Most warning signs show up before you sign anything, if you know what to actually look for during the sales and scoping process.
No written scope, or a scope so vague it could mean almost anything, is one of the clearest and earliest warning signs — it usually means either insufficient understanding of your environment or a deliberate effort to keep room for scope creep later.
Pressure to commit before you understand deliverables or timeline should slow you down rather than speed you up. Similarly, an inability to clearly explain who will actually perform the work, a lack of references for similarly-sized engagements, and guarantees that sound too clean are all worth taking seriously — genuine security work involves real uncertainty, and confident promises of a perfect, guaranteed outcome are a signal to ask harder questions, not a reassurance.
A written proposal with defined scope and pricing before commitment, a named specialist actually performing the work, and honesty about trade-offs and limitations — not just a confident, polished sales pitch with nothing concrete behind it.
Good providers are also comfortable explaining what could go wrong during an engagement and how they'd handle it, rather than presenting an unrealistically smooth picture of how the work will unfold.
If something about a pitch feels rushed, vague, or overly polished in a way that avoids specifics, that instinct is usually worth listening to. Providers with genuine expertise are generally comfortable slowing down and answering detailed questions rather than trying to move past them quickly.
Yes, and a credible provider should be able to offer them, or explain confidentiality constraints clearly rather than deflecting the question entirely without any explanation.
One isolated concern, clearly explained, isn't automatically disqualifying — but multiple red flags stacking up, or a provider who becomes evasive when you raise the concern directly, is a stronger signal worth acting on.