Guide
Double blind penetration testing, and how it stays safe
Double blind penetration testing keeps both sides in the dark. The tester starts with little information, and your security team is not told when testing happens, so detection is tested too.
- Fixed fee before we start
- Named tester in writing
- Retest and attestation letter
How double blind penetration testing works
In a standard test, defenders know testing is underway. In contrast, a double blind test hides it from them. Therefore you learn whether monitoring and response actually work.
The tester also starts with minimal information. As a result, the exercise resembles a real outside attacker more closely.
Double blind penetration testing compared with other approaches
Each approach answers a different question. However, double blind is the most demanding to run.
| Approach | Tester knows | Defenders know |
|---|---|---|
| White box | Full details | Yes |
| Black box | Little | Yes |
| Double blind | Little | No |
Double blind penetration testing readiness check
Tick what is in place.
Your result appears here as you tick, so you can see what is still open.
Safety in double blind penetration testing
Someone must know. So a trusted contact, often a senior leader, holds the authorisation and can stop the test at any moment.
- Written authorisation held by the trusted contact
- Agreed limits on systems and times
- A way to confirm testing if defenders escalate
- A clear stop procedure
When it makes sense
Mature teams with monitoring in place gain the most. Because the goal is testing detection, a team without monitoring learns little beyond what a standard test shows. Also, regulators or boards sometimes ask for evidence of response capability.
In addition, debrief defenders afterwards. The method follows NIST SP 800-115.
Fees and timing
Double blind work is scoped individually, because coordination adds effort. Larger engagements start from $29,000 as a fixed fee, with two retests inside 60 days. Testing is delivered by vetted third-party practitioners under our project management.
Also agree what happens if a real incident occurs during the test. So defenders never ignore a genuine alert.
Double blind penetration testing questions
Is double blind penetration testing legal?
Yes, with written authorisation from the system owner, held by a trusted contact.
Who knows about double blind penetration testing?
Only the trusted contact and a small group with a need to know.
What if defenders call the police during double blind penetration testing?
The trusted contact confirms the test, so the escalation path must be agreed in advance.
Is a retest included?
Yes. Larger packages include two retests inside 60 days.
Related guides
Plan double blind penetration testing safely
Tell us about your monitoring and goals. We reply with a fixed fee, usually within four working hours, with no call needed.
Get my fixed-fee quote