Sanctus Cybersecurity Sanctus Cybersecurity

Services / Penetration Testing

Penetration Testing for Iowa Businesses

A penetration test shows what an attacker could actually do with the weaknesses in your network. How far could they get, what could they reach, and what would it cost your business? Sanctus tests external networks, internal networks, and web applications for Iowa small and mid-sized businesses.

What a penetration test tells you

Anyone can run a scanner and hand you a list of vulnerabilities. A penetration test answers the questions that list cannot. Which of those issues actually matter, how do they combine, and how far could an attacker get? We find out whether someone starting from the internet, or from a single compromised laptop, could reach the data your business depends on.

That's the difference between knowing you have an unlocked door and watching someone walk through it. You come away with evidence, not guesses, and a short list of fixes that close the paths an attacker would use.

Types of penetration tests

External network penetration test

Simulated attacks against your internet-facing systems, such as firewalls, VPNs, remote access portals, email, and anything else exposed to the internet. The goal is to find exploitable weaknesses before real attackers do.

Internal network penetration test

Models what happens after a phishing email works or a VPN account is compromised. We look for lateral movement paths, privilege escalation, weaknesses in Active Directory, and gaps in network segmentation.

Web application penetration test

Manual testing of authentication, authorization, session management, APIs, and business logic, aligned with the OWASP Top 10 and real-world attack patterns. Ideal for customer portals, dealer or partner portals, and internal business applications.

How it works

  1. 1. Scoping

    We talk through your environment, goals, and concerns, then agree in writing on scope, excluded systems, testing windows, and emergency contacts. You get a quote based on the agreed scope before testing begins.

    A few days, mostly on your schedule

  2. 2. Testing

    Hands-on testing by certified testers within the agreed scope. Network tests follow the Penetration Testing Execution Standard (PTES), and web application tests also follow the OWASP Web Security Testing Guide.

    Typically one to two weeks, depending on scope

  3. 3. Reporting and walkthrough

    You receive a plain-English report, then we walk your team through what we found, why it matters, and what to fix first.

    Report within a week, then a one to three hour walkthrough

What you receive

  • Executive summary for owners and leadership, explaining overall risk in business terms
  • Findings report for your IT team, with a CVSS severity rating, evidence, and specific remediation steps for each issue
  • Prioritized remediation roadmap so your team knows what to fix first
  • Results walkthrough to answer questions from leadership and IT

What a penetration test costs

Most of our penetration tests cost $5,000 to $15,000. Where yours lands depends on a few factors.

  • The number of internet-facing systems in scope
  • The size of your internal network and number of locations
  • How many web applications or portals are included, and how complex they are
  • Whether external, internal, and web testing are combined in one engagement

Not sure a full penetration test is the right starting point? A vulnerability assessment or security posture review costs less and is often the better first step.

Who it's for

  • Small and mid-sized Iowa businesses without a dedicated security team
  • Organizations whose cyber insurance renewal or a customer's vendor questionnaire asks for a recent penetration test
  • Companies that have finished a vulnerability assessment and want to know what is actually exploitable
  • Teams launching a new customer portal, office, or major system that want it tested first

Testing is performed by GPEN, GCIH, and GSEC certified testers. We are independent. We don't manage your IT or sell security products, so we have no reason to downplay what we find.

Penetration testing questions

How much does a penetration test cost for a small business?

Our penetration tests typically run $5,000 to $15,000. The price depends on scope, including how many internet-facing systems you have, the size of your internal network and number of locations, and how many web applications are included. We scope every engagement up front, so you have a quote before any testing starts.

How long does a penetration test take?

Scoping usually takes a few days of back-and-forth, mostly on your schedule. Hands-on testing typically takes one to two weeks, depending on how much is in scope. The report is ready within a week of testing, and the results walkthrough with your team usually takes one to three hours.

What is the difference between a penetration test and a vulnerability assessment?

A vulnerability assessment finds and validates weaknesses across your environment. A penetration test goes further and actually exploits them, chaining issues together to show how far an attacker could get and what they could access. If you have never had a security assessment, a vulnerability assessment or posture review is often the better first step.

How often should a business get a penetration test?

Common guidance is at least once a year, and again after significant changes such as a new office, a major system migration, or a new customer-facing application. Many cyber insurance and customer security questionnaires ask when your last test was.

What methodology do you follow?

Network penetration tests follow the Penetration Testing Execution Standard (PTES), from pre-engagement and intelligence gathering through exploitation, post-exploitation, and reporting. Web application tests also follow the OWASP Web Security Testing Guide and cover the OWASP Top 10. Findings are rated using CVSS v4.0 so severity is consistent and comparable.

Will testing disrupt our business?

Before any testing starts we agree on written rules of engagement covering what is in scope, which systems are excluded, when testing happens, and who to call if something unexpected comes up. You will know what we are doing and when.

Do you only work with businesses in Cedar Rapids?

No. We are based in Cedar Rapids, Iowa, and work with businesses anywhere in the United States. All of our testing can be performed remotely, so your location is never a barrier.

What do we receive at the end?

An executive summary for leadership, a detailed findings report with evidence and remediation steps for your IT team, a prioritized remediation roadmap, and a walkthrough of the results.

Ready to find out where you stand?

Tell us what's prompting the question. We'll come back with a few questions of our own, not a sales pitch.

Find Out Where You Stand