Penetration testing that shows what's reachable from the internet.
Before your auditor, your insurer, or an attacker does. Manual testing by certified engineers based in Montana.
Starting at $3,750 for a one time engagement, or $250 a month under contract.

Most people don't shop for a pentest, they're told to get one.
Usually it arrives as an email with a deadline attached. Whatever sent it, the question underneath is the same: what's actually exposed right now, and how bad is it?
What we've found running pentests across Montana
At a rural hospital, K12 environments, and insurance agencies across the state. None of which anybody inside the building knew about. We have yet to complete a test without finding something exploitable.
A scanner and a tester answer different questions.
Both have a place. Run scans monthly for visibility. Bring a tester when you need to know what an attacker could actually do with what the scanner found.
Five stages, start to finish.
You know the price before it begins, and the same named engineer stays with you through the debrief and the retest.
Certified ethical hackers, based in Montana.
Your test is run by our own staff, not subcontracted out. The engineer who tests your network can drive to your building, and has tested environments like yours.
“Our IT provider already handles security.”
Then the test tells you whether that is working, which is useful to both of you. Four things stay true either way.
Two ways to buy it.
A one time engagement, or testing as a service under contract. Both include the report, the debrief and the retest.
“We only have one public IP.
How much risk could we have?”
A rural Montana medical facility told us that before testing found exposure their size hadn't protected them from.
If someone else is asking for this
EHR migration
Vendors and health systems increasingly require independent testing before cutover. Bring the requirement document; we'll scope to it.
State and federal grants
Montana grant language often requires ongoing vulnerability assessment and security auditing, which a single annual test doesn't satisfy. The monthly CVE mapped reporting exists for exactly this.
HIPAA
The Security Rule requires ongoing risk analysis, not a one time assessment. A dated test plus a 90 day retest produces the evidence trail.
Cyber insurance
Renewal questionnaires ask for independent testing and named tester credentials. Ours are listed above; the report is written so you can answer the form from it directly.
Not sure which applies? Send us the document. We read these all the time.
FAQ
Frequently asked questions
How long does the whole thing take?
Three days of hands on testing, then your report, typically one to two weeks from the last day of testing.
Is the retest an extra charge?
No. A retest at 90 days is included, and there are no retest fees inside the retest window.
Who actually does the testing?
A named engineer from our Montana team, holding CISSP, GCIH, CEH, CySA+ and CompTIA PenTest+. Not subcontracted and you have a direct line to them for the whole engagement.
Will testing disrupt our systems?
Testing is done by hand, not by hammering your network with automated tools. We agree the window on the scoping call and work around your hours where it matters. If anything looks likely to affect a live system, we stop and check with you first. You also have a direct phone number for the person testing if you need to request a pause.
Can we see a sample report?
Yes. Ask on the scoping call and we'll send a sample from a test lab set up comparably to your environment.
Should we test external or internal?
Most organizations start external — that's what auditors, insurers and grant reviewers ask about first. If you need both we'll scope it on the call.
Does our IT provider have to be involved?
Your call. Some clients want their provider in the room from day one, others want a clean read first. Either way the report goes nowhere else.
What if you find something critical during the test?
You hear about it the same day. Anything actively exploitable gets raised immediately rather than held back for the report.
What happens to sensitive data you find?
Any credentials or confidential material we come across during testing are covered by the NDA, handled under the engagement's confidentiality terms, and destroyed when the engagement closes.

Get a number before you commit to anything.
The scoping call is quick and free, you'll have a price before we hang up.
