A penetration test describes one moment. Your attack surface keeps moving.
Continuous Offensive Security Testing keeps your external attack surface under test all year. A consultant directs the engagement and does the work that needs judgement, while automation runs the long jobs a one-week test never gets to finish.
The same money, spent differently
An annual penetration test and a year of continuous testing cost about the same. What changes is how long you wait to find out something has been exposed, and which jobs actually get finished. Password spraying has to run slowly to avoid locking accounts out. Content discovery across a large estate takes days per host. Neither finishes inside a testing week, so they get sampled or dropped.
| Measure | Annual external penetration test | Continuous — base package |
|---|---|---|
| Testing days per year | About 5 | 365 |
| Time to learn about a new exposure | Up to 12 months | 1 business day |
| Covers assets deployed after testing began | No | Yes |
| Report accuracy | Accurate on the day it was issued | Current |
| Tasks that take weeks to finish, such as password spraying and content discovery | Rarely completed inside a one-week test | Run to completion |
| Cost | About $10,000 a year | About $10,000 a year |
A penetration test tells you what was true in March. This tells you what’s true today.
Agents for coverage, humans for judgement and control
The service is never agent-only, and it is never purely manual. Agents provide coverage at a scale and frequency a human team could not sustain. Consultants direct the testing, do the work that requires judgement, and validate every finding. Humans also define and enforce the boundaries the agents operate within, which makes oversight a safety control and not only a quality control.
What the tooling handles
- Keeps discovery and enumeration running across every in-scope asset
- Surfaces change and new exposure between consultant passes
- Repeats the mechanical checks at a frequency manual work cannot sustain
- Stays inside the scope a consultant has set, and never acts outside it
What our consultants do
- Run the testing: reconnaissance, exploitation, and chaining findings into attack paths
- Decide where to dig deeper, and what actually matters to your business
- Define the scope and configure the boundaries the tooling runs within
- Confirm every finding, then write and sign the report
Start with a penetration test
Most clients come to us for a scoped engagement first: a web application, an API, a cloud environment, a mobile app. That is a good way to see how we work before committing to anything longer, and it is often what an auditor or a customer is asking you for.
Once the report is delivered, the external estate is usually the part that keeps moving. That is the point at which continuous coverage starts to make sense.
Seven modules, assembled to your environment
Surface and Perimeter form the base package: one finds what you expose, the other tests it. The other five are added or removed independently.
Where the service stops
Coverage is continuous within a defined asset scope, with a defined set of monthly deliverables. A few things sit outside it, and they are worth knowing up front.
- It is not a replacement for deep point-in-time testing of a complex application.
- It is not intrusion detection, and it is not incident response.
- It does not remediate findings. We report and verify fixes; your team applies them.
- It reduces the time an exposure goes unnoticed. It cannot guarantee you will not be compromised.
- It is not monitored around the clock. Notification targets are set in business days.
Where to start
The base package covers external discovery and network testing for about $10,000 a year, billed annually. Other modules are quoted on your scope. We verify domain ownership and written authorisation before testing begins, so the first step is a conversation.