QuietHours by securITDiscuss your scope

Packages and pricing

Clear starting prices. Scope before spend.

These are the floors for the work we do most often. What you actually pay depends on scope, and we agree that in writing — tester-days included — before anything starts. Prices exclude VAT.

NO-FINDINGS GUARANTEE

If we find nothing validated,
there is no assessment fee.

We would rather tell you the truth about a quiet estate than invoice you for a report full of filler. If we complete an agreed scope and report no validated security findings, the assessment fee is €0.

  • The agreed scope must be testable
  • Third-party costs are excluded
  • Terms are confirmed in the proposal

Threat hunting, training, and audits

Focused investigations, practical training, and evidence-led reviews. Threat hunting is quoted after we review the question you want answered and the data available to investigate it.

PriceServiceWhat it covers
Quoted to scopeThreat huntingA focused search for attacker activity in your existing security data, with evidence, visibility gaps, and detection recommendations.
€250Cyber hygiene lectureA single awareness session for a whole team.
€400Training materials and testsReusable material with knowledge checks.
€200–€300Phishing campaignA controlled simulation with reporting on behaviour, not just clicks.
€500IT process auditA review of how security decisions actually get made and recorded.
from €500Policy developmentWritten policy that matches how your organisation works.
€1,000–€2,500Infrastructure auditConfiguration and architecture review across your estate.

Prices exclude VAT. The final price depends on scope, complexity, access, and testing window.

What actually moves the price

Five things account for most of the difference between a €2,000 test and a €12,000 one. If a proposal you are comparing does not address them, it is not comparable.

  1. 01

    How much is genuinely in scope

    Counting applications is not the same as counting attack surface. One application with six user roles and a partner integration takes longer than three brochure sites.

  2. 02

    Whether we test authenticated

    Unauthenticated testing finds the perimeter. Most exploitable impact sits behind a login, which means credentials, roles, and a longer test.

  3. 03

    How complex the environment is

    Custom protocols, legacy systems, hardened cloud estates, and anything with a hardware component all add testing days.

  4. 04

    Access and timing

    Delayed credentials, restricted testing windows, and out-of-hours requirements all cost time, and time is what you are buying.

  5. 05

    What happens after the report

    A remediation workshop and a retest are part of the work, not an upsell. Where the scope includes them, the price reflects it.

Pricing questions

How is threat hunting different from SOC monitoring?

SOC monitoring investigates alerts as they arrive. Threat hunting starts with a question about possible attacker activity and searches the security data you already collect, including activity that has not triggered an alert. We agree the hunt question, available data sources, and investigation window before quoting.

How do we follow progress and access our results?

Phishing campaigns, security audits and penetration tests come with a private client workspace. Follow project progress, review prioritised findings and remediation status, see published phishing campaign results, and download confidential reports. Your project team publishes updates as the work progresses.

What does a penetration test cost in Europe?

Our penetration tests start at €2,000 for a single web application or API, and €4,100 for a complex application, cloud, or network scope. Red team exercises start at €8,750. Across the European market, day rates vary widely, so compare proposals on tester-days and scope rather than on headline price.

Why are these starting prices rather than fixed prices?

Because the honest answer depends on scope. We publish the floor so you can budget, then we agree the exact scope, the number of tester-days, and the final price in writing before any work begins. You will not receive an invoice for something you did not approve.

Do these prices include VAT?

No. All prices exclude VAT. Third-party costs, such as licences or infrastructure you ask us to procure, are also excluded and stated separately in the proposal.

Is retesting included?

One focused retest is included in Pentest Essential. Pentest Advanced includes a remediation workshop and a retest. A fix is not evidence until somebody checks it, so we treat the retest as part of the engagement rather than a separate purchase.

What is the no-findings guarantee?

If we complete an agreed, testable scope and report no validated security findings, there is no assessment fee. The scope must be testable, third-party costs are excluded, and the exact terms are confirmed in the proposal before work starts.

Can you deliver in French?

Yes. We deliver in English and French, including procurement material that states our qualifications and delivery model plainly.

Next step

What do you need to test or investigate?

A 30-minute scoping call, then a written scope and price. No work starts until you have approved both.

Discuss your scope