Every low price in security testing hides an assumption. Ours is stated up front: $700 is a small, single-domain external scope with a handful of live hosts, tested by a person for three to five days. If your estate is bigger than that, the number moves, and you see the new number before you commit to anything.
The more useful question is not whether $700 is cheap. It is whether the thing a cheap external test looks at is the thing attackers actually use. For the first time in the Verizon report’s nineteen-year history, the answer is unambiguously yes.
- 31%
- Of breaches now start with exploiting a vulnerability, up from 20%, and now ahead of phishing and stolen credentials
- 22,000
- Confirmed breaches across 145 countries in the 2026 Verizon DBIR dataset
- 26%
- Of CISA known-exploited vulnerabilities were fully remediated, down from 38% a year earlier
- 43 days
- Median time to fully patch, up from 32 days
Read those together. The most common way in is an internet-facing weakness; organisations fix roughly a quarter of the ones already known to be exploited; and the ones they do fix take six weeks. A black box test is a direct measurement of that exposure, taken from where the attacker stands.
What fits inside the scope
- Passive and active reconnaissance across your public footprint, including hosts nobody remembers standing up.
- Subdomain discovery and service enumeration on every port that answers.
- Authentication, session and access-control testing on anything exposed to the internet.
- Password spraying against public login surfaces, at a rate that will not lock your users out.
- Secrets left in public repositories, JavaScript bundles and CI artefacts.
- Chained exploitation, where two low-severity issues combine into something that matters.
What a credential-free test cannot reach
This is the part most vendors leave out of the proposal. Broken access control between tenants, privilege escalation inside the application, and business-logic flaws in a checkout or approvals workflow all sit behind a login. A black box test spends its budget getting to the door rather than walking the building.
That matters because it changes what a short findings list means. A clean black box report says nothing about whether one of your customers can read another one’s invoices. It was never asked that question.
How to tell which test you need
Ask who is asking for the test. If it is a customer security review or an auditor, they usually want evidence that the application was tested with credentials, which means grey box. If it is your own board asking what an opportunistic attacker can reach from the open internet, black box answers that precisely and cheaply. Given that 31% figure, it answers the question that fits the most common breach.
Most teams start black box and move to grey box the following year. That order is fine. Skipping the second step is not.
The pricing question worth asking a vendor
Ask what changes the price. If the answer is the number of live hosts and applications in scope, you are talking to someone who has scoped a test. If the answer is vague, or arrives only after a discovery call with someone who does not test, the fixed price is a starting position in a negotiation.
Our scope sheet is a page long and the number on it does not move unless the scope does. That is the whole mechanism.