Vigilant Cybersecurity

How we test, and what you get.

Buying a pentest is hard if you have never bought one. Here is how we work and what you get at the end, before you commit to anything.

Read the questions

Example report

What we found

34 findings
  • Critical3
  • High8
  • Medium14
  • Low9
Retest34 of 34 fixed

What happens during your test, step by step.

01

Reconnaissance

Before we touch anything, we map what is publicly knowable about you: exposed infrastructure, forgotten subdomains, leaked credentials, third-party surface. Attackers start here, so we do too.

  1. Reconnaissance
  2. Enumeration
  3. Exploitation
  4. Escalation
  5. Report & retest

What lands in your inbox.

A report only helps if two people can use it: the engineer who fixes the problem, and the leader who decides to pay for the fix.

1Executive summaryFor people who do not work in security: the risk to the business, and the few things to do first.
2Every finding, with proofThe steps to repeat it, what it touches, and how bad it is for you, not just a score from a scanner.
3How to fix itClear fixes your engineers can act on, with the ones that remove the most risk at the top.
4The attack pathHow small problems join up into a big one, so leaders can see why a medium finding matters.
5Retest resultsWith the Complete package, we check every fix again and show which ones are closed.
6Signed letterWith the Complete package, a letter you can share with customers and auditors to prove the test was done.
Penetration test report
Example Co.

Executive summary

Broken access control on invoices

High
1. Sign in as a normal user
2. Change the invoice number in the address
3. Another company's invoice opens

How to fix it

How an attacker would chain it

Retest

Fixed. Checked again on the retest.

Signed letter

Questions buyers ask us most.

01What is penetration testing, and why do I need it?

A penetration test is an authorized simulated attack on your systems, performed by people using the same techniques as real adversaries. Unlike a scan, which reports what might be wrong, a pentest proves what an attacker could actually do: which systems they would reach, which data they would take, and how far they would get before anyone noticed. Most organizations need one because a customer, insurer, or regulator is asking for it. The reason to want one is that it is far cheaper to find these problems than to have them found for you.

02How often should my business conduct a penetration test?

Annually is the baseline that most frameworks expect, including SOC 2, PCI DSS, and ISO 27001. You should also test after any significant change: a major release, a cloud migration, a new authentication system, or an acquisition. Organizations shipping continuously often move to a semi-annual cadence, with targeted testing around high-risk releases in between.

03What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is automated. It compares your systems against a database of known issues and produces a list, usually with a meaningful number of false positives and no sense of what actually matters in your environment. A penetration test is performed by people. We validate findings by hand, chain several low-severity issues into a real attack path, and test the business logic unique to your application, which no scanner can evaluate because it has no idea what your application is supposed to do. Scanning is a healthy monthly habit. Testing is what tells you whether you are actually defensible.

04Will a penetration test disrupt my business operations?

Very rarely, and not by accident. We agree on rules of engagement before testing begins, including which systems are in scope, which techniques are off the table, and when testing runs. Denial-of-service testing is excluded by default. For fragile production systems we test during off-hours windows or against a staging mirror, and we keep a direct line open throughout so anything unexpected is handled within minutes.

05How long does a penetration test take?

Most engagements run one to three weeks of active testing, depending on scope. A single web application is typically five to seven days. A full internal and external network assessment for a mid-sized organization is usually two to three weeks. Reporting adds three to five business days after testing completes. We can start within a week. If you are working against a hard deadline, tell us on the scope call and we will plan around it.

06What do I actually receive at the end?

A report in two parts. An executive summary written for people who do not work in security, covering business risk and what to do about it. A full technical report with every finding, reproduction steps, evidence, severity rating, and specific remediation guidance. With the Complete package you also get a retest of every fix, and an attestation letter you can share with customers, prospects, and auditors as proof the assessment took place.

07Do you test AI and LLM-based systems?

Yes. It is one of our fastest-growing practice areas. We test prompt injection, both direct and indirect through retrieved content, plus tool and agent abuse, system prompt extraction, training data leakage, guardrail bypass, and excessive agency in systems where a model can take real actions. If your product gives a language model access to tools, data, or customer input, it has an attack surface most testing programs do not cover.

08How much does a penetration test cost?

Pricing is fixed, and based on the size of what we test rather than hours burned. Answer a few questions and you get a fixed-price proposal in about 90 seconds, with no call needed. We confirm it with you on a short scope call, and once you sign, it is locked. The Complete package adds retesting, the attestation letter and help with fixes.

Your proposal is 90 seconds away.

Type your website. Scope, timeline and a fixed price, in about 90 seconds. Free, and no sales call.

By getting a proposal, you agree to our Terms and Privacy Policy.

  • No surprise bills
  • Start within 1 week
  • Retest and letter in one price

Rather talk to a person? Book a call