engagements & details

Priced by scope,
not by package.

No fixed price lists and no padding. Every engagement is scoped to your environment and objectives, then quoted individually — so you only pay for the work your attack surface actually needs. Tell us what you want tested and we'll send a tailored quote.

scope_01

Web & API Pentest

Vulnerability assessment & focused penetration test for a single app or a contained external footprint.

◆ scoped to your assets
  • Web app or external host range
  • Manual testing + verified scanning
  • OWASP-aligned coverage
  • Prioritised findings report
  • Remediation debrief
  • Retest included
Request a quote
scope_03

Full Red Team

Goal-driven adversary simulation across digital, human and physical vectors against live defences.

◆ scoped to your objectives
  • Objective-based, full-scope operation
  • Phishing, C2 & evasion
  • Detection & response measurement
  • Purple-team debrief workshop
  • Attack-path narrative + timeline
  • Remediation roadmap
Request a quote

Every engagement is scoped and priced individually. Tell us what's in scope and we'll send a tailored quote  →  nadeen@01-security.com

What you receive

Every engagement, regardless of tier, ends with artefacts your team and your board can both act on.

  • Findings reportPrioritised by severity with reproducible steps, evidence and business impact.
  • Executive summaryA one-page, non-technical read for leadership and auditors.
  • Remediation guidanceConcrete, developer-ready fixes — not just "patch it".
  • Live debriefA walkthrough call so nothing gets lost in translation.
  • Attestation letterProof of testing for clients, partners and compliance.
  • Retest & verifyWe confirm each fix actually holds.

What shapes your quote

We price on effort and risk, not headcount. These are the levers that move a number up or down.

  • Scope sizeNumber of apps, hosts, identities and cloud accounts in play.
  • DepthBlack-box, grey-box or assumed-breach starting position.
  • ObjectivesA checklist test vs. a "capture the flag" against live defences.
  • EnvironmentProduction, staging, or hardened / segmented networks.
  • TimelineStandard windows vs. compressed or after-hours work.
  • Severity mixcritical high retest — findings drive follow-up.
optional_modules

Bolt-ons.

Add these to any tier when the scope calls for it.

Phishing Campaign

A targeted spear-phishing simulation with landing pages, tracking and a click-to-report breakdown.

Available as an add-on

Physical Intrusion

On-site social engineering and physical access testing against your premises and staff.

Available as an add-on

Secure Code Review

Manual, developer-led review of a critical codebase alongside dynamic testing.

Available as an add-on

Continuous Retesting

Quarterly re-runs against your changing attack surface on a rolling retainer.

Available on request

Cloud Config Review

Deep IAM and configuration audit across AWS, Azure or GCP tenancies.

Available as an add-on

Threat Modelling

Architecture-level workshop to find design flaws before a line of code ships.

Available as an add-on
methodology

Grounded in recognised standards.

We don't improvise coverage. Engagements are structured against the frameworks your auditors and regulators already trust.

PTES
Testing standard
OWASP
Web · API · MASVS
MITRE ATT&CK
Adversary TTPs
NIST 800-115
Technical guide
CIS Benchmarks
Config baselines
SOC 2
Evidence-ready
ISO 27001
Control support
PCI DSS
Segmentation & ASV
questions

Before you brief us.

How much does an engagement cost? +

There's no fixed price list. Cost depends entirely on your scope — the number of applications, hosts, identities and cloud accounts in play, the depth of testing, and your objectives. We scope every engagement individually and send a tailored quote. Email nadeen@01-security.com with what you'd like tested and we'll take it from there.

How long does an engagement take? +

Most penetration tests run one to two weeks from kickoff to report, depending on scope. Red team operations typically span three to six weeks. We agree a fixed window before any testing begins.

Will testing disrupt production? +

We test carefully and coordinate closely. Intrusive or denial-of-service style checks are only ever run with explicit written approval, and we can work entirely in agreed windows or against staging where required.

Is a retest included? +

Yes. Every tier includes at least one retest so we can verify your fixes actually close the finding. The report isn't finished until the door is shut.

Who actually does the work? +

Senior, certified operators — the same people you meet during scoping. We don't hand your network to juniors, and we don't offshore the testing.

Can you support our compliance audit? +

Absolutely. Our reports and attestation letters are built to satisfy SOC 2, ISO 27001, PCI DSS and similar requirements, and we're happy to liaise with your auditor.

How do we get started? +

Send us a short note about what you want tested and why. We'll run a free scoping call, agree objectives and rules of engagement, and send a tailored quote — usually within a couple of days.

next_step

Get a tailored quote.

Tell us what's in scope. We'll come back with objectives, a timeline and a quote you can take to your board.