Penetration Testing for Small Businesses: What to Expect and What It Costs

The short answer: A penetration test is a controlled, contractually authorised attempt to break into your network, application or data — carried out by a person who not only finds vulnerabilities but tries to exploit them and chain them together. That is what fundamentally sets it apart from an automated vulnerability scan, which merely compares software versions against a list of known holes. The price does not depend on the size of your company but on the scope: the number of addresses, applications and scenarios, the depth of the test, and whether a retest after remediation is included. A reputable provider will therefore pin down the scope first and only then give you a binding quote — a „pentest" offered on the spot at a suspiciously low price is usually resold scanner output. For a small business, the most sensible starting point is often a gap analysis as part of an IT audit, with the pentest then aimed at wherever the biggest risk turns out to be.

„Nobody is going to attack us, we’re not a bank." You hear this a lot in small companies — and it rests on the mistaken belief that attackers pick their targets by hand. Most attacks today work the other way round: automated campaigns scan the entire internet looking for vulnerable VPN gateways, forgotten websites and misconfigured services, and only then, based on what they find, is it decided what happens to the victim. That is exactly how companies end up with encrypted storage — we describe how such an attack unfolds in practice in our piece on ransomware on a NAS.

A penetration test does the same thing an attacker would, only earlier, under control, and with a report instead of a ransom demand. This article explains what it actually involves, how it proceeds, what you really get, and what makes up the price — because price is precisely where most providers stay silent, leaving quotes impossible to compare.

Penetration test vs. vulnerability scan

The most common misunderstanding on the market: a company orders a „penetration test" and receives a PDF generated by a scanner. Both have their place, but they are two different services with vastly different levels of effort.

Vulnerability scanPenetration test
Who performs itA tool (e.g. Nessus, OpenVAS)A person, using tools
What it revealsKnown vulnerabilities based on versions and signaturesWhat can actually be done with the weaknesses found
False positivesCommon, nobody verifies themFindings are verified by attempting exploitation
Chaining weaknessesNoYes — three „low" findings together can mean a full network takeover
OutputA list of CVEs with scoresDescribed attack scenarios, business impact, remediation priorities
EffortHoursDays

A scan is useful hygiene and features as one of the first steps in a good pentest. The problem starts when it is sold as a finished penetration test. The tell-tale sign: the report contains nothing but a table of vulnerabilities with CVSS scores — no description of what the tester actually achieved, no scenarios, no evidence. Paying the price of skilled human work for that output makes no sense.

What actually gets tested in a small business

The scope is assembled from blocks, and it is their selection that determines both the value and the price:

  • External perimeter — everything visible from the internet: public IP addresses, the VPN gateway, the firewall, remote desktops, the mail server, the website. Usually the first choice for a small business, because it mirrors the view automated attacks take.
  • Internal network — the „what happens once an attacker gets inside" scenario: a compromised laptop, a malicious attachment, a visitor with a cable. The test establishes how far someone can get from an employee workstation, typically towards the accounting system, backups and the domain administrator.
  • Web application or e-shop — testing to the OWASP methodology: authentication, role permissions, input handling, payments, APIs.
  • Wi-Fi — separation of guests from the corporate network, strength of the security, coverage outside the building.
  • Social engineering — controlled phishing aimed at employees. A sensitive discipline that only makes sense with clear ground rules and without publicly pillorying individuals.

On top of that you choose the level of knowledge the tester starts with: black box (knows nothing, like a genuine outside attacker), grey box (gets an ordinary user account) and white box (gets documentation and configurations). Grey box tends to offer smaller companies the best value for money — you are not paying for days of work spent discovering things you would have told the tester anyway.

How a penetration test proceeds, step by step

  1. Defining the scope (scoping). What exactly is tested, from when until when, from which addresses, what is off limits (e.g. touching the production database) and who to call if something goes wrong. Without proper scoping, no honest price can be quoted.
  2. Written authorisation and confidentiality. The contract and test authorisation are a precondition, not a formality — the same activity without the system owner’s consent constitutes the criminal offence of unauthorised access to a computer system. An NDA is part of it too, because the tester will see inside your company.
  3. Reconnaissance and mapping. What can be found about the company publicly, which services are running, which technologies and versions. Automated scanning belongs here too — as an input, not as the output.
  4. The testing itself. Manual verification of findings, exploitation attempts and chaining: a weak password on one service plus an outdated version on another plus over-permissive rights equals a path to your data. This is the heart of the work and the reason a test takes days.
  5. Report and presentation. Two layers: a summary for management (what genuinely threatens us and what to fix first) and a technical section for administrators (reproduction steps for every finding, recommended remediation).
  6. Retest. Once fixes are in place, critical findings are verified again. Ask in advance whether the retest is included in the price — this is exactly where quotes tend to differ.

What penetration testing costs

Now for the question that probably brought you here — and the one most competitors say nothing about. The reason is not secrecy but the fact that a „pentest„ without a scope is like „building a house" without plans. The price is built from effort: number of person-days × the specialist’s daily rate. What pushes the effort up:

  • breadth of scope — the number of public addresses, applications, roles within an application, branch offices;
  • depth — black box takes more work than grey box, an internal scenario more than an external one;
  • type of target — a web application with payments and an API is a different league from a perimeter check;
  • what is included — the retest, a management presentation, possibly a repeat a year later;
  • the tester’s seniority — it is worth asking about experience and certifications (e.g. OSCP).

As a rough guide: for a small business with one website and one perimeter we are talking about a handful of days’ work, not weeks — and the price reflects that. An honest, specific figure only comes with a quote for a precisely defined scope; anything else is a shot in the dark. You will find our rates and how we work in the IT services price list, and we will prepare a binding, tailored quote after a short gap analysis as part of our IT audit for businesses — which will also answer whether a pentest is the right first step, or whether you have a leakier spot somewhere else.

When comparing quotes, insist on the same things in writing from everyone: the same scope, the same level (black/grey box), information about the retest, and a sample report. And watch out for the red flags:

  • a price quoted on the spot, without a single question about the scope;
  • the promise „we’ll test everything" — everything cannot be tested, only a defined scope can;
  • a guaranteed „success rate for breaking in" — a serious tester never promises the result in advance;
  • an output that is nothing but an export from a scanner (see above).

Why small businesses are asking about pentests too: NIS2 and supply chains

The new cybersecurity act No. 264/2025 Sb. (Czech Collection of Laws), which transposes the European NIS2 directive into Czech law, has been in force since 1 November 2025. Even companies that do not fall under it directly feel its effects indirectly: larger customers are starting to ask their suppliers to demonstrate how their security is handled — through a questionnaire, an audit, sometimes the results of a penetration test itself. At that moment, a pentest with a report is a concrete answer instead of promises.

One note on terminology: a cyber audit is not the same as an audit of physical infrastructure. The inspection of cabinets, switches and cable routes that we describe in our article on auditing a computer network and cabling maps the state of things from the inside; a penetration test verifies resilience from an attacker’s point of view. Together they give the best picture — the audit tells you what you have, the pentest shows what of it can be exploited.

What to do after the test

A report that ends up in a drawer is money thrown away. After the test, it makes sense to:

  1. Fix the findings in the priority order given in the report — critical ones immediately, medium ones with a deadline, low ones into the maintenance plan.
  2. Verify your backups. A pentest often reveals that an attacker would reach the backups as well — and a backup that can be deleted from the same network is no protection against ransomware. We go through how to set up copies following the 3-2-1 rule in our article on an external HDD as your only backup.
  3. Introduce detection. Most findings share a common denominator: nobody would have noticed the attack. Logging, monitoring and endpoint protection need not be a corporate-scale project — we tackle endpoint detection with our own development too, see how we are building our own AI antivirus.
  4. Schedule a repeat. After a major infrastructure change, the rollout of a new application or a change of IT provider, it is worth repeating the test — the network from last year’s report no longer exists.

If you are not sure where to start, or you would first like to talk through informally what is worth testing in your case, get in touch — you will have the scope and the price up front, in black and white.

Frequently asked questions

How long does a penetration test take?

Depending on the scope, typically a handful of days of actual work plus time for the report; in calendar terms, allow for a longer window, since testing is scheduled around your operations. The exact timetable is part of the scoping.

Can the test break something or cause an outage?

The risk is governed by rules agreed in advance: destructive techniques are left out, sensitive systems are tested outside peak hours or on a copy, and a contact is agreed in case of trouble. Zero risk does not exist, but a controlled test is incomparably safer than a real attack, which will sooner or later exploit the absence of one.

How often should a penetration test be repeated?

At minimum after every major change — a new application, a new server, a network rebuild, a change of IT provider. For a stable environment, a regular interval makes sense; between tests, ongoing vulnerability scans keep the standard up.

Isn’t running a free vulnerability scan enough?

As a first piece of hygiene, yes — it will uncover forgotten services and outdated versions. But it will not tell you what can actually be done with the findings, it will not verify false positives, and it will not chain small issues into a real breach. A scan is a thermometer; a pentest is an examination.

Do we have to have a pentest because of NIS2?

It depends on whether you fall under a regulated service as defined by act No. 264/2025 Sb. — that is the first question a gap analysis will go through with you. Even outside direct regulation, though, customers and insurers often want a pentest as evidence that you are taking security seriously.