A penetration test is a time-boxed engagement in which security professionals attempt to compromise your systems using the same techniques real attackers.
A penetration test is a scoped, time-limited engagement where security professionals attempt to find and exploit vulnerabilities in your product, infrastructure, or corporate environment — using the same techniques a real attacker would. Unlike automated scanners, pentesters bring adversarial creativity and chained-attack reasoning. Pentests are required or expected for SOC 2 Type II, HIPAA, PCI DSS, and any enterprise sales conversation past a certain deal size.
(1) Web application pentest — testers exercise your app as authenticated and unauthenticated users, looking for injection flaws, auth bypasses, IDOR, business logic issues. Most common for SaaS. (2) Network/infrastructure pentest — external and internal network testing, cloud misconfigurations, exposed services. (3) API pentest — dedicated focus on your public/private APIs, often with a spec (OpenAPI) provided. (4) Social engineering — phishing simulations, physical tests. (5) Red team — an unscoped, goal-oriented engagement ('exfiltrate customer data') across every attack surface. Most startups run #1 and #3 annually; add #2 when infrastructure grows; add #4/#5 at enterprise maturity.
Black box — testers know only what a public attacker would (usually the URL). Realistic but wastes tester time on reconnaissance. Gray box — testers get authenticated accounts across role types and light documentation. The standard for most engagements; best ROI. White box — testers get source code, architecture diagrams, and internal access. Highest finding depth, most tester time. Gray-box is the correct default for annual SOC 2-driving pentests; white-box makes sense for high-stakes greenfield systems or when you specifically want architecture review.
Firms vary widely. Boutique firms (NCC Group, Trail of Bits, Doyensec, IncludeSec, Latacora) — deep expertise, thoughtful reports, $30-100K per engagement, competitive schedules. Mid-market firms (Bishop Fox, Praetorian, GoSecure) — solid quality, faster availability, $20-60K. Pentest-as-a-service (HackerOne Pentest, Cobalt, Bugcrowd) — crowdsourced testers, faster kickoff, $10-30K, quality varies. Avoid the cheapest option — a report of low-severity findings from a tester who ran an automated scanner is worth less than nothing because it produces false confidence. Ask for sample reports before hiring.
A well-defined statement of work includes: exact URLs, IP ranges, and APIs in scope; testing dates and testing hours (avoid business-critical windows); allowed techniques and prohibited ones (no DoS, no social engineering unless separately scoped); testing accounts and how to obtain them; escalation contact if the tester finds something critical mid-engagement; deliverable format and timeline. Typical annual pentest: 1-2 weeks of testing, 1 week of report writing, kickoff to final report in 4-6 weeks. Budget 2-4 weeks of engineering time for remediation after.
A good report includes: executive summary for non-technical stakeholders, methodology, findings with severity (Critical/High/Medium/Low/Info), reproduction steps, business impact, and remediation guidance. Findings tracked in your normal issue tracker with a security label. Critical/High get fixed before the report is used in customer-facing conversations; Medium/Low get scheduled based on effort/impact. Publish an attestation letter (summary the firm signs stating scope and that testing was completed) — this is what enterprise procurement actually asks for. Retest after remediation for High/Critical findings; most firms include one retest round.
Investor directory · Fundraising library · Articles A–Z · Company funding database