3 ms·
Speaking from a buyer's perspective (I've managed about three penetration tests) they costed around 10-15k per person week-ish. The cost can be adjusted depend
by codezero 5y ago
Speaking from a buyer's perspective (I've managed about three penetration tests) they costed around 10-15k per person week-ish.
The cost can be adjusted depending on how experienced the testers are, timing (I need it now vs I need it next month), and how much time they are expected to spend writing up executive reviews. We always opted to just get a list of vulns and passed on the executive reviews as they tended to take up at least a whole day or so of the budget.
You can also save a lot of time by having a really well prepared dev system set up and ready to go for them. Getting someone familiar with your setup while also trying to sort out VPN access, GitHub permissions, etc... costs time and money, so doing that ahead of the engagement saved me about a day of budget.
You can get things that are a lot cheaper, but that's usually just going to be a newly hired tester running burp suite or some other automated testing tool. It's still worthwhile to do though if you haven't, an OWASP top 10-20 automated scan may cost less than $5k but still can be helpful/insightful if you want to reduce your risk surface area.
- lucb1e 5y ago> I need it now vs I need it next month Is this figurative or do you really get a discount for planning it one month ahead where you're from? From my (n=2 employers) experience, projects are usually planned at least two months ahead (if it's not busy; end of year you can expect 4-5 months). The executive summary thing is also interesting. We take maybe 30 minutes at the end to sum up what we tested, which issues we found (particularly the impact in semi-layman's terms, depending on the impression we got from the contact person), and sometimes if there are big omissions from the scope that smell foul and someone (us or another company) really should still have a look at then we might remark that there as well. But we don't charge a day's rate for a short summary. I guess what you mean is more substantial than this?
- codezero 5y agoIt wasn't a negotiated line item, but more that we had a specific ask, and the agency we were engaged with had a particular expert available if we could wait > a month. This didn't directly affect the cost - which maybe I should have made more clear, but still affected what I think would be the value of the engagement. I guess I'm saying: be aware that you may pay the same for less if you are in a hurry, but it'll still be better than what you have without paying :) It's still my suggestion that if you know there's a specialist available, wait if you can and bring them in. For the summary: we always got the short summaries, list of vulns, recommended remediation. Tbh - I never paid for the exec summary, but my guess is that it was just taking all that stuff, spiffing it up into a PDF with clickable sections, and making it a lot more flowery? It sounded like something more desired by larger enterprise companies (maybe like this blog post!) than small ones like the one that I managed these engagements for.