Penetration testing in Billings, MT
A vulnerability scan with a cover page is not a penetration test. Insurers and bank examiners increasingly know the difference.
A named tester spends days trying to reach what matters: domain admin, wire approvals, patient data, the ERP.
A report someone else will accept, with a free retest of every critical and high finding within 90 days.
Our own staff, out of the downtown office at 404 N 31st St, #414. Nothing is subcontracted.
“They take the time to understand how a town operates and recommend security measures that are practical, effective, and make sense for a small municipality.”

10 min
Median first response
for security issues, measured in our own system over the last 90 days
100+
Incidents supported
by our team
7,500+
Devices monitored
under current contracts
On Google and Birdeye
Who in Billings has to do this, and who's asking.
Six reasons a Billings organization ends up needing a real test, and what the person asking actually needs back.

Dealerships and finance offices
Annual testing plus vulnerability assessments every six months, unless you run continuous monitoring. Reaches dealerships, mortgage brokers, tax preparers and title companies.
They want
A dated test and the six month assessments.

Banks and credit unions
Independent testing on a defined cadence. If your last test was run by the firm that manages your network, independence will come up.
They want
A tester who isn't the firm that runs your network.

Anyone taking cards
Internal and external testing annually, plus segmentation testing to prove the card environment is isolated. Restaurants, retailers and clinics with a front desk terminal.
They want
Proof the card environment is actually separate.

Healthcare
HIPAA doesn't name penetration testing, but an honest security risk analysis is hard to complete without one.
They want
Evidence behind the risk analysis, not a scan.

Cyber insurance renewals
The most common reason companies call us. The application asks whether you test annually, and answering yes after only a scan is how claims get contested.
They want
A yes you can back up if a claim is ever reviewed.

Grants and federal contracts
Grant conditions and contract clauses increasingly name a test and a date, and someone else has to accept the report.
They want
A report written to be accepted by a third party.
What Billings environments look like from the inside.
We test a lot of similar networks in the valley, and the same three findings come up.
Finding one
The 2016 domain controller nobody wants to touch
It runs a line of business application the vendor stopped supporting, so replacing it means replacing the application. It is often our fastest route to domain admin.
Finding two
Flat networks
In manufacturing, the office LAN and the shop floor often share a switch. From a workstation in accounting, nothing stands between us and the machine controllers.
Finding three
Remote access on shared credentials
Satellite clinics, field crews and seasonal operations. Someone has a VPN account several staff know, unchanged since a former employee left.
What you get, and what we won't do.
A report written to be read by an owner, an examiner and an insurer, not forty pages of scan output.
What you receive when the test closes
✓
Executive summary, five minutes to read
✓
Attack path narrative with screenshots
✓
Findings ranked by business impact
✓
Remediation plan with specific fixes
✓
Free retest of critical and high findings within 90 days
✓
Live debrief onsite, if you want it
Findings, redacted sample
HIGH
Domain admin reachable from a guest workstation
An unpatched legacy server let us move from the front desk to full control of the domain.
MEDIUM
Office and shop floor share a network
Machine controllers were reachable from an accounting workstation.
LOW
Default credentials on a printer admin page
Exposed scan to email settings and stored addresses.
Illustrative. Ask for a full redacted sample report and we'll email it the same day.
We won't exploit live plant systems
If you have OT worth testing, we test a replica or test passively, and say so in the scope.
We won't use the test to sell you the fix
If something we find is work we could take on, we'll say so plainly. The report is yours to hand to your existing provider or anyone else.
Timeline and cost.
Pricing comes down to how much there is to test. Here is where each test starts, so you can budget before the scoping call. If your situation is simpler, we'll quote it that way.
External network test
Three days of active testing, onsite or remote. The report typically follows within a week, with a walkthrough from the lead tester and the 90 day retest.
Typical scope
A clinic or firm with one or two public addresses, up to a larger organization with a range of them.
Starting at $250 per external IP, per month.
Scope an external testInternal network test
Three days or more, scoped to network size and segments, including any Active Directory or IoT environments.
Typical scope
Active Directory testing, or critical infrastructure where a flat network is the concern.
Starting at $550 per network, per month.
Scope an internal testSegmentation testing (PCI)
Scoped to how many segments must be proven separate. Usually shorter than a full internal test.
Typical scope
A card environment, a bank or credit union, or a town running IoT devices with city operations.
Priced in the same per network bands as internal testing.
Scope segmentation testingWho does the testing, and what that gets you.
Our own staff, out of the downtown office. Ask who is assigned and what they hold before you sign. Anyone should be able to answer.
Your insurer gets findings it accepts
Forensics training is why the report shows how an attacker would move, not just which port was open.
Your examiner gets an independent tester
We are not the firm that runs your network, and we work alongside the one that does.
Your team gets a deliverable it can act on
Scoping, rules of engagement and a written report built to a recognized standard.
You know exactly who is inside your network
The tester is named before work starts and works out of the Billings office. Nothing is handed to a firm you don't know.

Wild horses in the Pryor Mountains, south of Billings
Frequently asked questions
Is this an actual penetration test, or a vulnerability scan with a report attached?
Real test. A person, by hand, with a scan as one input among many. We're happy to show you a redacted sample report before you sign anything — ask and we'll email it the same day.
Will penetration testing break something in our production environment?
The risk isn't zero, which is why scope and rules of engagement come first and get signed by you. We agree in writing what's off limits, what hours we test, and who to call if something goes sideways. In practice production disruption is rare, and we design around it.
Do we still need a penetration test if we already have an IT provider?
That's the main argument for it. A test conducted by the people who built the network isn't independent, and examiners and insurers are starting to say so explicitly. We work alongside your existing provider and share findings with them directly if you want us to.
How often should a Billings business run a penetration test?
Annually is the floor for most compliance frameworks, and after any major infrastructure change. If you moved to a new ERP, opened a location, or migrated email tenants, the last test is stale.
Can you test remotely, or do you come to our office in Billings?
Both. External testing is remote. Internal testing usually means a day on site, and we drive — Billings, Laurel, Lockwood, Columbus, Hardin, Red Lodge. We're twenty minutes from most of the valley.
What do we actually receive at the end of the engagement?
An executive summary a board or an owner can read in five minutes, a technical narrative showing the actual attack path step by step with screenshots, findings prioritised by business impact rather than CVSS score, and a remediation plan with specific fixes. A live debrief on site in your conference room if you want it.
Do you retest after we have fixed the findings?
Yes. Every critical and high finding is retested free within 90 days, so you have proof the holes are closed for your insurer or your examiner rather than just a claim that they were fixed.
Who performs the testing, and do you subcontract any of it?
Our own staff, out of the downtown office at 404 N 31st St, #414. We don't subcontract Billings engagements to a third party firm, and we don't hand you a report generated by someone you'll never speak to.
Tell us what needs testing and who's asking.
The scoping call is free. You leave it with a starting price, and a redacted sample report if you'd like one.
Billings office: 404 N 31st St, #414, Billings, MT 59101.
“Great company, very helpful and professional. James is great at what he does and always eager to assist with an issue.”
Eric P., K12 school, Helena
