Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 39 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
How much cost a Pentest?
EH-Net
May 24, 2013, 08:02:20 AM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
How much cost a Pentest?
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: How much cost a Pentest? (Read 12154 times)
0 Members and 1 Guest are viewing this topic.
H1t M0nk3y
Hero Member
Offline
Posts: 865
How much cost a Pentest?
«
on:
March 16, 2010, 06:57:00 AM »
Hey,
I am still quite new to the security field and someone asked me yesterday the question: "How much cost a pentest?". Althought the answer to this question is obviously "it depends", I realized I couldn't even answer with a price range.
In addition, I was recently listening to a pentest security course and the teacher frequently mentioned that there are 2 kinds of pentesters: those who run Nessus and give the report they got and those who
do it properly
. So the following questions relate to a quality pentest, not just running a tool and printing the report.
For these 3 scenarios, what would be the effort (number of people, time) and the cost for a good test? I didn't give more details about these companies because we always have to give a price range without knowing much...
1) Small company of 10 employees.
2) A mid-size company of 100 employees.
3) A large company of 2000 employees.
My very humble rookie guess would be:
1) 1 person, 5 days, $2500
2) 2 people, 7 days, $7000
3) 4 people, 20 days, $40000
How far off am I?
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
j0rDy
Hero Member
Offline
Posts: 590
Re: How much cost a Pentest?
«
Reply #1 on:
March 16, 2010, 08:36:44 AM »
the variables are not the size of the company and number of employees. its about number of active hosts with number of active/running applications. the second part you got almost right: what if i do the first one with 5 employees and complete it in 1 day?
i'd do it like this (for an external scan):
number of servers/systems
this may vary from 1 to about 10(?), if it gets any bigger id do a pilot on a set of servers that are representative for the whole infrastructure.
number of active/running services
this may also vary a lot. if there is one active service (dedicated mail server for example) it takes a lot less effort to thorough scan the server. this however should be tested completely for vulnerabilities. what about custom build applications? do they require code review?
number of resources
how many people do you put on the job? this one goes with the next one:
number of days
how fast does the pentest have to be completed? this factor influences the resources factor.
there are a lot of other factors that influence the outcome of a price for a penetration test. i sure cant give you an accurate guess...anybody else?
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
Dutchie
Newbie
Offline
Posts: 33
Re: How much cost a Pentest?
«
Reply #2 on:
March 16, 2010, 09:02:12 AM »
At the EC-Council website
http://www.eccouncil.org/certification/certified_ethical_hacker.aspx
I found this information concerning an indication of costs:
10. I would like to provide professional service as a CEH professional. What can I expect to be paid per assignment?
The remuneration per assignment will vary with specifics of the client environment. However, on an average you can expect to be paid around $15,000 to $ 45,000 per assignment.
I do not know in how realistic this information is but there is an big gap with your guess!!! For consultancy work a fee of $500 a day isn't that "high".
Logged
RA, CISA, CISSP, C|EH, C|HFI, CWSP, LPIC-1
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: How much cost a Pentest?
«
Reply #3 on:
March 16, 2010, 09:18:09 AM »
Thanks for your answers.
Quote
a pilot on a set of servers
That makes so much sense to reduce costs.
Quote
what if i do the first one with 5 employees and complete it in 1 day
Unless there is a real emergency for a pentest, I would think the client will find it "too easy" if things can get done in 1 or 2 days. Also, it may be hard to bill $3000/day for pentesting. Regardless if the contract is per diem or per assignment, the client will do the math. Don't you think?
Quote
on an average you can expect to be paid around $15,000 to $ 45,000 per assignment.
I read it too when I did my CEH, but it doesn't say much...
Anyone else have already done pentesting for a company?
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
former33t
Full Member
Offline
Posts: 226
Re: How much cost a Pentest?
«
Reply #4 on:
March 17, 2010, 08:36:13 PM »
You mention the client doing the math even if the job is per assignment...
I have been in this situation as well and have to let the client know that I have experience in and licenses for specialized software their staff does not. This is a huge factor in the cost.
One thing that helps on a contract job is to get the client to allow a scope of internal/external testing that varies over a couple of weeks. One person I know intentionally overlaps pentest clients (when work is plentiful). Inevitably, while a pentest is going on, every IT problem is blamed on the test (even if only one or two people know about it). He says he lets them call a couple of times about "problems he's caused" before he's ever probed the network. He says it helps settle the client down before he actually touches anything. Claims he's still doing company fingerprinting during that time (and he may actually be, but most of the time he's finishing reports from a prior test).
This helps to:
1. Prevent the client from thinking you can do it all in one day.
2. Prevent the client from blaming perceived IT problems on the pentest.
Hope this makes sense/helps. As far as cost goes, the cost depends most on the scope of the test. A test that includes internal code review as opposed to simply fuzzing a web server will obviously cost more. The second important factor (particularly in the current economy) is what match of test scope (value) to price ratio makes sense for the company. Unless the company has specific compliance issues to address, you can sell the need for the most comprehensive test available (and they can believe the need 100%) but they won't bite if it doesn't make financial sense.
Logged
Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: How much cost a Pentest?
«
Reply #5 on:
March 18, 2010, 06:42:02 PM »
Wow, thanks former33t, you definitively bring a different perspective! But since no one can answer my very vague question, here is another one:
As a contractor, how much can an expert pentester charge per day?
As a comparison, in my web application world, a system architect on a contract with 7 to 10 years of experience will get around $675/day.
How this compare to a very good pentester? My feeling is the pentester needs to know more things than a system architect and therefore, should get more $$.
What do you guys think?
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
former33t
Full Member
Offline
Posts: 226
Re: How much cost a Pentest?
«
Reply #6 on:
March 18, 2010, 10:16:33 PM »
That's a tough question to answer. I'd say a truly expert contract pen tester could draw in that much or more per day with no problem, but you are really comparing apples and oranges.
In my experience, when we hire a DB programmer or systems engineer it is to complete tasks on some project we are working. The contract workers give some estimate of time expected to complete, but actual completion time depends on a number of factors that might not be clear until they actually start the project.
When you negotiate a pentest, you have negotiated to complete a specific scope of work (test X services on X servers, etc). I have never been engaged in an open ended penetration test. The penetration test is normally billed on a project basis, not an hourly or daily basis.
To put a price on it though, I would have no problem charging (or paying, if I needed to) $500-1000 per day to a contractor for expert penetration testing services. In my experience, anything under $80/hr is a deal for expert contracting services, $100-120 is about average, and anything more than $150 had better bring something darn special to the table.
That being said, I view a pentest much more like outsourcing a module of code to be written. I spec out what needs to be written, a contractor submits a bid, I hire, pay, and get the code. I don't care how many man hours it takes for them to do it (as long as it is delivered on the agreed upon schedule).
Logged
Certifications: CREA, MCSE: Security, CCNA, Security+, other junk
j0rDy
Hero Member
Offline
Posts: 590
Re: How much cost a Pentest?
«
Reply #7 on:
March 19, 2010, 03:57:20 AM »
i see that a little different. its true you have to have more knowledge about security/tools/methods then testers in other fields, but thats just part of the game. i dont see that as a reason to pay somebody more. thats like paying a garbage man per kilo of garbage he has picked up. if one is on a route that has more garbage, he shouldnt get paid more. a garbage man is a garbage man, just like a security/penetration tester is the same as a application tester.
on price thats just a different story. it depends on things like offer and demand. but when i look at the prices mentioned here i think thats pretty accurate (even though its more like a 1000$ then 500$).
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: How much cost a Pentest?
«
Reply #8 on:
March 19, 2010, 06:33:04 AM »
Thanks again for your answers.
What I meant by:
Quote
the pentester needs to know more things than a system architect and therefore, should get more $$
Is the more things you have to know in order to perform a given job, the more difficult it is to find a person like that. In other words, the offer becomes lower and lower. Therefore, salary tend to rise a bit.
But thank you for your answers!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
j0rDy
Hero Member
Offline
Posts: 590
Re: How much cost a Pentest?
«
Reply #9 on:
March 21, 2010, 04:15:58 AM »
Quote from: H1t M0nk3y on March 19, 2010, 06:33:04 AM
Thanks again for your answers.
What I meant by:
Quote
the pentester needs to know more things than a system architect and therefore, should get more $$
Is the more things you have to know in order to perform a given job, the more difficult it is to find a person like that. In other words, the offer becomes lower and lower. Therefore, salary tend to rise a bit.
But thank you for your answers!
if thats the case then its true. like i said its a offer and demand thing. so when they ask a little more, they should get it.
Logged
ISC2 Associate, CEH, ECSA, OSCP, OSWP
earning my stripes appears to be a road i must travel alone...with a little help of EH.net
hayabusa
Hero Member
Offline
Posts: 1633
Re: How much cost a Pentest?
«
Reply #10 on:
March 21, 2010, 07:36:10 AM »
I'm coming in late, to this one, as work's been crazy busy this past week... that said -
There are too many variables to give a 'flat rate,' at least if you're a smaller shop, doing this type of work. Companies like Core are coming around, and offering some very nice prices for smaller gigs, and you really need to be able to compete, so you'll need to look at the market in your area, scope of the test, the depth of products / services you need to evaluate in the test, the number of machines, the time involved, etc. You need to intelligently come up with some pricing that takes EACH of these into account, and have a price schedule you can work from, accordingly, to determine the cost of any given engagement. I can't count on both hands and feet the number of engagements, in the last year, where I've custom quoted pricing (and gotten the engagement over other firms) because I've been more flexible, and not come with a set price.
Logged
~ hayabusa ~
"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'
OSCE, OSCP , GPEN, C|EH
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: How much cost a Pentest?
«
Reply #11 on:
March 22, 2010, 06:44:35 AM »
I am not ready to do pentests now. In a couple of years, if things go well, I know enough to do a good job (hopefully!!!).
Other then trying very hard to get experience by working with established professionals, when I will start, I will probably ask a bit less then all the others in order to build my name...
I currently own a company, but I am more in web development than anything else right now. But I do know how a business works. I will try to start doing partnership or work for another company just to see how this pentest business works.
Anyway, as i said, I still have a few years ahead of me and I know that patience is gold!
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(8) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
Greetings
: Hi from the UK
(4) by
MrTuxracer
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.