PaulDotCom mailing list archives

Vulnerability assessments and their cost


From: tadaka at gmail.com (Jason Wood)
Date: Tue, 5 May 2009 15:10:34 -0600

I recently received some pricing on a web application vulnerability
assessment from a large security service provider who shall remain
nameless.  This assessment basically consisted of using web application
scanner, turning it loose, then performing some verification on the issues
reported.  No actual exploitation of the application would be done.  The
price was was fairly expensive.  So I have some questions for the everyone.

What seems to be the going rate for a:

- Web application vulnerability assessment?
- Network vulnerability assessment?
- Wireless vulnerability assessment?

I assume there is some disparity between the prices of a brand name security
service provider and a smaller security company.  Does anyone know what
those differences in price would be?

I'm trying to get some idea of what to expect as I contact different
companies.  I wouldn't mind knowing for any future private endeavors as
well.  :)

Thanks for the help all.

Jason
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20090505/87d6a444/attachment.htm 


Current thread: