Real people quote it, order it, install it and stay on your account.

IT RavenIT RavenStoreQuote list

Cybersecurity

Penetration Testing

A penetration test is a controlled attack on your own systems, carried out by people you hire, to find the weaknesses before a real attacker does. The testers use the same tactics an intruder would, and they hand you a report of what they got into and how.

  • 7 companies on the shelf
  • Coverage

Buyer's checklist

Eight questions that decide this purchase

Think these through before you buy. Answer what you can and your quote comes back faster. Skip what you cannot, and we will work through it with you.

  1. 01

    What is triggering this test, and who will read the report: engineers, executives, an auditor?

  2. 02

    What is in scope: the external network, the inside of the network, web or mobile applications, wireless, your people, your buildings?

  3. 03

    Where does the infrastructure live: in the cloud, on your premises, or both?

  4. 04

    Will testers start with login credentials, to measure insider risk, or with none?

  5. 05

    Must testing happen outside business hours to protect live systems?

  6. 06

    Which framework is driving it, and does that framework set a minimum scope or a required frequency?

  7. 07

    Do you want a scheduled engagement with human testers, an on-demand platform, or both?

  8. 08

    Is a retest after you fix the findings included?

7 companies to compare

Capabilities come from published supplier material. We confirm them for your addresses before anything is quoted.

More on what it is

Tests come from two vantage points. An external test plays an attacker on the public internet going after whatever you expose to it. The other kind starts from inside the network and shows what someone could reach once they are past the front door, whether that is an intruder or an employee. A related choice is whether the testers begin with a valid login, which measures what an insider could do, or with nothing at all.

A typical engagement runs in five stages. Set the goals and gather information. Find weaknesses that can be exploited. Exploit them, carefully. Escalate from that first foothold toward more valuable systems, which is called lateral movement. Then report.

The name covers several distinct services. Network, web application, mobile app and wireless testing each examine a different surface. Social engineering tests whether your people can be fooled by a deceptive email or phone call. A physical test tries to walk into the building. A red team exercise combines methods over a longer period against a defended target.

There are two ways to buy it. The traditional way is a scheduled engagement with human testers. The newer way packages a tester's methods into a platform you subscribe to and run on demand. Providers generally position the two as complements, and many buyers end up using both.

Judge a provider by its report. A list of technical flaws is the weak version. The strong version says what business risk each finding carries, finds the root cause of the serious ones, and gives you an order in which to fix them. A retest afterward confirms the fixes worked.

Who needs it

  • A regulation or a contract requires a test, whether in payment cards, healthcare, finance or government work.
  • You have applications, portals or APIs that face the public.
  • You have made a big change: a system upgrade, a new office, new network equipment, a move to the cloud.
  • You have never been tested, or not within the past year.
  • You run wireless networks or physical sites that an outsider could approach.

A test tells you where you are weak. It does not fix anything. If you already know the basics are missing, such as multi-factor sign-in or patching, fix those first and test afterward. Otherwise you pay to be told what you already know.

Signs you need it

  • Your defenses have not been checked since the environment, the staff or the threats changed.
  • Nobody knows whether traffic leaving your network is restricted, which is how stolen data gets out unnoticed.
  • The last test report was too shallow to act on.
  • An auditor or a customer has asked for a recent report and you have none.

How IT Raven helps

Add Penetration Testing to your quote list and tell us why you need the test, what is in scope and when the report is due. A person takes that to the testing firms in our 500+ partner network and matches on what matters: experience with your framework and your kind of environment, the credentials their testers hold, and whether a sample report reads like something your team could act on.

Scope is where these projects go wrong, so we help you write it down before anyone quotes: what may be touched, when, and what is off limits. We stay on one thread through scheduling, the test window and delivery of the report.

A test usually produces work. Monitoring belongs to Managed Security, and an audit deadline belongs to Compliance and vCISO. We can quote the fixes alongside the test, and the same team books your retest.

How buying works

The store is the easy part. Staying on the account is the job.

Anyone can show you logos. The reason to buy here is what happens on install night, and on the ticket you open nine months later.

  1. 01

    Build your quote list

    Add services and companies as you shop. No form stands between you and the shelf.

  2. 02

    We bring back real options

    A person shops the bench against your addresses, then walks you through what fits and what does not.

  3. 03

    We handle the order and install

    Paperwork, site survey, install dates, cutover night. You get one thread, not five vendors.

  4. 04

    We stay on your account

    Same team for moves, adds, tickets and the next renewal. That is the part everyone else drops.