- Priced on
- Day rate × scoped days
- The real variable
- Days, not rate
- Biggest risk
- Report fails the requirement
- Scoping call
- Free
Where a low price actually comes from
There are only four ways to make a penetration test cheaper, and they are not equally acceptable.
1. Lower overheads — legitimate
A small consultancy has no offices to fund, no account managers and no sales team. That is a genuine cost difference and it reaches you as a lower day rate without affecting the work. Our own rates sit below the large consultancies for exactly this reason.
2. Fewer days — legitimate, if you know
A three-day test costs less than a six-day test because it covers less. That is fine when the scope genuinely warrants three days, and a problem when a provider quotes three to win the work and then cannot cover what you needed. Always compare day counts, not totals.
3. Automation instead of testing — usually not acceptable
Running a vulnerability scanner and formatting the output takes a fraction of the time. It is also not a penetration test. It will not find broken access control, business logic flaws, or the chain of three minor issues that together give an attacker your database. Most compliance requirements that specify penetration testing will not accept it.
4. Junior staff — depends entirely on supervision
Large firms often sell senior expertise and staff with juniors, because that is how the economics work. Sometimes that is fine with proper review. Sometimes you are paying for someone learning on your systems.
When cheap is genuinely the right answer
We would rather say this plainly than pretend otherwise:
- Small, contained scope. A brochure website with a contact form does not need six days. A short test is the correct answer, not a compromise.
- You have already had a thorough test and want a lighter check after a specific change.
- Your real need is Cyber Essentials. If a customer's requirement is satisfied by certification, a penetration test is an expensive way to answer the wrong question.
- You have foundational gaps. If you have no multi-factor authentication, unsupported software in production or untested backups, spend the money fixing those. A test will confirm what you already suspect.
When cheap costs more
The failure mode is nearly always the same: the report has to satisfy somebody else.
A tender evaluator, a client's security reviewer, an auditor, an underwriter. If the report comes from an unaccredited provider, covers the wrong scope, or is visibly scanner output, it gets rejected. You then commission a second test under time pressure and pay twice — plus whatever the delay cost you.
That is the arithmetic that matters. A £1,200 test that fails the requirement is more expensive than a £3,000 test that passes it.
How to tell what you are being offered
Four questions that expose the difference quickly:
- How many days of manual testing, excluding report writing? If the answer is vague, that is the answer.
- Who is the named tester and what do they hold? "One of our qualified team" tells you something.
- Can I see a redacted sample report? Any competent provider has one. Refusal is informative.
- Is retesting included? Frequently excluded from a low quote and charged later at full rate.
Our pricing page explains what actually drives the day count, and how to compare providers covers this in more detail.
What we do about it
We quote on a call, for a defined scope, and hold the price. Retesting is included rather than sold later. And if a scoping conversation suggests you need less than you asked for — or something other than a penetration test entirely — we will tell you.
That is not generosity. A client who buys the wrong thing does not come back.
Common questions
Are you cheap?
Our day rates sit below the large consultancies because our overheads are lower, and the accredited tester does the work rather than a junior. We are not the cheapest quote you will find, and where someone is dramatically cheaper it is usually a scan rather than a test.
What is the least I can spend and get something useful?
A small, contained scope honestly tested. An external infrastructure test or a single straightforward web application is a genuinely useful engagement at the lower end. What does not work is a wide scope compressed into too few days.
Can I just get a vulnerability scan instead?
Sometimes, and we will tell you when. Scanning is cheap, fast and useful for finding missing patches across many machines. It is not a penetration test, it will not find logic flaws, and most compliance requirements that specify testing will not accept it.
A provider quoted half what you did. Should I be worried?
Look at the day count rather than the total, and ask what proportion is manual. Sometimes the cheaper quote is simply a smaller scope, which may be entirely appropriate. Sometimes it is automation with a report template. The four questions above will tell you which.
We genuinely cannot afford a full test. What should we do?
Tell us that. A narrower scope from an accredited provider is more defensible than a broad shallow one, and there may be a cheaper answer entirely — often Cyber Essentials. We would rather point you at the right thing than sell you the wrong one.
Related
Solusec
Typically replies within one business day
Hi 👋 Need a hand with pen testing, Cyber Essentials, or something urgent? Pick whichever suits you:
💬 WhatsApp usQuick questions, quick answers 📞 Call us
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day