Penetration Testing


ExcalTech’s penetration testing services safely test your network the way a real attacker would—so you can uncover security gaps before they become a business-disrupting incident. Get clear, actionable findings and a practical plan to strengthen your defenses.

Find Out What a Hacker Would Find. Before a Hacker Does.

Your business runs on technology you trust every day. A penetration test shows you, with proof, whether that trust is earned. We safely attack your network the same way a real criminal would, then show you exactly what we found and how to fix it.

In about two weeks, you’ll know what could happen to your network, with time to fix it before it does.

Why Test

Why You Want a Penetration Test

You Can’t Fix What You Can’t See

Most businesses that get breached had firewalls, antivirus, and backups in place. The problem wasn’t a lack of security spending. It was that nobody had ever tested whether those defenses actually worked together. A penetration test answers the question your IT tools can’t: if a real attacker targeted us today, how far would they get?

Prove Your Security Investment Is Working

You’ve spent real money on security. A penetration test is how you validate that spend. Either the test confirms your defenses hold, which is worth knowing, or it finds the gaps your tools missed, which is worth even more. Both outcomes make your next security dollar smarter.

Attackers Don’t Care How Big You Are

Small and mid-sized businesses are targeted precisely because criminals assume they’ve never been tested. Automated attacks scan everything connected to the internet, every day, looking for one weak point. It only takes one.

A Breach Costs More Than a Test. Every Time.

Downtime, ransom demands, legal exposure, notification costs, and lost customer trust add up fast. A penetration test costs a small fraction of a single incident and tells you where to focus before it matters.

The Process

How It Works

A Look, Not a Test

We Place the Device & Scope Your Environment

We place a small, secure device on your network and run a simple discovery scan. This is a look, not a test: no attack attempts, nothing touched. It just counts what’s connected, including the devices nobody remembers plugging in. You’ll see exactly what we found, so there are no surprises in the scope or the price. Decide to move forward, and testing can start right away on the same device.

The Test Runs

The assessment safely attempts the same techniques real attackers use: weak passwords, misconfigurations, moving between systems, reaching sensitive data. Everything is controlled and documented. Nothing is damaged, deleted, or held hostage, and your team works normally the entire time.

We Walk You Through the Results

We sit down with you and explain what happened in plain language: how far an attacker could get, what they could reach, and what to do about it. Together, we prioritize the issues we found and map out a practical path forward based on your business, risk level, and existing IT resources. You leave with clear next steps—not just a list of problems.

Timeline

From First Conversation to Full Picture in Two Weeks

Deliverables

What You Receive

The Executive Summary

A concise, plain-English overview written for owners and leadership. What was found, what it means for the business, and how urgent it is. Perfect for board meetings, insurance carriers, and client due diligence requests.

The Full Technical Report

The complete record of the assessment: what was compromised, how it was compromised, and the proof behind every finding. Your IT team or provider gets everything they need to understand exactly what happened.

The Fix Report

A detailed, prioritized remediation plan with step-by-step guidance for every finding. It’s written so your internal IT team or current provider can take it and run with it, no translation required. And if you’d rather not tackle it alone, we can handle the fixes for you or work alongside your team.

Pricing

Straightforward Pricing, No Surprises

Penetration testing is priced by the number of systems and devices on your network, which we call assets. Each computer, server, and connected device counts as one. Use the slider below for a ballpark estimate. During scoping, we run a simple discovery scan that counts your actual assets, nothing more, so your final quote reflects reality, not a guess.

50
Estimated Cost $5,000

Estimates are for budgeting purposes. Your exact price is confirmed after a free preliminary scan during scoping.

After the Test

A Test Tells You Where You Stand. We Help You Stay There.

A penetration test is a snapshot. Your network changes every week: new employees, new software, new devices, new threats. The businesses that stay secure treat testing as the starting point, not the finish line.

After your assessment, we can help you close the gaps we found, keep your systems patched and monitored, and retest on a schedule that fits your business. For teams that want proof their fixes worked, we also offer verification testing: we rerun the same attack paths from your report to confirm they’re truly closed, not just patched on paper.

Many of our clients start with a single penetration test and stay because having one team that finds problems, fixes them, and proves the fixes worked beats juggling vendors who only do one piece.

Questions

Frequently Asked Questions

What does the device do during scoping?

It performs a discovery scan only. Think of it as taking inventory: it identifies what’s connected to your network so we can give you an accurate price. It makes no attack attempts and doesn’t access your data. Nothing happens beyond counting until you give us the go-ahead.

Will the test break anything?

No. The assessment uses safe, controlled techniques designed to prove a weakness exists without causing harm. Nothing is deleted, encrypted, or taken offline. Your team can work normally through the entire engagement, and most never notice it’s happening.

Is my data safe during the test?

Yes. When the test reaches sensitive data, it documents that access as proof of the finding. It doesn’t ransom, alter, or expose your files. Results are handled through a secure, access-controlled platform, and findings are delivered to you and only you.

What if you find something really bad?

Then you found it before an attacker did, which is the entire point. Critical findings are prioritized at the top of your fix report, and we’ll walk you through the most urgent items first at your results meeting so the biggest risks get addressed fast.

How long does this all take?

Two weeks tops, from scoping to fix report. Scoping takes a day or two, the assessment itself runs for about a week to give your network a thorough look, and then we meet to walk you through the results and deliver your reports.

How often should we test?

Annual testing is the common baseline, and for some businesses that’s the right fit. But your network changes every time you hire someone, add software, or open a location, and each change can open a new door. That’s why many of our clients test quarterly or twice a year. Because your scoping is already done and the device process is already dialed in, recurring schedules cost noticeably less per test than standalone engagements. If staying continuously tested sounds better than an annual snapshot, bring it up on your scoping call and we’ll put together pricing that makes it easy.

Do I need to do anything to prepare?

Almost nothing. We need a network connection and power for the device, and a point of contact on your side. No software installs, no downtime, no disruption. One heads-up: if a security team or provider watches your network, let them know the test is happening so they observe rather than shut it down partway through, which would leave you with an incomplete picture. And if you’d rather not tell them, so you can see whether they catch it at all, we can plan for that during scoping.

The Scoping Call Costs Nothing.
Not Knowing Could Cost Everything.

Penetration Testing Form

One of our Technology Advisors will reach out to schedule your call.