"While the cost of penetration testing can be pretty high (typically between $1,000 and $100,000+)," I've always been curious about costs for real pentesting. 1-100k is a HUGE range, that can't mean the range in cost for the same project can be that big, can it? What's it cost to hire someone to run a decent set of tests on a Rails app, for instance? Could I really see that big of a range? Would I get way better resu…
Penetration testing and low-cost freelancing
21–30 of 76 posts
Re: Penetration testing and low-cost freelancing
#22The results are useless without a control.
Re: Penetration testing and low-cost freelancing
#23People are paying pentesters because their payer’s policy asks them to. Of course there will be a huge market for someone with an alleged certification to run automated tools, the value is in the box checking and report generation, not the bespoke broken website fixing.
In every org I've sat down with the head to explain those risks, I can see how it can be made priority and budget.
Re: Penetration testing and low-cost freelancing
#24Re: Penetration testing and low-cost freelancing
#25"While the cost of penetration testing can be pretty high (typically between $1,000 and $100,000+)," I've always been curious about costs for real pentesting. 1-100k is a HUGE range, that can't mean the range in cost for the same project can be that big, can it? What's it cost to hire someone to run a decent set of tests on a Rails app, for instance? Could I really see that big of a range? Would I get way better resu…
You should get significantly better results the more one pays - because of the human element.
For example, $1k gets you a basic Nessus/Nmap (basic vulnerability/mapping) scans, maybe SQL vuln, with automated reporting. More gets you architecture, infrastructure, penetration, white/black scenarios, risk assessment, external organization liability, code repo, data, compliance, and regulatory footing. Those can surpass $100k easily.
Re: Penetration testing and low-cost freelancing
#26Clickbait title. I refuse to click.
Re: Penetration testing and low-cost freelancing
#27Re: Penetration testing and low-cost freelancing
#28Re: Penetration testing and low-cost freelancing
#29The same is happening in the "smart contract audit" space. The results of the audit do not matter to the audience that wants to see the checkbox of "audit".
You can currently make a lot of money undercutting other auditors providing these audits.
The person requesting the audit is making multiple orders of magnitude more money by having the audit.
Re: Penetration testing and low-cost freelancing
#30Number 3 wil surprise you!