Replies: 1 comment 5 replies
-
On a related note, are there any other engagements that crypto security firms typically offer? Like extended periods of general security consulting during a protocol's development phase? Or being on call to help resolve an incident if one arises? Does Cyfrin offer any services like this that aren't just time-boxed audits? |
Beta Was this translation helpful? Give feedback.
5 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
This is just a general question on how auditing firms (including Cyfrin) typically arrive at a total price for an audit or other services and what the current rate as of today looks like.
I understand that the first general step is just scoping out the work and coming up with a time estimate based one lines of code and maybe a complexity score, but then is the price basically just an hourly rate times the number of hours? If so, what is a typical ballpark rate in today's market (I realize this probably varies wildly based on the firm's reputation)? Are there any add-ons/upsells that are typically sold? Also, what is a typical maximum number of auditors working simultaneously on a codebase and how would a firm determine if/when to put multiple auditors on a codebase?
I realize this is a lot of questions all at once but I'm just looking for a better understanding on how the industry works - thanks so much in advance!
Beta Was this translation helpful? Give feedback.
All reactions