• Events & Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
  • Events & Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
HBS logo
HBS Logo
  • Infrastructure
    • CLOUD

      • Cloud Solutions
      • Public Cloud
      • Hybrid Cloud
      • Infrastructure as a Service
      • Cloud Security Solutions
      • Backup, Replication and Disaster Recovery
      • HBS Cloud Hosting Services

      DATA CENTER

      • Data Center Solutions
      • Traditional Data Center
      • Hyperconverged
      • Colocation
      • Directory Services
      • Cloud Email and Calendar Solutions

      NETWORK AND ACCESS

      • Network Infrastructure
      • Enterprise Mobility
      • Wireless Solutions
      • SD-WAN
      • Structured Cabling
      • Staff Augmentation
  • Managed Services
    • MANAGED ONE

      • Managed One Overview
      • Managed Backup and Disaster Recovery
      • Managed Firewall
      • Managed SaaS Security

       

      • Managed HaaS and SaaS
      • Managed IT Help Desk
      • Managed Network and Server Monitoring
      • Managed Email and Collaboration Security

      HBS + PARTNER SOLUTIONS

      • HBS Secure with Verkada
      • HBS Collaborate with Webex
      • Managed XDR
      HBS Managed One Megamenu Graphic
  • Modern Workplace
    • MICROSOFT

      • Microsoft Licensing Management
      • Microsoft Modern Workplace
      • Microsoft Fabric

       

      • Dynamics 365 Business Central
      • Dynamics 365
      • Dynamics GP

      COLLABORATION

      • Audio Visual
      • Unified Communication Solutions
      • HBS Collaborate with Webex
  • Professional Services
    • ADVISORY

      • Virtual CISO
      • Virtual CIO
      • Project Management
      • IT Business Consulting

      ENGINEERING SERVICES

      • Staff Augmentation

      AI & ANALYTICS

      • Artificial Intelligence
      • AI Advance
      • AI Predict
      • AI Assist
      • Data Management and Analytics
      • Microsoft Fabric

      APPLICATION INNOVATION

      • Website Development
      • Application Development

      DOCUMENT MANAGEMENT

      • Document Management Services
      • Document and Check Scanners
  • Security
    • CYBERSECURITY

      • Managed XDR
      • Penetration Testing
      • Vulnerability Scanning
      • Email Security Services
      • Digital Forensics and Incident Response
      • Backup, Replication and Disaster Recovery
      • Firewalls
      • Cloud Security Solutions

       

      • Virtual CISO
      • Virtual Security Team
      • Virtual Security Engineer
      • Cybersecurity Risk Assessment
      • Governance and Compliance
      • SOC 2
      • CMMC
      • Managed Security Awareness Training

      PHYSICAL SECURITY

      • Security Solutions
      • HBS Secure with Verkada
      Cybersecurity Risk Assessment Megamenu Graphic
  • Search
Contact Us
Blog

Penetration Testing, You Get What You Pay For

  • Written by: Dave Nelson
  • April 28, 2015
A cybersecurity professional conducts a penetration test on multiple monitors, analyzing code and system vulnerabilities. Another individual is visible in the background working on a similar setup, representing a collaborative environment for vulnerability scanning and pen testing.

If you are a small community bank and someone is offering to do network level penetration testing for 1 or 2 firewalls for $1,500, that’s a reasonable bid. If however, you have a load balanced web application running on 3 or 4 front end servers, 4 application servers and a database cluster with multiple user roles, the costs should be much, much higher.

The first thing to remember is that vulnerability scanning is all automated. Don’t let someone sell you a vulnerability scan as a penetration test. Ethical hacking or penetration testing, is largely a manual process. If during your vendor evaluation a vendor says a penetration test is going to take 5 days but only charges $2,000, a red flag should go up. How is that possible? That’s not much more than Geek Squad rates. Nothing against Geek Squad but they are hardly business class IT support, much less information security experts.

If this is truly penetration testing, these costs should be much higher. Ask the vendor to explain their testing process. How much is automated vs manual. Ask what certifications they have that are specific to penetration testing. I’ll be frank with you. I’m a Certified Information Systems Security Professional (CISSP) with 20 years of experience and our team of penetration testers at HBS that have the Certified Ethical Hacker (CEH) or GIAC Penetration Tester (GPEN) certifications can run circles around me in this area of information security.

The last thing you want is to base your assurance of information security on a faulty penetration test. Take some time and ask questions. Compare the answers from multiple vendors. Contact a local ISSA chapter and ask someone there to give the quotes a quick glance for you. There is a lot of confusion in the market place about this topic so make sure to do that extra bit of due diligence to ensure your money is being well spent.

Related Content

Pen Tests vs. Vulnerability Scans - How They're Different & Why They're Both Important" written in bold blue and black text on a light abstract background.

Penetration Testing vs Vulnerability Scanning

Penetration testing vs vulnerability scanning—both different, but essential for a strong cyber strategy. Regular scans and tests can safeguard your systems.

Learn More »
Construction Baker Group

Penetration Testing on the IoT Front Lines

As the provider of security systems and other building controls, Baker Group needs total confidence that they’re handing customers a secure facility. Baker Group trusts HBS as its partner for risk assessments and penetration tests.

Explore More »
Internal vs. External Pen Testing Graphic

Internal Penetration Testing vs External Penetration Testing: Why You Need Both

Understand the purpose and value of internal and external penetration testing for weaknesses that come from inside and outside of your environment.

Read More »
  • Penetration Testing
Blog

Connect:

[email protected]  |  800.236.7914

HBS logo

HQ | 1700 Stephen Street
Little Chute, WI 54140
Locations

HBS Remote Support | Service & Technical Support | E-Bill Portal
Terms & Conditions | Cookie Policy | Privacy Policy | Onboarding Form | End User Agreements | E-Bill FAQ | Site Map
©2026 Heartland Business Systems. All rights reserved.

Halo from HBS
This chat may be recorded as described in our Privacy Policy.