-
We received a Penetration Test proposal that was quoted significantly lower than other proposals we received – why is that?2014-10-14
-
The most costly component of any true penetration testing engagement is the experienced security engineer - their time spent performing manual penetration testing. {SITE_NAME} leverages our experienced US penetration testing team for every engagement, and due to our streamlined and cost effective processes, we're able to provide aggressive pricing for our customers. We may not be your lowest cost provider of penetration testing, but we are absolutely confident that we are delivering comprehensive and thorough results.
Currently, there is no recognized "standard" for penetration testing, and the quality varies dramatically. Some vendors offer automated scans call it a penetration test. Others offer an automated scan with a manual review of the scan results and call it a penetration test. Still others will opt to outsource their security engineer work to the lowest cost bidder with offshore resources.
If your goal is to satisfy a compliance mandate, this type of testing can be rejected by auditors and lead to numerous and expensive rounds of repeat testing. If you seek to satisfy an important potential client, the client may want details about quality of the testing, and may legitimately reject these methods. Finally, if your purpose in testing is to secure your organization, these superficial methods of testing are only marginally better than vulnerability scans and can lead to an inaccurate belief in the security of your systems.
If you are pursuing penetration testing to satisfy compliance mandates, {SITE_NAME} will insure that the testing meets compliance requirements. For your potential or existing clients, we can provide client facing reports that include details about the scope and breadth of testing, but will not include sensitive details of the testing engagement results. If your purpose is improvement of your organizational security, we provide testing that thoroughly covers network, system and application layers, addressing the latest security threats.