Cybersecurity
Penetration Testing
A test, not a surprise.
A penetration test is an authorised, scoped attempt to break into your systems, carried out by a person rather than a scanner, to find out what someone could actually reach. happier IT runs tests for Canadian organizations of roughly 15 to 200 people, and says plainly when a test is premature and the money would do more good elsewhere first.
Who it's for
Almost nobody buys a test because they woke up curious.
Four reasons bring people to this page. We usually encourage three of them and talk the fourth out of it.
A client contract asks for one. A security schedule, a vendor questionnaire, or a procurement form with "annual penetration testing" written into it. You need a real test and a report you can hand over without editing.
An insurer or an auditor wants evidence. Cyber-insurance renewals and audit frameworks such as SOC 2, a common report on how a service provider handles other people's data, now name testing directly rather than implying it.
You have finished the basics and want your work checked. This is the best reason. Second-factor logins are on, endpoints are protected, a restore has been tested. A test now tells you something you did not already know.
Someone sold you the idea. If the basics are missing, a test costs real money to produce a report saying so. We would rather tell you on the first call than take the engagement.
The readiness test for a test
Three questions. Is multi-factor authentication, a second check, usually a prompt on a phone, before a login is accepted, on every account? Is there detection software on every device? Has anyone restored from your backup this year?
If any answer is no, spend the money there instead. A penetration test should find the interesting gaps. It should not be the thing that finds the obvious ones.
What's included
What is in a test, and what comes back to you.
Scope is agreed in writing before anyone touches anything. Nothing on this list happens by surprise, to you or to your staff.
-
A written scope and rules of engagement
Which addresses, applications and accounts are in play, which are explicitly out, the test window, and who to phone if something looks wrong. Signed by both sides before any traffic is sent.
-
An external test
What a person on the internet can see and reach: your public addresses, remote access, mail and web services, and any login page that faces the world.
-
An internal test
What someone already inside, a contractor, a guest on the wrong network, a device left signed in, could get to next. This is usually where the findings worth paying for turn up.
-
Identity and Microsoft 365 testing
The cloud tenancy is the front door for most organizations now. We test sign-in policy, administrator roles, mail rules and file sharing, not only the servers in your building.
-
Web application testing
For a customer portal, booking system, or anything you had built. Authentication, whether one account can reach another account’s data, and how the application handles input it did not expect.
-
Black, grey or white box, chosen deliberately
Black box means we start with nothing, like an outsider. White box means you hand over documentation and credentials. Grey box sits between. White box finds more per dollar; black box is closer to a real outsider and slower.
-
A report written for two audiences
A short summary a non-technical director can act on, and a technical section with evidence, reproduction steps and a specific fix for each finding, ranked by what it would mean in your environment rather than by a raw score.
-
A retest of the fixes, included
Once you have made the changes, we test the same findings again and reissue the report. A test with no retest tells you where you were, not where you are.
How it works
How a test runs, start to finish.
Most of the calendar time is scoping and scheduling. The hands-on testing is the shortest part of it.
-
Scope and permission
We agree what is in, what is out, and when. Where systems are hosted by somebody else, we get their written authorisation too, testing a platform without it is a reliable way to have an account suspended mid-engagement.
-
The test itself
Hands-on work by a named tester inside the agreed window. Anything serious is reported to you the day it is found rather than saved for the document, and you have the tester’s number for the whole period.
-
Report, debrief and retest
You get the report, then a call to walk through it with whoever will do the fixing. Then a remediation period you set, and a retest that records what actually closed and what did not.
What it costs
A fixed price per engagement, quoted after scoping.
This is one of the few things on this site that does not live inside a monthly fee. It is a specialist engagement with a start and an end.
Penetration testing is quoted as a fixed price for an agreed scope, not per user, per month.
Three things move it:
- How many targets. One external address range is a small job. Three sites, a cloud tenancy and a custom application is not.
- How much you tell us. A white box test buys more coverage for the same money, because the tester spends the days testing rather than mapping.
- Whether a retest is included. Ours is. Some quotes you compare us against price it separately, so it is worth asking.
If happier IT already runs your managed IT, testing stays separately quoted. You should be able to see the cost of being checked as its own line.
When we will tell you not to buy this
If second-factor logins are missing, or a third of your devices have no detection software, a test is not the next purchase. We will say so, put the cheaper work in writing, and still be here when a test is worth doing.
The free IT assessment will tell you which of the two you need.
Why us for this
Tested by people who hold the credential for it.
happier IT’s security team holds Certified Ethical Hacker (CEH) credentials, a recognised qualification for people who test systems with permission. Every certification our team holds is listed on our awards and certifications page.
Two commitments matter more than the badge. Anything we find being actively used against you becomes a phone call the same hour rather than a line in a report. And where we built the thing under test, the report says so.
Typical end-to-end timeline for an engagement of this size is two to three weeks, from scoping to the report landing.
Go deeper
- What is a penetration test? The definition, without the mystique.
- Vulnerability management The monthly practice a test measures.
- Cybersecurity services The controls worth having in place first.
Questions
What people ask before they sign anything.
What is the difference between a penetration test and a vulnerability scan?
A scan is automated and lists known weaknesses; a test is a person who then tries to use them. A scanner might report an out-of-date server and a weak login page as two unrelated findings. A tester joins them together, gets in, and shows you what that reaches from there. Scans should run every month and cost very little. Tests happen once or twice a year and cost real money. You want both, in that order.
Do we need a penetration test?
Only once the basics are in place, unless a client or a regulator is asking for one now, which changes the answer. Multi-factor authentication, endpoint detection and a tested backup remove more risk per dollar than a test does. After those, a test earns its cost, because it finds what a checklist cannot: weaknesses joined together, systems nobody remembered owning, and permissions granted years ago for a reason that has gone.
What does a penetration test cost in Canada?
It is quoted per engagement, on scope rather than headcount. When you compare quotes, ask three questions: how many tester-days, how much of the work is manual rather than an automated scan presented as a test, and is the retest included.
Will the test break anything?
It should not, and the scope document is how we make sure. Some techniques carry genuine risk, checking whether a service falls over under load, for example, and they are named and excluded unless you specifically ask for them. Fragile older systems get flagged before we start rather than discovered halfway through, and one call from you pauses the test.
What is black box, grey box and white box testing?
They describe how much we know going in. Black box: nothing but your company name, so the test includes finding what you have. Grey box: some information and a standard user account, which is the closest match to a realistic starting position. White box: full documentation, architecture and credentials. White box finds the most per dollar because no time is spent on reconnaissance. Most organizations of this size get the best value from grey box.
How often should we test?
Once a year is the usual cadence, plus after any significant change: a new office, a cloud migration, a new customer-facing application, a merger. Testing more often without changing anything in between mostly buys the same report twice. What should run continuously is the cheaper practice underneath: vulnerability management.
Related
Where to go next.
Want to know what this would look like for you?
A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.