price that arrives before anyone has asked what you run is either a generic package or a number that will change after you sign. What you should expect is a scoping conversation followed by a written quote with the scope, exclusions, and change-order triggers attached.

    What should I ask to see before signing with a security consultancy?

    Three things: a sanitized sample of the deliverable you are buying, the names of the individuals who will do the work, and a written exclusions list. Each one is routine for a firm that expects to be judged on its work, and each one is awkward for a firm relying on a capability deck. Reading a redacted report tells you more about quality in ten minutes than any reference call.

    Are small security consulting firms riskier than large ones?

    Firm size is a poor proxy for engagement quality, because what you receive is produced by specific people rather than by a logo. Large firms bring depth, global coverage, and a brand that matters in specific situations such as public-company readiness or large acquisition diligence. Specialist firms typically put more senior time on the actual work. The useful question in both cases is who is assigned to you and what proportion of the engagement they personally deliver.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.