Penetration testing services put a qualified attacker against your systems under contract, on a fixed scope, and hand you a report you can act on. Sthenos runs penetration testing services, vulnerability assessment services, and IT security audit engagements for enterprise and government teams across network, web, API, cloud, and application layers, following NIST SP 800-115 and the OWASP Testing Guide. Every engagement ends with a retest, because a finding you have not re-verified is still an open finding.

Typical scope2 to 4 weeks

From kickoff to final report for a single application or network segment.

StandardsNIST 800-115

Executed alongside the OWASP Testing Guide, PTES, and MITRE ATT&CK.

RetestIncluded

Every confirmed finding is re-tested after your fix, at no extra charge.

DeliveryTwo reports

A technical findings report and a board-readable executive summary.

What penetration testing services cover

A penetration test is scoped by attack surface, not by product name. Most engagements combine two or three of the areas below. Naming the surfaces up front is what keeps the quote honest and the results comparable between vendors.

Attack surfaces we test

External networkInternet-facing hosts, VPN edges, exposed services and forgotten subdomains.
Internal networkLateral movement, privilege escalation and segmentation testing from a foothold.
Web applicationsThe OWASP Top 10, business-logic abuse, authentication and session handling.
APIsREST and GraphQL authorisation flaws, object-level access control, rate limits.
Cloud configurationAWS, Azure and GCP identity, storage exposure and over-broad role bindings.
Social engineeringPhishing simulation and pretext calling, run only with written authorisation.

Scope is agreed in writing before testing begins. Anything outside the signed scope is not touched.

Vulnerability assessment vs penetration testing

These get quoted against each other constantly, and they answer different questions. A vulnerability assessment tells you what is exposed. A penetration test tells you what an attacker can actually do with it. Buying the wrong one is the most common waste in this category.

Vulnerability assessment

Breadth

  • Automated scanning across the whole estate
  • Produces a ranked list of known weaknesses
  • Runs monthly or quarterly on a schedule
  • Does not confirm whether a flaw is exploitable
  • Lower cost, wider coverage

Penetration test

Depth

  • Human-led, chained exploitation of real weaknesses
  • Proves impact: what data moved, what access was gained
  • Runs annually, or after a significant release
  • Eliminates false positives by demonstrating them
  • Higher cost, decisive evidence

Most regulated programmes need both: continuous assessment for coverage, an annual test for proof.

A practical rule. If you cannot yet name your exposed assets, start with a vulnerability assessment. If you already have a patch backlog and need to know which items actually matter, you need a penetration test.

How much does penetration testing cost?

Penetration testing cost is driven by scope size and testing depth, not by vendor size. Below is what the market charges, compiled from third-party industry sources, and what we charge for the same scope. Our figures include the retest.

What the market charges, and what we charge

External network, up to 25 IPs

Market$5,000 to $10,000
Sthenos$3,250 to $6,500

Web application, human-led

Market$5,000 to $30,000
Sthenos$3,250 to $19,500

Cloud environment

Market$5,000 to $50,000
Sthenos$3,250 to $32,500

Enterprise, multi-surface with retest

Market$75,000 to $150,000
Sthenos$48,750 to $97,500

Market figures are published ranges compiled from Astra Security, Software Secured and Blaze Information Security, current as of 2026. Sthenos figures are our own indicative ranges for the same scope, with the retest included rather than billed on top. Your quote is fixed in writing before work begins.

Three things move the number more than anything else: how many distinct applications or subnets are in scope, whether testing is black box or credentialed, and whether the engagement includes a retest. We quote all three explicitly rather than as a single line item.

On retesting. Industry sources note that bundling retest rounds into scope typically raises a vendor’s total by 10 to 20 percent. Our retest is included in the quoted price, so compare like for like when you read a cheaper proposal.

Our penetration testing methodology

Every engagement runs the same five phases, whether it is a single API or a full internal network. The phases come from NIST SP 800-115 and the Penetration Testing Execution Standard, so the output is comparable against any other competent firm’s work.

  1. Scoping and rules of engagementWe agree assets, testing windows, escalation contacts, and what is explicitly out of bounds. Signed before anything is touched.Week 0
  2. Reconnaissance and enumerationMapping the real attack surface, which is routinely larger than the asset inventory says. Forgotten subdomains and stale services surface here.Days 1 to 3
  3. Exploitation and chainingConfirming weaknesses by using them, then chaining them. A medium plus a medium is often a critical, and only chaining reveals it.Days 4 to 10
  4. ReportingTwo documents: reproducible technical findings with evidence, and an executive summary that states business impact without jargon.Days 11 to 14
  5. Remediation support and retestWe re-test every confirmed finding after your fix and reissue the report with the status updated. Included, not billed separately.After your fix

Testing is scheduled around your change freezes and business hours. Destructive testing is never run without explicit written approval.

Cyber security assessment and IT security audit services

Not every question needs an attacker. Cyber security assessment services and IT security audit services evaluate your controls, policy and architecture against a named framework, and are usually what a board, insurer or prime contractor is actually asking for when they say they want a security review.

  • Information security audit services and cyber security audit services measured against ISO/IEC 27001 Annex A or the NIST Cybersecurity Framework, producing a control-by-control gap register.
  • Cyber security compliance services mapping your current state to the framework your contract names, whether that is SOC 2 criteria, HIPAA, PCI DSS, CMMC or FedRAMP.
  • Architecture and configuration review against CIS Benchmarks for the platforms you actually run, rather than a generic checklist.
  • Identity and access review covering privileged accounts, service principals, joiner-mover-leaver handling and standing access that should have expired.
On compliance claims. We help clients prepare for and evidence these frameworks. We do not represent our own attestation status as part of a sales conversation, and you should ask any vendor to show you their report rather than accept a logo on a slide.

Application security and cloud security services

Application security services move testing left, into the build, so the annual penetration test stops finding the same class of defect every year. Cloud security services address the configuration layer, which is where most cloud incidents actually begin.

Application security

  • Secure code review on the paths that handle authentication, authorisation and money.
  • Threat modelling at design time for new services, using STRIDE or attack trees.
  • SAST and dependency scanning wired into CI so a vulnerable package fails the build.
  • Developer remediation sessions, so fixes hold rather than recur next release.

Cloud security

  • AWS, Azure and Google Cloud configuration review against CIS Benchmarks.
  • Identity and role analysis, targeting over-broad permissions and unused standing access.
  • Storage exposure review across buckets, blobs, snapshots and backups.
  • Infrastructure-as-code policy checks, so a corrected setting cannot be reintroduced by the next deploy.

Cybersecurity consulting services

Testing tells you where you stand. Cybersecurity consulting services decide what to do about it. Our cyber security consulting work is advisory rather than tool-led: we help you sequence remediation against risk and budget, and we do not resell the products we recommend.

  • Fractional security leadership. A named advisor acting as vCISO for organisations that need the judgement without a full-time hire.
  • Security programme design. Building the policy set, risk register and control map from nothing, or rebuilding one that has drifted.
  • Remediation roadmaps. Turning a findings report into a sequenced plan with owners, effort estimates and dependencies.
  • Third-party and vendor risk. Assessing the suppliers inside your boundary, which is where an increasing share of incidents originate.
  • Incident readiness. Tabletop exercises and runbook review, so the first time you practise is not during an actual breach.

Organisations approach this under several names. IT security consulting, information security consulting and cyber security consultancy all describe the same engagement shape here: a senior practitioner, a defined question, and a written answer you own.

Security testing in the software development lifecycle

Security testing belongs inside delivery, not only at the annual audit. Where conventional software testing asks whether the system does what it should, security testing services ask what else it can be made to do. Teams that treat software testing and security testing as one discipline find defects while they are still cheap to fix.

  • Requirements and design. Abuse cases written alongside user stories; threat modelling before the first commit.
  • Build. SAST and software composition analysis gated in CI, so a known-vulnerable dependency fails the pipeline.
  • Pre-release. Targeted DAST and manual testing on authentication, authorisation and payment paths.
  • Production. Continuous vulnerability assessment services plus an annual penetration test for proof.
Where security testing in software testing usually breaks down. The scanner is wired into CI, its output goes to a dashboard nobody owns, and the backlog grows until it is ignored. The fix is not a better scanner. It is a named owner and a policy that fails the build.

What a penetration test satisfies

Most organisations buy a test because a framework, a customer or an insurer asked for one. Here is what each commonly expects, so you can scope once and satisfy the requirement rather than testing twice.

Requirement What it expects Typical cadence
PCI DSS Internal and external testing, plus segmentation testing where segmentation is claimed Annually and after significant change
SOC 2 Evidence of a vulnerability management programme; testing commonly requested by auditors Annually
HIPAA Technical evaluation of safeguards protecting electronic protected health information Periodically and after material change
ISO/IEC 27001 Technical compliance review supporting Annex A control assurance Annually
CMMC / NIST 800-171 Security assessment covering controlled unclassified information boundaries Per assessment cycle
Customer security review A current report with findings remediated and retested On request, usually annually

What to ask any penetration testing company

The quality gap between penetration testing companies is wide and is not visible in the proposal. Directory lists of top pen testing companies rank by marketing spend, not by testing depth, so use the questions below instead. These five questions separate human-led testing from a rebadged scan.

  1. Who is testing, and what are their certifications? Ask for named testers with OSCP, CREST or GPEN, not a company-level claim.
  2. Is a retest included in the price? If it is billed separately, the quote is not comparable to one that includes it.
  3. Can I see a redacted sample report? A serious firm will send one. The report is the deliverable, so judge it before you buy.
  4. What proportion of the work is manual? Automated scanning is a starting point. Business-logic flaws are only found by a person.
  5. How are findings evidenced? Every finding should carry reproduction steps a developer can follow without you in the room.

Frequently asked questions

How long does a penetration test take?

Most pen testing services quote two to four weeks end to end for a single application or network segment: roughly ten working days of testing, then reporting. Full-scope red team engagements run six to twelve weeks.

What is the difference between a vulnerability assessment and penetration testing?

A vulnerability assessment identifies and ranks known weaknesses using automated scanning across a wide surface. A penetration test is human-led and proves exploitability and business impact on a narrower scope. Regulated programmes typically run continuous assessment plus an annual test.

Will testing disrupt production systems?

Testing is scheduled around your change windows, and destructive techniques such as denial-of-service are excluded unless you request them in writing. Escalation contacts are agreed before testing starts so anything unexpected is stopped immediately.

Do you test cloud environments?

Yes, across AWS, Azure and Google Cloud, covering identity and role configuration, storage exposure, network boundaries and infrastructure-as-code. Note that cloud providers require notification for certain test types, which we handle as part of scoping.

What do we receive at the end?

A technical findings report with severity ratings, evidence and reproduction steps; an executive summary written for a non-technical reader; a remediation session with your engineers; and a retest with an updated report once fixes are in place.

Do you work with government agencies?

Yes. Roughly a third of our work is public sector, and engagements are scoped against NIST SP 800-115 and NIST 800-171 where controlled unclassified information is in play. The remainder of our work is commercial, and the methodology is the same in both.

Ready to scope a penetration test? Tell us what is in scope and what is driving the requirement, and we will come back with a fixed-price proposal for penetration test services that names the testers, the standards, and the retest terms. Talk to our security team or call +1 301-793-3980.

Contact us
Partner with Us for
Comprehensive IT

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Your benefits:
What happens next?
1

We Schedule a call at your convenience 

2

We do a discovery and consulting meeting 

3

We prepare a proposal 

Request a Free Consultation
Book a 30-minute call →Prefer to talk first? Skip the form and grab a time directly.

We respond within one business day