Offensive security, on a subscription
Continuous attack surface monitoring with Pincher, plus a fixed penetration testing cadence, bought once a year as one agreement.
Essential
Continuous coverage with a testing cadence a single environment can absorb.
From$40,000per year
Testing- Two external penetration tests a year
- One internal penetration test a year
- Any of them swappable for a web application test
Included- Pincher attack surface management, running continuously
- Analyst-validated findings, not a queue of raw alerts
- Retests of high and critical findings, included
- A scheduled review each quarter with the testers who did the work
Best forA single environment: under roughly 1,000 endpoints, one directory forest, one or two applications in scope.
Scope EssentialComplete
Quarterly external testing and a twice-yearly internal, on top of continuous monitoring.
From$64,000per year
Testing- Four external penetration tests a year
- Two internal penetration tests a year
Included- Everything in Essential
- Scope re-baselined each year against what Pincher has found
- Named testers who carry your environment between engagements
Best forA growing estate: roughly 1,000 to 5,000 endpoints, several applications and APIs, more than one directory forest.
Scope CompleteEnterprise
Built around the estate rather than fitted to a tier, with the cadence your obligations set.
Custom
Testing- Testing cadence set by your compliance and release calendar
- Network and web application testing mixed to match where risk sits
- Segmentation and multi-entity scope handled explicitly
Included- Everything in Complete
- Coverage across business units, subsidiaries, and acquisitions
- Reporting shaped to the framework you answer to
- Direct escalation routes agreed before the first engagement
Best forMulti-entity and regulated estates: payment service providers, groups carrying acquisitions, environments with enforced segmentation.
Talk to us about scope
Starting prices in USD for a twelve-month term, billed quarterly in advance. Each program is quoted against your environment — see how we price it below.
Testing on a rhythm, not on a renewal date
Most organizations buy penetration testing the way they buy a fire inspection: once a year, because somebody asked for the certificate. The test is real work and the report is genuinely useful, and then the environment keeps moving for another eleven months while nobody is looking at it.
That gap is where incidents come from. Not the finding in the report — the subdomain that went live in March, the storage bucket a migration left open, the acquisition whose estate nobody has audited.
A program closes the gap by running two things at different tempos. Continuous attack surface monitoring tells you what changed and what you are exposing right now. Scheduled penetration tests tell you how deep a determined attacker gets once they pick a target. Neither one substitutes for the other, and buying them separately means paying twice for the same scoping conversation.
What is in every program
Pincher, operated by our team. Continuous external discovery of what you expose, with every candidate finding validated by a tester before it reaches you. False positives never arrive. Real ones arrive with evidence attached. This is our attack surface management service, included in every program rather than sold alongside one.
Penetration tests on a fixed cadence. Scheduled at kickoff, delivered by testers who already know your environment by the second engagement. The repeat-test economics are the reason a program costs less than the same work bought piecemeal.
Retests of what matters, included. High and critical findings get retested as part of the program, because a serious finding is not closed just because somebody told us it was fixed. Lower-severity findings are verified at the next scheduled test rather than individually — that keeps the cadence pointed at risk instead of at paperwork.
One number, quarterly. A fixed annual price, billed quarterly in advance, agreed before you sign. No per-engagement quoting, no waiting on a purchase order while a release ships.
How we price it
Each program has a published starting price, which is the floor for the smallest environment we sell it for. What moves a quote above the floor is the same handful of things every time: how many endpoints are in scope, how much you expose externally, how many applications and APIs we are testing, and how complicated your directory estate is.
We would rather publish the floor than make you sit through a discovery call to find out whether we are in your budget at all. If the number is wrong for you, that is worth knowing in a minute rather than a month and three calls from now.
A program is not the right purchase for everyone. If you need one specific assessment for one specific deadline, buy that instead — we sell it, and we will say so.
Questions about the programs
- Why is the price a range rather than a number?
- Because testing effort tracks the environment, not the calendar. Two companies buying the same cadence can differ by a factor of three in endpoints, external footprint, applications in scope, and directory complexity. The figure on each program is the floor — the smallest environment we sell that program for. You get one fixed annual number before you sign anything, and it does not move during the term.
- What happens if we do not use all our tests in a year?
- They do not roll over. A program buys a cadence, and the value of a cadence is that testing happens on a rhythm rather than accumulating into a rushed engagement in month eleven. We schedule the year at kickoff so this stays a planning question rather than a December problem, and we will tell you well before a window is at risk.
- Can we start with a single test instead?
- Yes, and plenty of clients do. A one-off engagement is the right purchase when you need a specific answer or a specific report for a specific deadline. A program is the right purchase when the question is continuous — what changed this quarter, what did we expose last week, is remediation actually holding. We are happy to start with one test and talk about a program at the end of it.
- Can we swap a network test for a web application test?
- Yes, on Essential and Enterprise. If your risk sits in an application rather than the network around it, a scheduled test is better spent there, and trading one for the other does not change the price. Tell us at kickoff or when we re-plan the year, so the swap is a scheduling decision rather than a change order.
- Is Pincher something we log into and run ourselves?
- No. Pincher is the platform our team operates on your behalf. Discovery runs continuously, our testers triage what it surfaces, and what reaches you is a validated finding with evidence and a remediation step. You are not buying a dashboard and the job of watching it.
- Do retests cost extra?
- Not for the findings that matter. Retesting high and critical findings is part of the program, because a serious issue is not closed until somebody has confirmed the fix works. Lower-severity findings are verified at your next scheduled test rather than retested one at a time. Helping your team design or implement a fix is a separate line either way — that is consulting rather than testing, and we would rather price it honestly than bury it.
- How is a program billed?
- Quarterly in advance across a twelve-month term, not per engagement. That keeps the commercial relationship continuous in the same way the testing is, and it means a test never waits on a purchase order.
- What if our environment changes significantly mid-term?
- Tell us — though Pincher will often surface the new exposure before anyone gets around to it. Scope is re-baselined annually against what it has actually found rather than against what the estate looked like on the day you signed. If something significant lands mid-term, we will quote the additional testing rather than pretend the original scope still covers it.
Not sure which program fits?
Tell us roughly how big your environment is and what you already have covered. We’ll come back with the program that fits and a fixed annual price.