Skip to content
All writing

[ Method ]

What a $700 black box pentest actually buys you

The honest version: what fits inside a small external scope, what does not, and when the cheap test is the right one.
Published
19 August 2026
Written by
Vaptiq Testing Team
Length
3 min read

The short version

  • Exploiting an internet-facing vulnerability is now the single most common way attackers get in, ahead of phishing and stolen credentials for the first time in 19 years.
  • $700 covers a small single-domain external scope, not an application behind a login.
  • If a vendor quotes a fixed price without asking how many live hosts you have, the number is fiction.

Every low price in security testing hides an assumption. Ours is stated up front: $700 is a small, single-domain external scope with a handful of live hosts, tested by a person for three to five days. If your estate is bigger than that, the number moves, and you see the new number before you commit to anything.

The more useful question is not whether $700 is cheap. It is whether the thing a cheap external test looks at is the thing attackers actually use. For the first time in the Verizon report’s nineteen-year history, the answer is unambiguously yes.

31%
Of breaches now start with exploiting a vulnerability, up from 20%, and now ahead of phishing and stolen credentials
22,000
Confirmed breaches across 145 countries in the 2026 Verizon DBIR dataset
26%
Of CISA known-exploited vulnerabilities were fully remediated, down from 38% a year earlier
43 days
Median time to fully patch, up from 32 days

Read those together. The most common way in is an internet-facing weakness; organisations fix roughly a quarter of the ones already known to be exploited; and the ones they do fix take six weeks. A black box test is a direct measurement of that exposure, taken from where the attacker stands.

What fits inside the scope

  • Passive and active reconnaissance across your public footprint, including hosts nobody remembers standing up.
  • Subdomain discovery and service enumeration on every port that answers.
  • Authentication, session and access-control testing on anything exposed to the internet.
  • Password spraying against public login surfaces, at a rate that will not lock your users out.
  • Secrets left in public repositories, JavaScript bundles and CI artefacts.
  • Chained exploitation, where two low-severity issues combine into something that matters.

What a credential-free test cannot reach

This is the part most vendors leave out of the proposal. Broken access control between tenants, privilege escalation inside the application, and business-logic flaws in a checkout or approvals workflow all sit behind a login. A black box test spends its budget getting to the door rather than walking the building.

That matters because it changes what a short findings list means. A clean black box report says nothing about whether one of your customers can read another one’s invoices. It was never asked that question.

How to tell which test you need

Ask who is asking for the test. If it is a customer security review or an auditor, they usually want evidence that the application was tested with credentials, which means grey box. If it is your own board asking what an opportunistic attacker can reach from the open internet, black box answers that precisely and cheaply. Given that 31% figure, it answers the question that fits the most common breach.

Most teams start black box and move to grey box the following year. That order is fine. Skipping the second step is not.

The pricing question worth asking a vendor

Ask what changes the price. If the answer is the number of live hosts and applications in scope, you are talking to someone who has scoped a test. If the answer is vague, or arrives only after a discovery call with someone who does not test, the fixed price is a starting position in a negotiation.

Our scope sheet is a page long and the number on it does not move unless the scope does. That is the whole mechanism.

The engagement that covers this

Find out what is reachable, before somebody else does.

Thirty minutes is usually enough to scope an engagement and put a fixed price in writing. You talk to someone who tests, not a sales engineer.