How to Vet a Penetration Testing Firm | Lorikeet Security Canada Skip to main content
Back to Blog

How to Vet a Penetration Testing Firm Before You Buy: 5 Questions That Expose an Automated Scanner Reseller

Lorikeet Security Canada Technical Team Sep 11, 2026 9 min read 1,420 views

TL;DR: Direct answer: Ask who actually conducts the testing, whether retesting is included at no additional charge, whether multi-tenant authorization (BOLA/IDOR) is actively tested with multiple provisioned accounts, and request a redacted sample report. A firm that hesitates or quotes a price without asking about application roles is simply reselling automated scanner output.

The Difference: Scanner Reseller vs Offensive Engineers

The cybersecurity consulting marketplace is flooded with firms that sell "penetration tests" for $3,000 to $5,000. In reality, the vast majority of these providers run an automated scanner such as Nessus, Burp Suite Pro, or Qualys, paste the tool's raw XML output into a branded PDF template, and deliver it as an assessment.

Automated scanning has its place in continuous hygiene, but it is not penetration testing. Automated tools cannot understand business logic, identify subtle authorization bypasses across tenancy boundaries, exploit chained vulnerabilities, or assess whether your AWS IAM trust relationships allow unauthorized privilege escalation.

When an enterprise auditor or sophisticated client reviews a scanner export, they immediately spot the boilerplate recommendations and lack of exploit validation. This can cause severe deal delays and force your team to commission a second, legitimate test at double the total expense.


Question 1: Who Conducts the Fieldwork?

In many large consulting shops, sales meetings are handled by seasoned practice directors, but the actual testing is outsourced offshore or assigned to junior interns with minimal offensive experience.

Ask explicitly: "Who will be the assigned lead tester on our environment, and what hands-on certifications or CVE research have they published?"

Look for rigorous, practical examination credentials such as the Offensive Security Certified Professional (OSCP), OSWE (Web Expert), or OSEP (Evasion). Unlike multiple-choice security certificates, these credentials require candidates to compromise complex multi-tier enterprise networks within strict timed exam constraints.


Question 2: Do You Require Multiple Tenant Accounts?

For any modern B2B SaaS application, Broken Object Level Authorization (BOLA / IDOR) is the number one most critical vulnerability class. It occurs when User A from Company X can access, modify, or delete sensitive records belonging to Company Y simply by manipulating an API parameter or database GUID.

No automated tool can discover BOLA flaws without custom business logic context. To test for cross-tenant data leakage, a tester must be provisioned with at least two distinct organizations or tenant accounts, systematically executing actions from Tenant A while targeting objects belonging to Tenant B.

The Acid Test: If a penetration testing firm provides a scoping questionnaire that does not request credentials for at least two tenant organizations and multiple role tiers (Admin, Standard User, Read-Only), they are not planning to conduct authenticated business logic testing.


Question 3: What Is Your Retesting Policy?

A penetration test is only as valuable as the remediation that follows it. Once your developers patch the identified vulnerabilities, you must prove to your auditors and enterprise customers that the fixes are sound.

Many firms artificially deflate their upfront quote, only to hit clients with surprise retesting fees of $2,500 to $4,500 later in the project. Always demand written clarification on retesting:

  • Is retesting included in the initial engagement fee?
  • How long is the retesting window (e.g., 30 to 60 days following report delivery)?
  • Does the firm issue an updated Letter of Attestation reflecting verified remediation?

At Lorikeet Security Canada, complimentary retesting of critical and high findings within 30 to 60 days is standard across all engagements.


Question 4: Can We Inspect a Redacted Report?

Before executing any contract, ask to inspect a sanitized sample report. High-calibre offensive firms will happily provide an example report demonstrating their reporting calibre.

Review the sample report with your engineering leads and look for these telltale elements:

  • Reproducible Curl Commands: Does each finding contain the exact HTTP request, headers, parameters, and authentication tokens needed for a developer to reproduce the issue in 60 seconds?
  • Attack Path Narrative: Is there an executive narrative explaining how vulnerabilities were chained together to compromise data, rather than a disconnected list of CVEs?
  • Custom Remediation Guidance: Does the advice reflect your modern technology stack (e.g., Node.js, Python, AWS, Docker), or is it generic text copy-pasted from an online database?

Question 5: Is Pricing Flat-Rate or Hourly?

Hourly billing or open-ended "time and materials" arrangements align the consulting firm's financial incentives against your project's success. If the firm runs into environment complications or testing delays, your budget balloons.

Demand a guaranteed, flat-rate Statement of Work. A transparent firm can accurately scope your attack surface (number of web interfaces, API endpoints, role levels, and cloud boundaries) during a focused 20-minute scoping call and provide a locked price with zero surprise change orders.

Frequently Asked Questions

What is the standard price range for a genuine application penetration test in Canada?

A legitimate, human-led web application or API penetration test for a modern SaaS company typically ranges between $10,000 and $13,500 CAD, depending on the number of endpoints, user roles, and complexity. Quotes under $4,000 almost universally indicate automated scanning.

Should penetration testing be conducted in staging or production?

A dedicated, production-identical staging environment is optimal for high-risk exploits (such as authorization and database injection tests). However, production testing with strict rules of engagement is often required to validate live CDN, WAF, and network segmentation controls.

How many days does a comprehensive web application pentest take?

Active fieldwork for a standard SaaS web application and API typically requires 5 to 8 business days of manual testing, followed by report delivery within 2 to 3 days.

Want to see what an authentic penetration test deliverable looks like?

Download our specimen penetration testing report to inspect our methodology, vulnerability proofs, and executive Letter of Attestation.

1,420 views
Link copied!
Lorikeet Security Canada

Lorikeet Security Canada Technical Team

Penetration Testing & Compliance Consulting

Lorikeet Security Canada helps Canadian organizations and high-growth engineering teams in Calgary, Toronto, and nationwide assess risk, satisfy enterprise procurement questionnaires, and close security gaps with certified penetration testing and compliance readiness.