What Does “Cheap” Penetration Testing Actually Buy?

Low-cost testing is not automatically bad. But a low price always buys something specific, and knowing what you are giving up is the difference between a bargain and paying twice.

Priced on
Day rate × scoped days
The real variable
Days, not rate
Biggest risk
Report fails the requirement
Scoping call
Free

Where a low price actually comes from

There are only four ways to make a penetration test cheaper, and they are not equally acceptable.

1. Lower overheads — legitimate

A small consultancy has no offices to fund, no account managers and no sales team. That is a genuine cost difference and it reaches you as a lower day rate without affecting the work. Our own rates sit below the large consultancies for exactly this reason.

2. Fewer days — legitimate, if you know

A three-day test costs less than a six-day test because it covers less. That is fine when the scope genuinely warrants three days, and a problem when a provider quotes three to win the work and then cannot cover what you needed. Always compare day counts, not totals.

3. Automation instead of testing — usually not acceptable

Running a vulnerability scanner and formatting the output takes a fraction of the time. It is also not a penetration test. It will not find broken access control, business logic flaws, or the chain of three minor issues that together give an attacker your database. Most compliance requirements that specify penetration testing will not accept it.

4. Junior staff — depends entirely on supervision

Large firms often sell senior expertise and staff with juniors, because that is how the economics work. Sometimes that is fine with proper review. Sometimes you are paying for someone learning on your systems.

When cheap is genuinely the right answer

We would rather say this plainly than pretend otherwise:

  • Small, contained scope. A brochure website with a contact form does not need six days. A short test is the correct answer, not a compromise.
  • You have already had a thorough test and want a lighter check after a specific change.
  • Your real need is Cyber Essentials. If a customer's requirement is satisfied by certification, a penetration test is an expensive way to answer the wrong question.
  • You have foundational gaps. If you have no multi-factor authentication, unsupported software in production or untested backups, spend the money fixing those. A test will confirm what you already suspect.

When cheap costs more

The failure mode is nearly always the same: the report has to satisfy somebody else.

A tender evaluator, a client's security reviewer, an auditor, an underwriter. If the report comes from an unaccredited provider, covers the wrong scope, or is visibly scanner output, it gets rejected. You then commission a second test under time pressure and pay twice — plus whatever the delay cost you.

That is the arithmetic that matters. A £1,200 test that fails the requirement is more expensive than a £3,000 test that passes it.

How to tell what you are being offered

Four questions that expose the difference quickly:

  • How many days of manual testing, excluding report writing? If the answer is vague, that is the answer.
  • Who is the named tester and what do they hold? "One of our qualified team" tells you something.
  • Can I see a redacted sample report? Any competent provider has one. Refusal is informative.
  • Is retesting included? Frequently excluded from a low quote and charged later at full rate.

Our pricing page explains what actually drives the day count, and how to compare providers covers this in more detail.

What we do about it

We quote on a call, for a defined scope, and hold the price. Retesting is included rather than sold later. And if a scoping conversation suggests you need less than you asked for — or something other than a penetration test entirely — we will tell you.

That is not generosity. A client who buys the wrong thing does not come back.

Common questions

Are you cheap?

Our day rates sit below the large consultancies because our overheads are lower, and the accredited tester does the work rather than a junior. We are not the cheapest quote you will find, and where someone is dramatically cheaper it is usually a scan rather than a test.

What is the least I can spend and get something useful?

A small, contained scope honestly tested. An external infrastructure test or a single straightforward web application is a genuinely useful engagement at the lower end. What does not work is a wide scope compressed into too few days.

Can I just get a vulnerability scan instead?

Sometimes, and we will tell you when. Scanning is cheap, fast and useful for finding missing patches across many machines. It is not a penetration test, it will not find logic flaws, and most compliance requirements that specify testing will not accept it.

A provider quoted half what you did. Should I be worried?

Look at the day count rather than the total, and ask what proportion is manual. Sometimes the cheaper quote is simply a smaller scope, which may be entirely appropriate. Sometimes it is automation with a report template. The four questions above will tell you which.

We genuinely cannot afford a full test. What should we do?

Tell us that. A narrower scope from an accredited provider is more defensible than a broad shallow one, and there may be a cheaper answer entirely — often Cyber Essentials. We would rather point you at the right thing than sell you the wrong one.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.