6 ms·
I'm a cyber security specialist (in web application security) with a few certifications and 10+ years of experience. I charge usually $350 an hour unless it's
by bubblehack3r 4y ago
I'm a cyber security specialist (in web application security) with a few certifications and 10+ years of experience.
I charge usually $350 an hour unless it's something I estimate will require the help of an outsider to which I may go as high at $1k an hour.
Answering everyone asking how we find clients - I love public speaking and so I try to do as much as I can. 80% of my clients saw me speak, the other 20% come from word to mouth. Highly recommend if you have the ability.
- PaulWaldman 4y agoHow long are your engagements?
- bubblehack3r 4y agoThey can go anywhere from one hour (e.g awareness training) to a full month (e.g complex web application pentest)
- PaulWaldman 4y agoIronically, I've found it's easier to charge higher rates for longer engagements.
- bubblehack3r 4y agoAlthough I charge a flat fee, I've found that companies tend to be more accepting to my pricing when it's a longer engagement than a shorter one
- orzig 4y agoYeah, the fixed “cost“ (in effort) of bringing someone in can totally dominate the financial cost for smaller engagements. Especially when a manager is spending their large company’s dollars.
- ryanSrich 4y agoI’ve seen some companies charge very little ($2-$5k) for a pen test. How are you able to charge $350/hour for essentially the same work? Is there some pitch or playbook you’re using to justify the price for doing the same work?
- cratermoon 4y agoA $5K is pentest is just some guy running a couple of off-the-shelf, open source, or scriptkiddie tools and handing you the reports. For $350/hr you get - someone knowing which pentest tools to start with - someone knowing how to follow up with more focused attention on problem areas and run additional tests - someone analyzing the raw reports to understand the causes of the vulnerabilities - a multi-page written formal report with interpretations and recommendations for mitigation, including a cost/risk/benefit summaries. Edit to add: in my experience the companies offering cheap pentests and handing you the logs are the ones that then say, "If you want to understand these logs and know what to do about them, you can contract with us at $VERY_HIGH_RATE"
- folmar 4y agoI've seen a couple of the cheap pen tests by a few German companies. The whole thing looked like a 1-2 days of work and the person doing it was doing the basic stuff, but definitely conducted by a knowledgeable person and when problems were found reasonable suggestions were offered in the report. The apps were standard - frontend in Angular, backend in Spring Boot on Tomcat. basic DoS, XSS, SQLi, token abuse, open ports with not up to date services, generic vulnerability scanner, basic password brute forcing
- madaxe_again 4y agoMan. I (CISSP, CISA), 20 years of experience, everything from development to dev management to sales and marketing to finance to fundraising, the whole shebang, do ISO27001 ISMS’s and coach through certifications… for $70/hr. But then, my clients are based in the U.K., where technology is still generally seen as worthless.
- jll29 4y agoThat's what a (Master-level) plumber charges per hour in Germany. By offering such discounted rates, people consider you 'less valuable' a priori. I have indeed heard anti-"IT" sentiments in the UK, where managers often come from outside disciplines (e.g. "politics, philosophy and economics" type of oxbridge degrees). Some of these people adjust quickly and pick up technical skills naturally, whereas others couldn't insert a 9 V block battery into a toy without a YouTube video after a decade of "IT" exposure. But they also do not know what something is worth without a clear explanation, so your value is bound by your ability to articulate it.
- madaxe_again 4y agoFair. Thank you. You’ve just inspired me to fire off a round of emails announcing a 500% rate increase, listing the pretty significant accomplishments I have achieved for each client, and underlining the point that their businesses would likely not exist were it not for my support over the many years I have worked with them. I don’t exaggerate - many of them would never have got off the ground without me dragging them through the startup thorns and driving their first few years of technical sales. Either they’ll like it, or I’ll just quit technology, as the resentment just keeps growing.
- dsr_ 4y agoIf you scare off 80% of your recurring clients, you've drastically lowered your workload without penalty. If you scare off just 50% of your recurring clients, you've halved your workload and are making more money. The downside is if you scare off more than 80% of your recurring clients.
- doctorhandshake 4y agoForgive me if this is obvious but how do you get speaking opportunities? Are you applying to calls for presentations at conferences?
- bubblehack3r 4y agoI take part in local meetups who are always looking for speakers and apply to CFP.
- orzig 4y agoEvery technical meetup group I have been involved with his perennially desperate for speakers. If you make the effort to be present both physically and virtually for about three meet up groups over the course of about three months, I think it’s very likely you could get slotted in to speak by month 6. It’s possible they would add you on as a moderator for the group, guaranteeing persistent visibility if you are willing to put in the work (assuming you are a honest and decent person, this is a win-win because these communities have a huge positive externalities)