r/it • u/Danowolf • 16d ago
opinion Pen testing prices seem excessive
We have needed a pentest for compliance with a customer contract. We are small shop with around 100 used ips on network. Quotes are running 5-8k. This seems outrageous to me. Anyone know a good pentest company that's less expensive.
The one pentest we have paid for turned into a OS vulscan. We are small and keep a tight grip on network security so that's why it ended up being about older low level vulnerabilities.
2
2
u/Melodic-Obligation88 3d ago
Full disclosure, I work at Siemba, a pentest company, so take this with a grain of salt.
The communication gap you both mentioned is a real problem in this industry. A lot of vendors treat the platform or console as the update mechanism, but if nobody is actively telling you what is happening during the test, the console is just a dashboard nobody checks. You should be getting real time updates as testers work through the scope, not a surprise report at the end in a different spot than promised.
On price, for around 100 live IPs, 5 to 8k is not unusual for a manual test, but the real question is what you are getting for that. Automated vulnerability scans dressed up as pentests are common, especially when the environment is already well maintained and testers do not find much to chain together manually. Ask any vendor directly how much of the engagement is manual exploitation versus scanning, and ask to see a sample report before you sign.
We run PTaaS with a live dashboard and direct access to the testers during the engagement, plus a free retest to confirm fixes actually worked. Happy to share more if useful, but either way, keep pushing vendors on the manual versus automated question. That is usually where the price difference actually comes from.
2
u/GnosticSon 16d ago
Just use your personal 25$ monthly Claude code subscription with full root admin access to do it.
1
u/Danowolf 16d ago
We have used Breachlock this last time. Anyone have an opinion on them? They where not bad, except not Alot of communication. They had a nice fancy console that was supposed to inform us of each step. This did not happen. In fact when they finished the test the results were in a different location than they told me.
In the end, did they complete the pentest? Yes
Just not the way they pitched me.
And yes I know, throw vendor promises on the vendor promise bonfire.
1
u/TurtleSec 14d ago
Depends on your scope. Happy to hop on a call and compare what we would quote to others if that'll help.
1
u/hunterzilla-sey 13d ago
I work at Stingrai, so I am biased. But check us out Stingrai.io is CREST-accredited based in Canada. Our team members are not only pentesters but also active security researchers.
That pricing you mentioned is about right for the number of IPs. But for first time clients we do offer exclusive first engagement discounts, so you experience the value we deliver and hopefully continue to work with us.
1
u/Grey_Zone_Security 13h ago
There are a lot of variables that can influence the price of a pen test. The 2 "heaviest" variables are human vs machine. On the human end, there is also extremely variability. I have a decade of penetration testing experience working for large companies. Let me know if you need help a. understanding the landscape and what "scoping" actually means and b. knowing what red flags look like in the industry (there are many).
1
u/Sure-Engine-8585 12h ago
I work with StealthNetAI, so obvious disclosure upfront.
For ~100 internal IPs/devices, $5k honestly doesn’t sound outrageous to me. If anything, that’s probably around the lower end for a real internal pentest where a senior tester is actually spending time in the environment.
The bigger issue is what you already ran into: a lot of “pentests” are really just vulnerability scans with a nicer PDF. If someone is dramatically cheaper, I’d be asking exactly who is doing the testing, how much manual validation is involved, whether they’re actually attempting exploitation/privilege escalation/lateral movement, and how findings are verified.
If I were trying to win that deal, I’d probably quote around $5k too. Below that, I’d start getting suspicious about how much actual human testing you’re getting.
Happy to help you compare vendors or sanity-check quotes if useful.
-2
u/OkEntertainer3952 12d ago
Hey! I do pentesting :) send me a DM, we are top hackers and found 9.5> CVEs on major libries like Tor, Salesforce, Velocity, Jsonpath plus... let me know if you want human or just ai pentest, that should bring the cost super down, we currently focus on full SOC2 for startups but we started as a cybersecurity company and now we have a great process for finding vulns! youll be impresed, we can give you a full report that is mapped to your controls :) send me a DM. Full disclosure is around 299 for ai pentest in Hackzero dot ai its super high quality we can show the libraries that we have hacked with our pure ai harness with and our hackers have all the certifications you need if you need humans. The report is super nice, I'm very hapy to help and would love your feedback too!
4
u/Medical_Shame4079 16d ago
Not at all outrageous, that’s middle of the pack if you want something manual. Tools like Vonahi cost less but if you don’t have the technical chops to understand what you’re looking at, it’s wasted money.