What Does a Security Test Cost for a Small Site?
By CodexierPublished 4 min read
'Security test' can mean anything from a free online scan to weeks of manual work by specialists. The price range is correspondingly wide, which makes quotes hard to compare. This guide separates automated scans from manual penetration tests, explains what drives the cost of each, describes what a useful report contains, and helps you decide which one your site actually needs. For most small business websites the honest answer is a good scan plus solid maintenance, not a full penetration test.
Automated scans vs manual tests
| Aspect | Automated scan | Manual penetration test |
|---|---|---|
| What it finds | Known vulnerabilities, outdated versions, missing headers, open ports | The above plus logic flaws, access control errors, chained attacks |
| How it works | A tool runs predefined checks | A tester explores the application like an attacker |
| Time | Minutes to hours | Days, sometimes weeks |
| Price driver | Tool licence or a small fixed fee | Number of tester days |
| False positives | Common, needs interpretation | Few, findings are verified |
Scope and what drives the price
Penetration tests are priced by time, and time is driven by scope. Rates vary between firms and we do not quote market figures here, but you can compare quotes by looking at what is included. Ask each supplier to state the number of days and exactly what will be tested.
- Number of applications, domains and APIs in scope.
- Number of user roles to test: visitor, customer, admin. Each role adds work.
- Whether the mobile app and its backend are included.
- Whether the test is done with credentials (grey box) or from outside only (black box).
- Whether a retest after fixes is included, which it should be.
- Reporting requirements, such as a management summary for a customer or a certification.
What the report should contain
The report is what you are really paying for. A good one is readable by both management and developers, and every finding can be acted on.
Summary
The overall risk level in plain language, for management or the customer who asked for the test.
Findings with severity
Each vulnerability rated, often on the CVSS scale, with the business consequence explained.
Reproduction steps
Exactly how the finding was triggered, so developers can reproduce and verify the fix.
Recommendations
Concrete fixes in priority order, not just 'update your software'.
Be wary of a 'penetration test' report that is mostly the output of an automated scanner with a logo on top. The give-away is findings without reproduction steps, and many low-priority items with no context.
Fixing findings afterwards
A test does not make a site safer; the fixes do. Budget for them before ordering the test. Critical and high findings should be fixed within days, medium within weeks. Then retest to verify. If you have a web agency or maintenance partner, involve them in planning the test so fixes can start immediately.
For a personal data breach, remember the 72-hour rule: under GDPR you must report certain breaches to IMY within 72 hours of discovering them. A test that reveals a past breach can trigger that duty.
When a scan is enough
For a company website with contact forms on WordPress or a hosted platform, a scan combined with regular updates, backups, strong logins and security headers covers the realistic risks. Our DIY website health check and WordPress security checklist take you through the basics.
A manual penetration test becomes relevant when you handle customer accounts, sensitive data or payments in custom code, when a customer or insurer requires it, or when NIS2 brings you into scope as a supplier. Our website and app health audit starts from 4 990 kr and covers scanning, configuration and prioritised fixes; our performance and security optimization carries out the hardening. For a formal manual penetration test we recommend an independent specialist, and we fix the findings. Book a call to find out which level fits.
Frequently asked questions
How often should a small business run a security scan?
At least monthly for a site that is regularly updated, and after every larger change. Many maintenance plans include continuous scanning.
Is a free online scanner good enough?
It is a fine first check of headers, certificates and obvious issues. It will not find logic flaws or check logged-in areas, and results need interpretation.
Do we need a pentest for GDPR?
GDPR requires appropriate security measures, not a specific test. For systems with sensitive personal data, regular testing is part of showing that your measures are appropriate.
Should the same company that built the site test it?
For a formal penetration test, an independent tester is better. For scans and routine checks, your developer or maintenance partner is fine.
Unsure what level of testing you need?
Book 15 minutes. Tell us what your site does and what data it handles, and we will tell you whether a scan, an audit or a full penetration test is the right step.
Book a free 15-minute call