5 ms·
Pentester for 10 odd years: usually for an external test you would scope it at X days depending on the number of IPs etc. And it should note that an external te
by morrbo 6y ago
Pentester for 10 odd years: usually for an external test you would scope it at X days depending on the number of IPs etc. And it should note that an external test really doesn't find much. External is usually £750/day for 1-2 days testing and one reporting. Internal testing (ie. Auditing a domain and all computers attached) is about the same price, maybe a bit more, and takes a bit longer usually. A build review is hardening the server itself, takes about a day and a day reporting. App testing is totally dependent on the app itself (this is where people have a crack at an actual installed web application usually using user accounts etc. And runs a bit more - £800+ per day usually. Specialist stuff (hardware testing, code review (what I used to do), social engineering, hardcore app testing (stuff like auditing bespoke network devices, high frequency trading apps, etc. Etc.)) is typically 1-1.2k a day.
You can get it cheaper but a lot of it - for better or for worse - really comes down to the skill of the individual consultant. You can pretty much halve these prices, but then you'd end up getting stuff outsourced to India and it wouldn't be any good. Depends if you care about the security of your product or just want a box ticked for some arbitrary compliance and want it done as cheap as possible.
I haven't been a tester/consultant for a few years now, but the prices hold up. That being said one development which has happened since I've left the industry is the advent of crowd sourced pentesting. I know a lot of friends who moonlight with these things and are very good at their jobs, and the rates are lower. The name crowd strike comes to mind, but I'm not 100% sure if that was the company or not. I know a lot of good UK based companies (if it's a web app/remote then the physical testers location doesn't matter) if you needed.
- starfallg 6y agoYour comment really surprised me as I didn't expect that this was just a pen-test, but after visiting the link, indeed it was! I think it's a bit sneaky as for a product like this, people expect this to be a code and crypto audit. The "network" part should be emphasised and in the title of the page, instead of just the PDF.
- user5994461 6y agoIn this business the title "External Penetration Test and Vulnerability Assessment" means the auditing company has run qualys/nessus* against bitwarden.com. * expensive commercial vulnerability scanning tools.
- deleted 6y ago[deleted]
- splynch 6y agoThose prices might stand up for contractors -- but are a bit low to bring in a commercial outfit, at least for any of the larger reputable security consulting businesses. Would suggest starting prices would be closer to £1000 a day. And rates are significantly higher in the US. Accountability and consistency is a real concern in crowdsourcing. There is a reason we dont spend too much time designing an idea and then crowdsourcing all development. Why would security be different?
- morrbo 6y agoThe crowd sourcing stuff that I've seen comes in two different formats usually. There is the one where you put your URLs/IPs up there a d say "this is in scope"and someone finds something wrong, you pay them (ie. Someone says this has xss, you pay them a few hundred dollars) which has relatively little risk in terms of you only pay for what you get. The other ones are where you'd be allocated a test which then gets shipped out to some consultant anywhere in the world. I agree these are more risky (as you pay a flat rate). These are the ones I was hinting at that my friends moonlight on,but you do need some proof of technical ability and have to take a fairly decent entrance exam to participate in which (from what I've heard) hasn't been subject to the rampant cheating/"preparation" that other UK based aptitude tests/things like OSCP have. I'd personally go to a reputable vendor and ask for a senior consultant, but it's definitely a viable alternative especially if money is tight. Disagree about the pricing though, 750 (excl VAT) a day for external testing is pretty reasonable these days even for big vendors. App testing though, yeah, the prices can easily push 1k+ depending on what it is.
- raesene9 6y agoInteresting how little pentest rates have moved on in the UK in the last 20 years. I was a customer of big UK testing companies back then and rates were around that already, so there's been effectively no increase there in that timeframe, if you're still getting work at the £750-£1000 range.
- morrbo 6y agoYep, more competition, more knowledge and more efficiency is meaning that you can't really push big prices unless you're either going for a massive company (I've seen my day rate as high as 1800 before for doing relatively generic work for gov organizations). When I first started contracting we were replacing a big-4 consulting firm charging 3200/day for some stuff (!) For a UK insurance comoany. Alternatively as I mentioned if you're doing specialist work (code review, hardware, some forms of SE, mainframe testing) you can definitely push the numbers up depending on the client. I have friends still working at several of the larger companies and the day rates really around about 8-900/day on average but they just supplement it by tacking an extra day on whenever they can. All depends on the customer and the sales guy tbh. On average I'd even say that my day rate went down compared with 10 odd years ago - when you needed an interview at GCHQ to get CHECK - as there were just few people doing it whereas there are loads now.
- no-dr-onboard 6y agoAppsec pentester for 6 or so years: The 1-1.2k a day figure (GBP) is relatively low for 2020. I know you mentioned that i's been a while; just trying to shed some light. Boutique Firm X billed at 285/hr with an average of 60 hours for a small application. That comes out to $2,280 USD a day. Standard Small Consulting Firm Y billed at 250/hr. In the past 6 years I have yet to see anything below 235/hr, which is still $1880 USD/day (1479, GBP). Hope that helps, GP.
- raesene9 6y agoWorth noting that (IME) US day rates are a lot higher for pentest work :) your US rates sound similar to what I've seen but Morrbo's UK rates sound ballpark right for the UK (I'd have said a little higher but it does depend on the company and work)
- dogma1138 6y agoWhen I did pentesting for a consulting firm the daily rate was £2000-2500 (depending if we had to pay reverse VAT for non UK/SM clients, and some other factors) we worked with financial firms and software companies primarily, there for remote on-site would be the same + expenses. More bespoke services like proper red teaming, DDoS simulation IOT/connected cars/hardware were about double that. £800 a day is the very bottom of the price scale in the UK for general SME public sector companies.
- rtempaccount1 6y agoLet me guess, Big-4? boutiques in the UK don't usually charge that kind of day-rate and the big banks all use their purchasing power to get day rates down. £800/day is low, but not unheard of especially if you use freelancers/small boutiques, but £2k/days is more than I've seen for most things in the UK.
- dogma1138 6y agoNo, quite boutique but not a UK firm I was one of 5 in the UK office. We didn’t really deal with retail banks the banking clients would be investment and asset management banks like RaboBank.