P
P
PetrovArtemii292021-04-17 22:36:31
Burglary protection
PetrovArtemii29, 2021-04-17 22:36:31

Does it make sense to pay companies like Kontur for Pantest (Pentest)?

Where should a micro-enterprise go for a quality penetration test? Complete, and not up to the first theoretical vulnerability such as an unlicensed operating system (just an example).
Are there companies in the middle price segment, preferably up to 100,000? Is it worth trusting people like Kontur, Beeline, who are now doing this, or is their level so-so?

Answer the question

In order to leave comments, you need to log in

6 answer(s)
Z
Zamanbek Zhaxylykov, 2021-04-26
@Zamoony

the most important rule is that the costs of the audit (the pentest is included here) do not exceed the potential losses when opening a potential problem. + it is necessary that after the audit the found holes will not close by themselves in order to get rid of them, you need your own specialists (or you will have to turn to a third-party company again). after you calculate the costs, you can already think about whether you need it.

C
ComodoHacker, 2021-04-18
@ComodoHacker

The main question is what will you do with the results? Well, they find a bunch of things, you rush to fix everything? It can cost much more than 100K. And if not, why testing?
More important questions. What does a "micro-enterprise" do? How did you initially approach the issue? Do you have your own specialist? Is there a threat model?

V
ValdikSS, 2021-04-18
@ValdikSS

A "full" test is called an audit, not a pentest. Pentest, as a rule, shows what an attacker can find in a fixed time, and audit involves a deep study of systems, software, equipment, and their interaction.
I advise you to start by discussing your systems and building a threat model with a dedicated consultant. I recommend contacting https://dsec.ru/

A
Andrey Saburov, 2021-04-19
@scanfactory

The main thing is to clearly set goals and understand the goals that you are pursuing.
Do you need help fixing vulnerabilities/holes?
But I would not advise contacting Kontur, etc., these offices most often use outsourcing (we know, since we are performers).
Contact us, we will help you with a free consultation - [email protected]

V
Vladimir, 2021-04-19
@SibUrsus

Well, then order from trusted and reliable ones. I hope you have no doubts about Doctor Web's competence? Request com. proposal, maybe not so scary. https://antifraud.drweb.ru/expertise/scope

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question