Website Audits... Are they really worth all the hype?

Discussion in 'BlackHat Lounge' started by temporary, Mar 3, 2013.

  1. temporary

    Jun 17, 2009
    I'm not too sure if getting a website audit done will be worthwhile.

    I'd love to hear from people who have received a website audit. Are you able to provide a sample so that I know what level to expect, were you happy with the report (as in was it worthwhile) and if you had taken action, did you see an improvement once you fixed the issues the audit uncovered?

    Thanks all!
  2. Zapdos

    Oct 22, 2011
    Eastern North Carolina
    What is your definition of audit?

    There are security audits. Those are usually much more expensive and take a bit of time to do if its an actual audit and not automated. They'll give you the attack vectors and sometimes suggestions on how to fix them.
    There are usability audits. These are relatively cheap ($10->$40 per person) and only require about 6 I believe to reach the starting point of minimal returns. Haven't gotten any myself yet since I can usually convince people to do these for free lol
    There is support audits which look at your support funnel to find any possible leaks or ways that it would not help the customer at all

    Need to be a bit more specific.