/
/
security validation
security validation

Penetration testing coordination

Scoped, managed, and closed-loop — pen tests that actually change your risk posture. This is a coordination fee. The pen test is performed by a third-party vendor ($8,000–$30,000+ separately, client-paid). We manage the vendor and translate results into actionable remediation.

A pen test is only as useful as what you do with it

Most companies get a raw pen test report and hand it to an already-overloaded engineer who is not sure what to prioritize. We manage the vendor relationship, translate findings into business-risk language, and drive the remediation to closure — then feed findings into your tabletop exercise and GRC platform evidence. Important: This is a coordination and management fee only. The penetration test itself is performed by a third-party vendor. Pen test vendor costs are client-paid and disclosed at the scoping call.

Pricing tiers

Launch
$2,000–$3,500
coordination fee · 10–18 hrs · 1–2 weeks pre-test
Overage: $185/hr · Pen test vendor cost est. $8K–$30K+ (client-paid)
  • Pen test vendor selection and vetting
  • Scope definition and rules of engagement documentation
  • Vendor contracting support
  • Test day coordination (scheduling, access, technical contacts)
  • Results review: plain-language remediation priorities
  • GRC platform evidence upload (findings + remediation tracking)
Growth · Most popular
$4,000–$7,500
coordination fee · 20–40 hrs · 2–3 weeks pre-test
Overage: $195/hr · 30-day remediation check-in · Vendor cost est. $10K–$25K
  • Everything in Launch, plus:
  • Multi-scope coordination (web app, internal network, API)
  • Detailed remediation roadmap with owner assignments and timelines
  • Remediation validation support (retesting guidance)
  • Annual pen test program calendar and vendor management
  • SOC 2 and ISO 27001 evidence packaging for auditors
Scale
$8,000–$16,000
annual program · 40–80 hrs/year
Overage: $225/hr · Total annual vendor costs est. $20K–$60K+
  • Everything in Growth, plus:
  • Purple team coordination (pen test findings fed into tabletop scenarios)
  • Social engineering campaign coordination (scoped separately)
  • Executive summary and board presentation of findings
  • Remediation validation testing coordination
  • Annual pen test maturity assessment

Important note

  • This is a coordination fee only — the pen test is performed by a third-party vendor
  • Pen test vendor cost est. $8K–$60K+ depending on scope (client-paid)
  • Feed pen test findings into a tabletop exercise for maximum value — we coordinate both

Pen test findings become more valuable when fed into a tabletop exercise.

We coordinate both — testing your IR plan against the actual vulnerabilities found in your environment.