Currently dealing with a breach or active incident?Call 406-924-3731×
≡
Billings, Yellowstone County and South Central Montana

Penetration testing in Billings, MT

A vulnerability scan with a cover page is not a penetration test. Insurers and bank examiners increasingly know the difference.

A named tester spends days trying to reach what matters: domain admin, wire approvals, patient data, the ERP.

A report someone else will accept, with a free retest of every critical and high finding within 90 days.

Our own staff, out of the downtown office at 404 N 31st St, #414. Nothing is subcontracted.

“They take the time to understand how a town operates and recommend security measures that are practical, effective, and make sense for a small municipality.”
Loren T., Mayor of Fairfield
Two engineers working at a network rack

10 min

Median first response

for security issues, measured in our own system over the last 90 days

100+

Incidents supported

by our team

7,500+

Devices monitored

under current contracts

5.0★★★★★

On Google and Birdeye

Who's required to test

Who in Billings has to do this, and who's asking.

Six reasons a Billings organization ends up needing a real test, and what the person asking actually needs back.

Cars on a dealership lot
FTC Safeguards Rule

Dealerships and finance offices

Annual testing plus vulnerability assessments every six months, unless you run continuous monitoring. Reaches dealerships, mortgage brokers, tax preparers and title companies.

They want

A dated test and the six month assessments.

Billings, Montana
Your examiner

Banks and credit unions

Independent testing on a defined cadence. If your last test was run by the firm that manages your network, independence will come up.

They want

A tester who isn't the firm that runs your network.

A card being swiped at a payment terminal
PCI DSS v4.0

Anyone taking cards

Internal and external testing annually, plus segmentation testing to prove the card environment is isolated. Restaurants, retailers and clinics with a front desk terminal.

They want

Proof the card environment is actually separate.

Front desk at a Montana clinic
HIPAA risk analysis

Healthcare

HIPAA doesn't name penetration testing, but an honest security risk analysis is hard to complete without one.

They want

Evidence behind the risk analysis, not a scan.

A small business coffee shop
Your insurer

Cyber insurance renewals

The most common reason companies call us. The application asks whether you test annually, and answering yes after only a scan is how claims get contested.

They want

A yes you can back up if a claim is ever reviewed.

Signing a government contract agreement
The grant administrator

Grants and federal contracts

Grant conditions and contract clauses increasingly name a test and a date, and someone else has to accept the report.

They want

A report written to be accepted by a third party.

From the inside

What Billings environments look like from the inside.

We test a lot of similar networks in the valley, and the same three findings come up.

Finding one

The 2016 domain controller nobody wants to touch

It runs a line of business application the vendor stopped supporting, so replacing it means replacing the application. It is often our fastest route to domain admin.

Finding two

Flat networks

In manufacturing, the office LAN and the shop floor often share a switch. From a workstation in accounting, nothing stands between us and the machine controllers.

Finding three

Remote access on shared credentials

Satellite clinics, field crews and seasonal operations. Someone has a VPN account several staff know, unchanged since a former employee left.

What you get

What you get, and what we won't do.

A report written to be read by an owner, an examiner and an insurer, not forty pages of scan output.

What you receive when the test closes

✓

Executive summary, five minutes to read

✓

Attack path narrative with screenshots

✓

Findings ranked by business impact

✓

Remediation plan with specific fixes

✓

Free retest of critical and high findings within 90 days

✓

Live debrief onsite, if you want it

Findings, redacted sample

HIGH

Domain admin reachable from a guest workstation

An unpatched legacy server let us move from the front desk to full control of the domain.

MEDIUM

Office and shop floor share a network

Machine controllers were reachable from an accounting workstation.

LOW

Default credentials on a printer admin page

Exposed scan to email settings and stored addresses.

Illustrative. Ask for a full redacted sample report and we'll email it the same day.

We won't exploit live plant systems

If you have OT worth testing, we test a replica or test passively, and say so in the scope.

We won't use the test to sell you the fix

If something we find is work we could take on, we'll say so plainly. The report is yours to hand to your existing provider or anyone else.

Find out what's actually reachable
The scoping call is free. You leave it with a starting price, and a redacted sample report if you'd like one.
Timeline and cost

Timeline and cost.

Pricing comes down to how much there is to test. Here is where each test starts, so you can budget before the scoping call. If your situation is simpler, we'll quote it that way.

External network test

Three days of active testing, onsite or remote. The report typically follows within a week, with a walkthrough from the lead tester and the 90 day retest.

Typical scope

A clinic or firm with one or two public addresses, up to a larger organization with a range of them.

Starting at $250 per external IP, per month.

Scope an external test

Internal network test

Three days or more, scoped to network size and segments, including any Active Directory or IoT environments.

Typical scope

Active Directory testing, or critical infrastructure where a flat network is the concern.

Starting at $550 per network, per month.

Scope an internal test

Segmentation testing (PCI)

Scoped to how many segments must be proven separate. Usually shorter than a full internal test.

Typical scope

A card environment, a bank or credit union, or a town running IoT devices with city operations.

Priced in the same per network bands as internal testing.

Scope segmentation testing
Credentials

Who does the testing, and what that gets you.

Our own staff, out of the downtown office. Ask who is assigned and what they hold before you sign. Anyone should be able to answer.

Your insurer gets findings it accepts

Forensics training is why the report shows how an attacker would move, not just which port was open.

GIAC GCFA, GCFE and GNFA

Your examiner gets an independent tester

We are not the firm that runs your network, and we work alongside the one that does.

Independent of your IT provider

Your team gets a deliverable it can act on

Scoping, rules of engagement and a written report built to a recognized standard.

GIAC GCIH, PenTest+, and CISSP

You know exactly who is inside your network

The tester is named before work starts and works out of the Billings office. Nothing is handed to a firm you don't know.

Background checked staff, not subcontractors
Wild horses in the Pryor Mountains, south of Billings

Wild horses in the Pryor Mountains, south of Billings

FAQ

Frequently asked questions

Is this an actual penetration test, or a vulnerability scan with a report attached?

Real test. A person, by hand, with a scan as one input among many. We're happy to show you a redacted sample report before you sign anything — ask and we'll email it the same day.

Will penetration testing break something in our production environment?

The risk isn't zero, which is why scope and rules of engagement come first and get signed by you. We agree in writing what's off limits, what hours we test, and who to call if something goes sideways. In practice production disruption is rare, and we design around it.

Do we still need a penetration test if we already have an IT provider?

That's the main argument for it. A test conducted by the people who built the network isn't independent, and examiners and insurers are starting to say so explicitly. We work alongside your existing provider and share findings with them directly if you want us to.

How often should a Billings business run a penetration test?

Annually is the floor for most compliance frameworks, and after any major infrastructure change. If you moved to a new ERP, opened a location, or migrated email tenants, the last test is stale.

Can you test remotely, or do you come to our office in Billings?

Both. External testing is remote. Internal testing usually means a day on site, and we drive — Billings, Laurel, Lockwood, Columbus, Hardin, Red Lodge. We're twenty minutes from most of the valley.

What do we actually receive at the end of the engagement?

An executive summary a board or an owner can read in five minutes, a technical narrative showing the actual attack path step by step with screenshots, findings prioritised by business impact rather than CVSS score, and a remediation plan with specific fixes. A live debrief on site in your conference room if you want it.

Do you retest after we have fixed the findings?

Yes. Every critical and high finding is retested free within 90 days, so you have proof the holes are closed for your insurer or your examiner rather than just a claim that they were fixed.

Who performs the testing, and do you subcontract any of it?

Our own staff, out of the downtown office at 404 N 31st St, #414. We don't subcontract Billings engagements to a third party firm, and we don't hand you a report generated by someone you'll never speak to.

How it starts

Tell us what needs testing and who's asking.

The scoping call is free. You leave it with a starting price, and a redacted sample report if you'd like one.

01
Ready now?
Call 406-924-3731 or send the form. Someone in Billings picks up, or you hear back within one business day after hours.
02
Not sure you need a test?
Ask for the sample report and a scoping call. If a scan or an assessment is the better fit, we'll say so.
03
Comparing prices?
Every price is published. See the pricing page before you call.
5.0 on Google and Birdeye.

Billings office: 404 N 31st St, #414, Billings, MT 59101.

“Great company, very helpful and professional. James is great at what he does and always eager to assist with an issue.”

Eric P., K12 school, Helena

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
We reply within one business day.