Skip to content
Thornbury Labs
Authorised testing only. We test with your written authorisation, so scope and rules are agreed before testing begins. Testing is delivered by vetted third-party practitioners, and we do not describe our work as certified.

Guide

Manual penetration testing, measured in hours you can see

Manual penetration testing means a named person spends real hours trying to break your system. So the number that matters in any quote is how many of those hours you are buying.

  • Fixed fee before we start
  • Named tester in writing
  • Retest and attestation letter
Manual penetration testing: count the hours, name the tester and read the proof

What manual penetration testing finds

Tools match known patterns. However, the serious findings in modern apps are usually logic flaws, so they need a person who understands what the app is meant to do.

  • One customer reading another customer's data
  • A user giving themselves admin rights
  • A payment or discount step that can be skipped
  • Several small issues chained into one serious one

Manual penetration testing hours by package

We put the hours in the contract, because that line explains most of the gap between two quotes.

PackageManual hoursFrom
Essential15 or more, so one asset is covered properly.$5,900.
Standard45 or more, across up to three assets.$14,500.
Advanced90 or more, because full scope needs depth.$29,000.

Is your quote really manual penetration testing?

Tick each item the proposal states clearly. Fewer ticks usually means more automation.

Your result appears here as you tick, so you can see what is still open.

How to check a quote for manual penetration testing

Ask how many hours are hands-on. Also ask who will test and what they hold. If a firm cannot answer both in one line, you are probably buying a scan at test prices. As a rough guide, a $6,000 test is about 15 hours, while a $20,000 one is about 60.

Where tools still help in manual penetration testing

Testers do use tools, because they speed up discovery. But the tool output is a starting point, not the finding. Each finding in our report is reproduced by hand, so false alarms are removed before you see them.

What the method looks like

Work follows the OWASP Web Security Testing Guide and NIST SP 800-115. So your auditor can see which areas were covered, and in what order.

Manual penetration testing questions

Is manual penetration testing slower than automated testing?

Yes, but that is the point. Hands-on work usually runs three to ten days, because a person checks what a tool cannot.

Do testers use any tools?

Yes, for discovery. However, every reported finding is confirmed by hand.

How many hours do we need?

It depends on scope. One asset usually needs at least 15, so three assets need more.

Can we see the hours in the contract?

Yes. Every package states the manual hours in writing.

Related guides

Get manual penetration testing with hours in writing

Send your scope and we reply with a fixed fee that states the manual hours, so you can compare quotes like for like.

Get my fixed-fee quote