BSBlackthorn Security (704) 555-0198
Testing defenses since 2013

We break in first, and we write down how

Real penetration testing by people who do this every week, with findings ranked by what an attacker would actually do next. Free retest after you fix, always included.

12 yrstesting networks
480+engagements delivered
< 1 hrbreach response target
Freeretest after remediation
Engagements

Testing, response and the paperwork auditors want

Fixed price for defined scopes, quoted after a free scoping call, with a free retest included.

From $11,500

External network penetration test

Everything reachable from the internet, exploited not just scanned, with a ranked remediation plan.

From $16,000

Internal and Active Directory test

Assumed breach from a standard workstation, tracing the real path to domain admin.

From $9,800

Web and API application test

Authenticated testing against business logic, access control and injection, mapped to OWASP.

From $48,000

Red team exercise

Multi week objective based operation including phishing and physical entry, measuring detection not just entry.

From $2,900/mo

Incident response retainer

Guaranteed one hour response, pre negotiated terms and forensic imaging capacity held for you.

From $7,500

Compliance readiness assessment

Gap analysis for SOC 2, PCI DSS or HIPAA with a prioritized, costed remediation roadmap.

About Blackthorn

Twenty two testers, no offshore scan and forward

Blackthorn has been testing networks since 2013 and every engagement is delivered by a named consultant on our own payroll. We do not resell an automated scan with a logo on it. Reports are written to be handed to an engineer and to an auditor, which are two different audiences and we write for both.

•Every finding validated by hand, no unverified scanner output in a report
•Free retest of remediated findings within 90 days, in every fixed price scope
•Consultants hold OSCP, OSCE or equivalent hands on certification
Modern control room with people monitoring large digital displays and computer systems.
Reviews

From CISOs and IT directors

“They got domain admin in nine hours from a standard laptop and then spent a day explaining exactly how to make that impossible. That report changed our budget conversation.”

Tanya B., IT Director, manufacturing

“We called the hotline at eleven on a Sunday night. An engineer was in our bridge in thirty five minutes and containment started before midnight.”

Anonymous, Regional bank, ransomware incident

“Our auditor accepted the report without a single follow up question, which had never happened with our previous vendor.”

Gary N., Compliance manager, healthcare
FAQ

Testing scope, safety and results

Will testing take our systems down?

Very rarely, and we plan around it. Denial of service testing is excluded by default, we agree on a rules of engagement document before anything starts, and you have a named tester's direct number throughout. If something behaves unexpectedly we stop and call you within minutes rather than pressing on.

What is the difference between a vulnerability scan and a penetration test?

A scan lists things that might be exploitable. A penetration test proves which ones are, chains them together and shows you what an attacker reaches. We run scanners as one input, then every finding in the report is validated by hand, which is why you will not see pages of unverified informational noise.

Is the retest really free?

Yes, on any fixed price engagement, within 90 days of the report. You fix, we verify, and we issue an updated report showing findings as remediated. Auditors generally want that updated letter, and charging you for it would be charging you twice for the same engagement.

How quickly can you respond to an active breach?

Retainer clients get an engineer on a call within one hour, any hour, with terms already signed so nobody is negotiating a contract during an incident. Without a retainer we will still take your call on the hotline and we do take on emergency work, but the paperwork adds hours you will not want to spend.

Contact

Scope a test or call the hotline

Scoping calls are free and take about thirty minutes. If you are in an active incident right now, call the hotline instead of filling out a form.

Phone(704) 555-0198
Address300 S Tryon St, Suite 1600, Charlotte, North Carolina
HoursMon to Fri 8am to 6pm ET, breach hotline 24/7
AreaUnited States, on site testing nationwide