Most penetration testing marketing is written for organisations with a security team, a compliance function and a budget line for this. If you are a twenty-person business where the person responsible for IT is also responsible for three other things, very little of it applies to you.
This is the version for that situation.
Worth answering honestly, because the answer is sometimes no.
You probably do if any of these apply:
You probably do not yet if all of these are true: you have no public-facing application of your own, everything you run is standard SaaS, nobody has asked, and you have not yet done the basics — multi-factor authentication everywhere, patching that actually happens, no unsupported operating systems, administrator accounts separated from everyday ones.
If that last group is you, spend the money on those basics first. A penetration test will simply produce a report telling you to do them, at considerably higher cost. Cyber Essentials is a more useful first purchase, and it is cheap.
Small organisations rarely need everything tested. They usually need the right one thing tested properly.
What someone on the internet can reach without any access. This is the baseline, it is the least expensive, and for most small businesses it is the right first purchase. It also routinely finds assets nobody remembered were exposed — an old staging site, a legacy portal, a service that should never have been public.
If you built software that customers log into, this matters more than your network. It is where your data lives, and it is the thing no generic control protects. If a customer questionnaire triggered this, it is usually the application they are asking about.
If your business runs on Microsoft 365 and a couple of SaaS tools rather than servers you own, this finds more than a network test will. Cloud environments fail through misconfiguration — over-permissive roles, gaps in conditional access, incomplete MFA, public storage — not through anything a perimeter scan sees.
What an attacker reaches after a successful phishing email. Valuable, and usually the richest source of findings, but the right second or third purchase rather than the first.
A full-scope engagement covering everything sounds thorough and is usually waste. Test what would hurt most. Add scope next year.
A test is a snapshot. Your environment changes, and new vulnerabilities are disclosed constantly. Annual testing with scanning in between is the realistic pattern for a small business — and scanning at £1,000 a year costs less than most single tests.
The test is the cheap part. Remediation is where the effort goes. If the entire budget goes on testing, you get a document instead of an improvement.
The customer or insurer who prompted this wants to see issues resolved, not identified. Confirm before you buy whether retesting is included — ours is.
CREST and CHECK matter enormously on government and large-enterprise tenders and not at all on most SME purchases. Check whether anyone has actually asked before paying for it.
A small UK business testing for the first time is typically looking at £500 to £2,000 depending on what is tested. That is our published range: £500 external infrastructure, £1,000 web application, £1,500 internal or cloud, £2,000 mobile application. Full detail is in our cost guide.
If quotes are coming in dramatically higher, the usual cause is scope built for a larger organisation. Go back and ask what would happen if you tested only the external perimeter, or only the one application that matters. The number usually changes considerably.
If quotes are coming in dramatically lower, read our piece on what cheap testing actually includes before signing.
You do not need internal expertise to buy this well. You need four answers:
If you cannot answer the first one, that is not a problem. Discovering it is part of an external test.
For a typical UK SME with no prior testing:
That is a realistic security programme for a small business, and it is achievable on a budget that does not require a board paper.
Describe your setup and we will tell you what we would test, in what order, and what it costs. If our honest answer is that you should spend the money elsewhere first, that is what you will get.