If your business takes credit cards, prepares tax returns, holds patient records, or answers a cyber insurance questionnaire every year, you most likely need a penetration test. A pentest is an authorized, simulated attack on your network that shows what someone could really get into. PCI DSS and the FTC Safeguards Rule both call for one at least every 12 months for the businesses they cover. At safemode IT, pentest pricing is based on the number of IP addresses in scope. Internal and external IPs cost the same, and the re-test is included.
Start with a 10-minute discovery call: phone 512-761-7652 or book a time with Ron.
What is a penetration test, and how is it different from a vulnerability scan?
A vulnerability scan gives you a list of weaknesses a tool can see. A penetration test tries to use them, chaining several together the way a real attacker would. If a scan flags an old VPN portal, the pentest checks whether someone can get in through it and how far they'd get.
We test your network from both sides:
External testing goes after your internet-facing systems with no inside knowledge, looking for exposed services, weak or default logins, outdated edge devices and loose firewall rules.
Internal testing starts as if an attacker already has a foothold from a phishing email or a stolen laptop, then measures how far that goes through privilege escalation and lateral movement toward your servers and domain admin.
safemode IT runs every engagement on vPenTest from Vonahi Security, a CREST-accredited network penetration testing platform. It does more than scan. It runs relay attacks, cracks captured password hashes, escalates privileges and moves laterally, then documents each step. A security consultant reviews the findings before your report ships, and testing is non-destructive, so nothing on your network gets changed or deleted.
Why does a small business need a penetration test?
Software vulnerabilities are now the most common way attackers get in. Verizon's 2026 Data Breach Investigations Report found that 31% of breaches start with a software vulnerability, ahead of stolen passwords. Ransomware showed up in 48% of breaches.
U.S. breaches cost more than anywhere else IBM studied. IBM's Cost of a Data Breach Report 2026 puts the average U.S. breach at a record $11.5 million.
Your firewall and cybersecurity tools tell you about the attacks they stopped. A pentest shows you the openings they missed.
Which industries need penetration testing most?
These are the businesses most likely to have a regulator, card brand, auditor or customer ask for the report:
Healthcare practices holding patient records
Financial firms, including CPA and tax prep offices, mortgage brokers and wealth managers
Retailers, restaurants and service businesses that process card payments on their own systems
Texas state agencies and the vendors that support them
Appraisal districts and local government offices
Law firms and title companies with confidential client files
Businesses that keep getting security questionnaires from larger customers
What laws and standards require a penetration test?
PCI DSS
Under PCI DSS v4.0.1, the current version published by the PCI Security Standards Council, requirements 11.4.2 and 11.4.3 call for internal and external penetration testing at least once every 12 months, plus after any significant infrastructure or application change. If you use network segmentation to shrink your card environment, requirement 11.4.5 says you test that segmentation too.
FTC Safeguards Rule
Covered financial institutions need annual penetration testing and vulnerability assessments at least every six months, unless they run effective continuous monitoring (16 CFR 314.4(d)(2)). The rule counts tax preparers, mortgage brokers and real estate appraisers as financial institutions. Firms that hold information on fewer than 5,000 consumers are exempt from this testing requirement.
HIPAA
The current Security Rule never says "penetration test." It does require an accurate and thorough risk analysis plus periodic technical evaluations, and a pentest is one of the clearest ways to document both. HHS has proposed an update that would require penetration testing at least once every 12 months. Its most recent regulatory agenda lists July 2027 as the target for a final rule.
Texas state agencies
The DIR Security Control Standards Catalog tells agencies to run an external network penetration test at least every two years. Texas Government Code 2054.516 separately requires a pentest on agency websites and mobile apps that process sensitive personal information. Vendors should read our guide to TAC 202 compliance.
Not sure which of these applies to you? Book a 10-minute discovery call and we'll tell you straight, no pressure.
How much does a penetration test cost at safemode IT?
We price pentests like our flat-rate managed IT: you know the number before testing starts.
Pricing is based on the number of IP addresses in scope, so a small office pays for a small network. There's no hourly billing.
Internal and external IPs are the same price.
Every engagement includes a re-test. After your fixes are in, we run the test again to confirm the holes are closed, at no extra charge.
Scope, timing and any sensitive systems are agreed and signed off before anything is tested.
Results come back within about 48 hours of testing wrapping up, in three pieces: an executive summary for leadership, a technical report with CVSS-scored findings and remediation steps, and a sortable vulnerability spreadsheet. You decide who fixes what: your own IT team or us.
Call 512-761-7652 for a quote based on your IP count, or see our penetration testing services.
Will a penetration test lower my cyber insurance premium?
Maybe, but don't plan on a line-item discount. Underwriters price your policy on the security controls you report on your application, and a pentest is one input among many.
The bigger value is proof. With a recent pentest and verified fixes, your questionnaire answers have a report behind them. In 2022 Travelers went to federal court to void a manufacturer's cyber policy after a ransomware attack, arguing the company had claimed multi-factor authentication it didn't fully have. Both sides agreed to rescind the policy, and the court ordered it.
Heading into renewal? Ask your broker whether a current pentest report changes your premium or terms with that carrier, and don't check any box you can't prove. We fill out the insurance attestation with you and make sure the answers hold up.
Frequently asked questions
Is a vulnerability scan enough for compliance?
Usually not. PCI DSS and the FTC Safeguards Rule list vulnerability scanning and penetration testing as separate requirements. A scan finds possible weaknesses. A pentest shows which ones an attacker could use.
Does HIPAA require an annual penetration test?
Not by name today. The Security Rule requires a risk analysis and periodic technical evaluation, and a pentest is a strong way to document both. HHS's proposed update would require one at least every 12 months.
Do I need both an internal and an external penetration test?
PCI DSS requires both. For everyone else, external testing covers what a stranger on the internet can see, and internal testing shows how far an attacker could move after one bad phishing click. We charge the same per-IP rate for both.
Will a penetration test disrupt my network?
No. Testing is non-destructive, and scope, timing and any sensitive systems are signed off before it starts. The test proves what an attacker could do without changing, deleting or damaging your systems or data.
How often should a business get a penetration test?
Once a year is the common baseline. PCI DSS also calls for a new test after significant changes, like a new firewall, an office move or a new internet-facing application. Because vPenTest is built to run on demand, we can also test quarterly or monthly if you handle sensitive data or your network changes often.
Book a 10-Minute Discovery Call
safemode IT is based in Kyle and works with businesses in Kyle, Buda, San Marcos, Austin and Bastrop. Call 512-761-7652 or book a time with Ron. No pressure, no obligation.
Not sure your IT is as solid as it should be? Take 10 minutes and tell us about your setup. No pressure, no obligation.
Book a 10-Minute Discovery Call →Last updated: September 16, 2026


