Currently dealing with a breach or active incident?Call 406-924-3731×
≡
Penetration testing · Montana

Penetration testing that shows what's reachable from the internet.

Before your auditor, your insurer, or an attacker does. Manual testing by certified engineers based in Montana.

Starting at $3,750 for a one time engagement, or $250 a month under contract.

★★★★★5.0 on Google and Birdeye.Read all reviews on Google →
A security engineer in a server room
$3,750
Starting at
for one time engagements
$250
Starting at
for ongoing contracts
1–2 weeks
Typical report turnaround
Since 2013
Our team serving Montana
supporting businesses and nonprofits across the state
Why you are here

Most people don't shop for a pentest, they're told to get one.

Usually it arrives as an email with a deadline attached. Whatever sent it, the question underneath is the same: what's actually exposed right now, and how bad is it?
‍

The software vendor
From: compliance@[EHR vendor]
Subject: Vendor security review — action required before migration
Before we can schedule your migration, we need the executive summary of a penetration test performed within the last twelve months, together with evidence that any critical or high findings have been remediated.
Please return this by the end of the month so the project timeline is not affected.
The prime contractor
From: [prime contractor] — supplier compliance
Subject: Flow down requirement — NIST 800-171 / CMMC evidence
As a condition of the subcontract, suppliers handling controlled unclassified information must provide evidence of independent security testing of externally reachable systems, along with a documented remediation plan.
Please confirm your most recent test date and attach the summary. Award cannot proceed without it.
What manual testing finds

What we've found running pentests across Montana

At a rural hospital, K12 environments, and insurance agencies across the state. None of which anybody inside the building knew about. We have yet to complete a test without finding something exploitable.
‍

A lab server running Windows Server 2008
Still in production and reachable. A system people used every day, running an operating system that stopped receiving security patches in January 2020.
A camera system open to the outside world
Installed by a vendor, managed by a vendor, exposed by a vendor. Nobody on staff had put it there, and nobody on staff knew it was reachable at all.
VPN access without multifactor authentication
More than thirty subcontractors held VPN access with no MFA. One stolen password from an attacker inside the network with the same reach as staff.
Sample attack path — illustrative
Clinical network Internet ISP handoff FirewallPorts forwarded to NVR and door access Remote workersVPN, no MFA MDF closetStacked switches, every clinical port NVRPublished, default login Door accessPublished, default login Lab serverOS end of life Domain controllerEnumerable externally EHR and filesPatient records WorkstationsClinical staff 1 2 3 4 5 What we've found 1 Servers published to the internetThe NVR and the door accesscontroller, both with default logins. 2 Remote access without MFAA stolen password is a secondway onto the same flat network. 3 Flat network, no segmentationEverything is reachable from anyworkstation or server on the LAN. 4 Domain controller exposedEnumerable from outside thenetwork, and accounts are next. 5 Server past end of lifeNo patches, beside patientrecords. Already rightGuest Wi-Fi is on its own segmentwith no route to clinical systems. Two servers published to the internet, remote access without MFA, and a flat network behind all of it — so any foothold reaches every host.
Two low findings and one flat network is a path, not three tickets.
A scanner reports each of these separately, ranked by severity in isolation. A tester follows them in order and tells you where they end up. That chain is what a report is for, and it is the part a scan cannot produce. A vulnerability scan can flag an out of date operating system. It can't tell you that the OS is on a machine your lab still depends on, or that your camera vendor left a management interface on the public internet.
Scan or test

A scanner and a tester answer different questions.

Both have a place. Run scans monthly for visibility. Bring a tester when you need to know what an attacker could actually do with what the scanner found.

Vulnerability scan
Manual penetration test
What it does
Checks systems against a database of known issues
A person tries to get in, the way an attacker would
What it finds
That a system is out of date
That the out of date system is the one your lab depends on
Context
None. Everything is a finding
Ranked by real business impact, not CVSS score
Chained attacks
Not tested
Tested. Two low findings that combine into one serious one
Cadence
Monthly, for visibility
Annually, or before an audit, migration or funding review
Cost
Included in monitoring
Starting at $3,750, or $250 a month under contract
The engagement

Five stages, start to finish.

You know the price before it begins, and the same named engineer stays with you through the debrief and the retest.

01
Scoping call
Thirty minutes, no charge, and nothing installed.
→ A price, before we hang up
02
Testing
Manual testing by a named Montana engineer, external or internal as scoped.
→ Anything critical, the day we find it
03
Report
A single page summary for the board, with technical detail underneath.
→ Findings ranked by business impact
04
Debrief
A walkthrough with the engineer who did the testing, and your IT provider in the room if you want them.
→ The report becomes a plan of work
05
Retest
We verify the fixes rather than take your word for them, at no extra charge within the agreed window.
→ Dated evidence the work was done
Not sure whether you need a full test or something smaller?
Read us the requirement on the scoping call. Thirty minutes, no charge, and you will have a price before we hang up.
Who does the testing

Certified ethical hackers, based in Montana.

Your test is run by our own staff, not subcontracted out. The engineer who tests your network can drive to your building, and has tested environments like yours.

Montana local staff
Nothing is subcontracted and nothing leaves the state. The engineer who runs your test is the one you meet at the debrief.
CISSP, GCIH and CompTIA PenTest+
CISSP is the credential your insurer's questionnaire asks about by name. GCIH and PenTest+ are the offensive ones examined on how attackers get in, not on how to configure wireless.
Experience in environments like yours
Clinics, municipalities, manufacturers and contractors, plus the incident work that shows how these systems actually fail.
If you already have a provider

“Our IT provider already handles security.”

Then the test tells you whether that is working, which is useful to both of you. Four things stay true either way.

We tell you what we find
Everything goes in the report, including anything that reflects on whoever set it up. That isn't a pitch; it's what auditors look at.
Findings your IT can act on
Written so your existing team or provider can work from them directly, ranked by real impact rather than by scanner score.
You decide who sees it
It is your report. We do not send it to anyone you have not told us to send it to, including your provider.
You're not locked into anything
A test is a defined piece of work. Ongoing testing is a separate decision you make afterwards, if you want it.
What it costs

Two ways to buy it.

A one time engagement, or testing as a service under contract. Both include the report, the debrief and the retest.

Standard penetration test
Starting at $3,750
A scoped engagement with the report, the debrief and the retest all included. Priced on the scoping call, before any work begins.
Ongoing testing under contract
Starting at $250 / month
Monthly assessments mapped to CVEs, with a focused retest, which builds the dated evidence package reviewers and grant funders ask for.
Case study

“We only have one public IP.
How much risk could we have?”

A rural Montana medical facility told us that before testing found exposure their size hadn't protected them from.

Because they needed to prove ongoing security work for state and federal grant funding, we followed the test with monthly vulnerability assessments mapped to CVEs and a focused 90 day retest on everything they'd fixed. That combination gave them a dated evidence package for reviewers.
Their funding held.
Read the case study →
“They understand that small communities have different needs than large organizations.”
Loren T.
Mayor of Fairfield
REQUIREMENTS

If someone else is asking for this

EHR migration

Vendors and health systems increasingly require independent testing before cutover. Bring the requirement document; we'll scope to it.

State and federal grants

Montana grant language often requires ongoing vulnerability assessment and security auditing, which a single annual test doesn't satisfy. The monthly CVE mapped reporting exists for exactly this.

HIPAA

The Security Rule requires ongoing risk analysis, not a one time assessment. A dated test plus a 90 day retest produces the evidence trail.

Cyber insurance

Renewal questionnaires ask for independent testing and named tester credentials. Ours are listed above; the report is written so you can answer the form from it directly.

Not sure which applies? Send us the document. We read these all the time.

FAQ

Frequently asked questions

How long does the whole thing take?

Three days of hands on testing, then your report, typically one to two weeks from the last day of testing.

Is the retest an extra charge?

No. A retest at 90 days is included, and there are no retest fees inside the retest window.

Who actually does the testing?

A named engineer from our Montana team, holding CISSP, GCIH, CEH, CySA+ and CompTIA PenTest+. Not subcontracted and you have a direct line to them for the whole engagement.

Will testing disrupt our systems?

Testing is done by hand, not by hammering your network with automated tools. We agree the window on the scoping call and work around your hours where it matters. If anything looks likely to affect a live system, we stop and check with you first. You also have a direct phone number for the person testing if you need to request a pause.

Can we see a sample report?

Yes. Ask on the scoping call and we'll send a sample from a test lab set up comparably to your environment.

Should we test external or internal?

Most organizations start external — that's what auditors, insurers and grant reviewers ask about first. If you need both we'll scope it on the call.

Does our IT provider have to be involved?

Your call. Some clients want their provider in the room from day one, others want a clean read first. Either way the report goes nowhere else.

What if you find something critical during the test?

You hear about it the same day. Anything actively exploitable gets raised immediately rather than held back for the report.

What happens to sensitive data you find?

Any credentials or confidential material we come across during testing are covered by the NDA, handled under the engagement's confidentiality terms, and destroyed when the engagement closes.

The Rimrocks above Billings, Montana
Next step

Get a number before you commit to anything.

The scoping call is quick and free, you'll have a price before we hang up.

01
Been told to get a test?
Read us the requirement and we'll tell you what it actually asks for.
02
Know what you need?
Tell us the scope and we'll price it on the call.
03
Not sure yet?
No charge and no pitch for the conversation either way.
Testing by our own Montana engineers. Report, debrief and retest included.
“James and his team at Big Sky Cybersecurity are an integral part of my business' team as they help to protect my business from various cyber threats.”
Chad M.
Accounting firm owner
★★★★★ 5.0 on Google and Birdeye · Read the reviews
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
We reply within one business day.