BrickellTechnologies

Research

How much does a penetration test cost?

Elias Hasas · ·7 min read

Ask ten firms what a penetration test costs and ten will tell you it depends. That is true, and it is also a non-answer, and you are trying to build a budget.

So here is the mechanism instead. Once you understand what the number is made of, you can estimate your own before anyone quotes you, and you can tell which of two quotes is wrong.

The number is days

Almost every honest penetration test is priced the same way underneath: a senior person’s time, multiplied by how many days the work takes, plus a couple of days for the report.

That is the whole model. When a firm quotes you a flat price they have estimated the day count and multiplied. When one quotes suspiciously low, they have either estimated fewer days or assigned someone cheaper, and it is worth knowing which.

So the real question is not “what does a pentest cost.” It is “how many days does my scope take,” which is a question you can reason about.

What drives the day count

Roughly in order of impact.

How many distinct things are in scope. One web application is not the same job as one web application plus its mobile client plus the API they share. Each addition brings its own attack surface.

How many user roles the application has. This is the one clients underestimate most. Testing access control means testing every boundary between roles, and boundaries grow faster than roles do. Two roles is one relationship. Five roles is ten. Add multi-tenancy, where every customer is also a boundary, and it grows again.

Whether you provide credentials. Counterintuitively, credentialed testing usually costs less per unit of coverage, because we spend the time inside the application instead of at the front door.

How big the network is. Host counts matter, but less linearly than people expect. Four hundred hosts that are all the same image is closer to one host than to four hundred.

How much you want proven. There is a real difference between “tell us this is exploitable” and “chain it end to end and show us the data.” The second costs more and is sometimes worth it, particularly if you need to convince someone internally who does not believe you.

Retesting. Some firms include it, some bill it separately. Ask, because it changes the comparison. We include ninety days.

Rough day counts

These are our own scoping ranges for testing days, before report time. They are not quotes, and any of them can move once we know the specifics.

EngagementTesting days
Single web application, 2 to 3 roles5 to 8
External network perimeter3 to 6
Internal network and Active Directory6 to 12
Mobile app plus its backend7 to 10
Cloud posture review, single account4 to 8

Add two to three days for the report and the walkthrough. If somebody quotes you two days for an internal Active Directory assessment, they are selling you a scan.

What a suspiciously cheap quote actually means

There are only a few ways to make this work cost dramatically less, and none of them are efficiency.

Somebody runs a scanner and reformats the output. This is the common one. You can spot it in the deliverable: findings phrased in the scanner’s language, CVSS scores with no context about your environment, and no attack narrative anywhere. If the report never says “and then we used that to reach this,” nobody tried.

Or the work goes to a junior tester with a checklist, while the person you met on the call is on the next pitch. Not automatically bad, if there is real review behind it. Ask who is doing the work and what happens to their output.

Or the scope has been quietly cut. Read what the quote excludes as carefully as what it includes.

Questions worth asking any firm

  • Who specifically will do the testing, and can I talk to them before I sign?
  • How much of this is manual, and what do you use tools for?
  • What does the deliverable look like? Ask for a redacted sample. A firm that will not show you one is telling you something.
  • Is retesting included, and for how long?
  • What happens if you find something critical on day one?
  • Will you talk to my engineers directly, or does everything route through an account manager?

That last one predicts the experience better than almost anything else on the list.

The thing that actually wastes money

Not overpaying. Buying the wrong engagement.

Plenty of companies buy a penetration test when what they needed was a vulnerability assessment, because a customer used the words “pen test” in an email. If you do not know what is running or how out of date it is, a deep test of one application answers a question you did not have. Breadth first, depth second, in that order.

The reverse also happens: a scan gets bought when the actual question is whether the application’s authorisation logic holds up, which no scanner will ever tell you.

We would rather talk you into the smaller engagement and be right than sell you the bigger one and be forgettable. If you describe what you are running and what is driving the date, we will tell you which one you need, including when the answer is neither yet.

That conversation is free and takes about half an hour. Ask for one.

Know what an attacker would reach first.

Tell us what you run and what worries you. We will come back with a scope, a fixed price and the earliest week we can start.