5 ms·
Those prices might stand up for contractors -- but are a bit low to bring in a commercial outfit, at least for any of the larger reputable security consulting b
by splynch 6y ago
Those prices might stand up for contractors -- but are a bit low to bring in a commercial outfit, at least for any of the larger reputable security consulting businesses. Would suggest starting prices would be closer to £1000 a day. And rates are significantly higher in the US.
Accountability and consistency is a real concern in crowdsourcing. There is a reason we dont spend too much time designing an idea and then crowdsourcing all development. Why would security be different?
- morrbo 6y agoThe crowd sourcing stuff that I've seen comes in two different formats usually. There is the one where you put your URLs/IPs up there a d say "this is in scope"and someone finds something wrong, you pay them (ie. Someone says this has xss, you pay them a few hundred dollars) which has relatively little risk in terms of you only pay for what you get. The other ones are where you'd be allocated a test which then gets shipped out to some consultant anywhere in the world. I agree these are more risky (as you pay a flat rate). These are the ones I was hinting at that my friends moonlight on,but you do need some proof of technical ability and have to take a fairly decent entrance exam to participate in which (from what I've heard) hasn't been subject to the rampant cheating/"preparation" that other UK based aptitude tests/things like OSCP have. I'd personally go to a reputable vendor and ask for a senior consultant, but it's definitely a viable alternative especially if money is tight. Disagree about the pricing though, 750 (excl VAT) a day for external testing is pretty reasonable these days even for big vendors. App testing though, yeah, the prices can easily push 1k+ depending on what it is.
- raesene9 6y agoInteresting how little pentest rates have moved on in the UK in the last 20 years. I was a customer of big UK testing companies back then and rates were around that already, so there's been effectively no increase there in that timeframe, if you're still getting work at the £750-£1000 range.
- morrbo 6y agoYep, more competition, more knowledge and more efficiency is meaning that you can't really push big prices unless you're either going for a massive company (I've seen my day rate as high as 1800 before for doing relatively generic work for gov organizations). When I first started contracting we were replacing a big-4 consulting firm charging 3200/day for some stuff (!) For a UK insurance comoany. Alternatively as I mentioned if you're doing specialist work (code review, hardware, some forms of SE, mainframe testing) you can definitely push the numbers up depending on the client. I have friends still working at several of the larger companies and the day rates really around about 8-900/day on average but they just supplement it by tacking an extra day on whenever they can. All depends on the customer and the sales guy tbh. On average I'd even say that my day rate went down compared with 10 odd years ago - when you needed an interview at GCHQ to get CHECK - as there were just few people doing it whereas there are loads now.
- ramimac 6y agoJust for reference, the former example you give is just a bug bounty as far as I can tell. The discussion of relative merit of bug bounty versus a pentest is well trod ground, so I won't rehash here except to say I would never consider a bug bounty replacement for a pentest, and if you're asked for a pentest report as part of third-party vetting etc. many organizations will be concerned to see a bug bounty program compiled report. The latter example sounds like https://cobalt.io/ https://cobalt.io/. I've seen several reports and all I can say is if I were vetting a third-party or otherwise looking for assurance of security posture I would still want to see a "real" pentest from a reputable firm.
- splynch 6y agowas going to say similar things. A bug bounty has value -- and its effectively to incentivise someone who finds a vulnerability to tell you, rather than exploit it or sell it to someone who will exploit it. Its the same as a pen test. I dont want to name companies and start a war, but the industry is moving in a dangerous direction with some of the other options -- there are companies offering pen testing where those companies have no full time employees. They post the scope, and their registered users can sign in, take the work, and deliver it. Quality is all over the place. And things like confidentiality, data processing, etc, and any way to confirm a corporate entity adheres to their contractual obligations? Nonexistent.