Home / Services / Modular Services / IT Services /  24/7 Security operations / Penetration Testing | Portfolio & Costs

Modular services

Penetration Testing | Portfolio & Costs

Advanced Cybersecurity Solutions by Modular Services

Strengthen Your Firm’s Cyber Defences

About Modular Services

Securing the digital landscape is at the heart of what we do at Modular Services.

With over a decade of experience in the legal sector, we understand the specific challenges faced by law firms when it comes to managing cyber risk.

Our team of highly skilled professionals, including certified penetration testers, delivers best-in-class services to ensure your firm’s most sensitive data remains secure.

Our Penetration Testing Portfolio

Emulating the role of a malicious external actor attempting to breach your firm’s network perimeter.

Simulating internal threats, testing privilege escalation, and identifying lateral movement opportunities within your network.

Identifying and exploiting critical vulnerabilities in your firm’s web applications.

Conducting code reviews and security assessments to uncover exploitable vulnerabilities.

Testing the security of your corporate Wi-Fi network to prevent unauthorised access.

Identifying blind spots in your firm’s digital footprint and safeguarding against impersonation risks.

Reviewing your cloud configurations to identify and rectify potential security gaps.

Testing the physical security of your firm’s premises by attempting unauthorised access to sensitive areas.

Conducting phishing, vishing, and other social engineering exercises to assess staff awareness and readiness.

Ensuring your firm meets the latest UK data protection and cybersecurity regulations.

Testing the robustness of your password policies to prevent credential theft or reuse attacks.

Key Penetration Testing Insights

Internal Network Security

Our testing frequently reveals vulnerabilities such as weak access control policies and credentials stored in plain text within configuration files. These issues are easily exploitable by malicious actors if not addressed swiftly.

Password Hygiene

We regularly observe weak password policies that expose firms to credential-based attacks. Strong password complexity and two-factor authentication (2FA) are essential to maintaining security.

Patching and Updates

Delays in applying security patches leave law firms vulnerable to attack. A comprehensive patch management process is vital to securing your IT infrastructure.


Factors Influencing Costs

The total cost of penetration testing depends on several key factors:

Organisation Size


The number of assets being tested greatly influences cost and duration:

    • 1-50 assets (small scope): Typically completed by one tester, taking approximately 10 days.
    • 50-250 assets (medium scope): Usually requires 2-4 testers.
    • 250-1000 assets (large scope): Generally requires 4-6 testers.
    • 1000+ assets (very large scope): Requires a dedicated team of experts.

 

Type of Penetration Test: 


The type of test will impact the complexity and cost. Some examples include:

    • Network Penetration Test (Internal or External)
    • Web Applications Penetration Test: Focused on web applications, mostly external but can also be internal.
    • Wireless Penetration Testing: Requires on-site testing and specialised equipment.
    • Cloud Security Assessment: Reviews cloud configurations and identifies security gaps.
    • Physical Penetration Testing: Involves travel to the site and the use of specialised tools.

 

 

Engagement Complexity

The complexity of the organisation’s infrastructure and systems being tested will influence the duration and the number of testers required.

Testing Methodology

❯  Black-box engagement
No prior information provided, most challenging to execute, posing as an external attacker.

❯  Grey-box engagement
Limited information provided, simulates an “assume breach” mindset. Ideal for firms new to penetration testing.

❯  White-box engagement
Full access provided, testing process flaws and assessing damage potential from a compromised asset.

Tester Expertise and Costs

Hourly rates for experienced penetration testers range from €250 to €500. Specialised services like reverse engineering or advanced product security evaluations may incur higher fees. Testers with advanced expertise are essential for uncovering complex security flaws that could be missed by less experienced professionals.

Find out average costs

Average Market Costs (5-Day Engagements)

  • Network Penetration Test – €10,000
  • Web Applications Penetration Test – €12,500
  • Web Applications Security Assessment – €7,000
  • Wireless Penetration Testing – €5,500
  • Digital Footprint Assessment – €3,000
  • Cloud Security Assessment – €15,000
  • Physical Penetration Testing – €5,000

Example Offer

A 5-day grey-box network penetration test (small scope) may look like this:

Item Description Cost
Testing Team Two certified penetration testers conducting the assessment €10,000
Testing Plan Document outlining scope, objectives, methodology, and timeline €200
Testing Report Detailed findings, recommendations, and evidence from the test €2,000
Testing Presentation Summary of key results and conclusions €500
Testing Tools Software and tools used for the engagement €1,000
Total Cost: €13,700

Contact us

Committed to technical excellence, industry best practice, methodologies, and accreditation.

Read the lastest
news and insights.