External penetration test of network and applications

A report the auditor and the insurer accept.

$4,480 for a network · $8,960 for an application or API.

Get a quote

When did someone last test your perimeter by hand?

Usually nobody. The scanner in your subscription ran yesterday and produced forty pages of warnings: nobody has time to read them, and what to fix is anyone’s guess. Your client’s questionnaire and your insurer’s application ask for something else: a test done by a person, and a report you can reproduce.

A report you can actually fix from

You get a short list of what really works against you. The scanner clears the obvious, then a person takes over: chains of small things, application logic, role permissions — what a machine does not see.

Every finding is written out step by step: how to reproduce it, what the attacker gets and how it ends if you leave it. Next to it we say what to fix first and what second. Not a list of warnings, a list of tasks.

We sign the rules of the test before it starts: what is in scope, what hours we work and who to call if something goes down.

What the test includes

  • included: Scope agreed and written authorisation to test
  • included: External perimeter, public services and entry points
  • included: Hands-on testing, not just a scanner run
  • included: Report: how to reproduce every finding, step by step
  • included: What each finding leads to and what to fix first
  • included: A walkthrough of the report with your engineers or vendor
  • included: A letter confirming the test for your client and insurer
  • paid to the vendor: Tool licences and cloud permissions — billed by the supplier

Your price

External network

$4,480 per perimeter

Forty hours of hands-on work.

What the tier includes

  • included: Public perimeter: services, entry points, remote access

Web application or API

$8,960 per application

Eighty hours: logic, roles and permissions.

What the tier includes

  • included: Application logic, roles and permissions, bypassing server-side checks

Test and retest

$12,320 for the pair

One hundred and ten hours plus a retest.

What the tier includes

  • included: Public perimeter: services, entry points, remote access
  • included: Application logic, roles and permissions, bypassing server-side checks
  • included: A retest of closed findings and an updated report

Extras

  • not included: SOC 2 readiness and keeping Type 2from $2,250
  • not included: CMMC readiness for defense contractorsfrom $3,360
  • not included: Questionnaires your client has sent$1,350 per questionnaire
  • not included: Preparing for a cyber policy renewal$2,250 one-off
  • not included: We watch for attacks around the clock$18 per endpoint a month
  • not included: Fractional chief information security officerfrom $2,500 a month
  • not included: If you are breached, we investigate — monthly$670 a month
  • not included: Patient records kept protected+$40 per seat a month

Questions

How is this different from the scanner we already have?

A scanner lists symptoms. A person checks whether they add up to a way inside. Only what we managed to reproduce goes into the report, so it is short: you can start fixing straight away, without guessing which forty pages out of forty matter.

Will the test take our systems down?

Usually not. Techniques that can bring something down are used only with your separate permission. You choose the hours. You stay in touch with our engineer for the whole test: say stop and it stops within minutes.

Who fixes what you find, and what does that cost?

Whoever runs the system fixes it: your engineer, your developer or your vendor. The plan is written in order — what comes first, what comes next. If there is nobody to do it, we will: that is separate work by the hour, and we name the sum before we start.

Do we need a pen test if nobody has asked for one?

Then it is a question of order, not urgency. First close what has a date on it: the client questionnaire, the policy, the assessment. We say so in the first conversation, even when it pushes back our own work. The test will keep; the date will not move.

Where to send the quote

Tell us what we are testing and when you need the report — we will send a quote by email.

When to start
Who asks for a test, and in what form