The basics
A penetration test (or pentest) is a controlled, simulated cyberattack carried out by security professionals. We attempt to break into your systems the same way a real attacker would, then hand you a detailed report of everything we found and exactly how to fix it.

Think of it as hiring someone to try to rob your house before a criminal does, so you can find out which windows don't lock before it matters.
A vulnerability scan is automated: software checks your systems against a database of known weaknesses and flags what it finds. It's fast and affordable, and a solid starting point.

A penetration test goes further. A human tester actively tries to exploit those weaknesses to see how far an attacker could actually get. Manual testing finds things automated tools miss: logic flaws, chained vulnerabilities, misconfigurations that only matter in combination.

Analogy: a scan checks if your doors are locked. A pentest tries to actually get in.
External penetration test: We attack your business from the outside, the same position a hacker on the internet would be in. This covers your public-facing systems: websites, login portals, email servers, firewall configurations, and any services exposed to the internet.

Internal penetration test: We simulate what happens if an attacker is already inside your network, whether through a breach, phishing, or a malicious insider. This tests how far an attacker could move once they're in and what they could access.

Most businesses benefit from both. Our Pentest Bundle covers external and internal at a discounted combined rate.
Yes. And more than you might think. Small businesses are targeted specifically because attackers assume their defenses are weaker, and often count on it. According to Verizon's Breach Impact Study, the median financial hit to a small or midsize business from a breach is around $38,000, with severe cases running well into six figures.

The vulnerabilities in your systems exist whether you know about them or not. The only question is whether you find them first, or someone else does.
Not being hacked yet isn't the same as being secure: it may just mean you haven't been targeted yet, or that an attacker is already in and hasn't made their move.

A penetration test gives you a real answer instead of an assumption. You'll know your actual exposure, not your best guess at it.
The process
Every engagement runs the same six steps: scoping call, reconnaissance, vulnerability identification, exploitation, reporting, and debrief. Nothing starts until you've reviewed and signed off on what systems we're testing and what the rules are. The whole process from kickoff to final report typically takes one to two weeks.

Your report has two parts: a plain-English executive summary for you, and technical findings for whoever handles your IT. After delivery, we schedule a debrief call to walk through everything.
No. Before testing starts, we agree in writing on what we test, how we test it, and when. That document governs everything. We work around your business hours and flag anything unexpected before we act on it.

If something comes up mid-engagement that could affect your operations, we stop and call you before continuing. You stay informed the whole time.
For most SMB engagements, active testing runs three to five business days. From kickoff to final report delivery, plan for one to two weeks depending on scope and your team's availability. A vulnerability scan turns around faster, typically within a few days.

Scheduling is flexible. We work around your operations rather than asking you to work around us.
Not much. You need to tell us what systems you want tested and give us a point of contact. For an internal test, we need network access, either on-site or through a VPN. We walk you through the specifics during the scoping call.

You don't need an IT background to get started. We've scoped engagements for business owners who run everything themselves and for companies with a full IT team.
Every report has two sections. The executive summary is written for you: plain English, no jargon, focused on what we found and what to fix first. The technical findings section is written for your IT team or managed service provider, with step-by-step remediation instructions for each issue.

We do a debrief call after delivery to walk through the findings together. If anything in the report is unclear, that's the time to ask.
No, and that's by design. Having the same team test your systems and then fix the problems is a conflict of interest. We find the issues and tell you exactly how to fix them. Your IT team or managed service provider handles the remediation.

If you don't have an IT team, we can point you toward options. We want the fixes to actually happen, not just sit in a report.
Pricing & scope
Pricing depends on what you want tested and how big your environment is. For most Texas SMBs, here's a starting range:

Vulnerability Scan: from $1,000
External Penetration Test: from $4,500
Internal Penetration Test: from $6,000
Pentest Bundle (External + Internal): from $8,500

Those are starting prices, not fixed quotes. Contact us for pricing specific to your environment and what you're trying to accomplish.
Yes. Our vulnerability scan is designed for this. It gives you a clear picture of your exposure at a fraction of the cost of a full pentest and is a solid first step if you've never had a security assessment. Starting at $1,000.

Most clients who start with a scan use the results to prioritize what to fix first, then move to a full pentest when they're ready. It's a reasonable way to build toward full coverage.
Firewalls and antivirus are passive. They catch known threats as they arrive. A penetration test is active: it finds out what gets through, what was misconfigured, and what an attacker could do if they bypassed your defenses entirely. The two work together, not instead of each other.

Most businesses that get breached had antivirus running. The tools were there. The gaps were somewhere the tools weren't looking.
Once a year at minimum. You should also get a new assessment any time you make a significant change to your environment: launching a new application, adding a location, moving to the cloud, or onboarding a major vendor. Your environment changes, and so does the threat landscape.

A test from two years ago shows a two-year-old picture of your exposure. A lot can change in that time.
Cybersecurity consulting costs in Texas vary widely by scope and service type. At Xero Trust Security, our fixed starting prices are:

Vulnerability Scan: from $1,000
External Penetration Test: from $4,500
Internal Penetration Test: from $6,000
Pentest Bundle (external and internal combined): from $8,500
Virtual CISO (vCISO): variable based on scope, project-based or ongoing

Final pricing depends on the number of assets, environment complexity, and compliance requirements. Every engagement is scoped individually. Request a quote or email us for pricing specific to your situation.
Working with us
Every engagement starts with a signed non-disclosure agreement and clearly defined rules of engagement. Any data we encounter during testing is handled with strict confidentiality. It is never shared with third parties and is not retained after the engagement closes. Your report belongs to you alone.

We take the trust that comes with this work seriously. You're giving us access to sensitive systems, and that access comes with an obligation to protect what we see.
All testing is authorized in writing before we touch anything. The rules of engagement document defines exactly what systems are in scope, what actions are permitted, and the timeline. That document creates a clear legal authorization for the engagement and protects both parties.

Nothing happens without your explicit written sign-off. If a system isn't in the signed scope document, we don't touch it.
We schedule a debrief call to walk through the findings together and answer any questions. After that, the next step is yours: implementing the remediation steps in the report. Your IT team or managed service provider handles the fixes.

If you want a follow-up assessment after remediation to confirm the fixes held, we can scope that as a separate engagement. Many clients find that useful before a compliance audit or renewal.
Compliance & requirements
It depends on your industry and what data you handle. If you process credit card payments, PCI DSS requires it. If you handle patient health information, HIPAA's Security Rule requires a risk analysis that typically includes penetration testing. SOC 2 auditors expect it. Government contractors may be required under CMMC.

Not sure what applies to your business? Email us and we can help you figure it out before you commit to anything.
Yes, if you accept credit cards. PCI DSS applies to any business that stores, processes, or transmits cardholder data, regardless of size. There is no small business exemption. The requirements scale based on your transaction volume, but the obligation exists either way.

Many small businesses assume their payment processor handles compliance for them. That's only partially true. You are still responsible for securing your own environment.
PCI DSS requires penetration testing at least once a year and after any significant change to your infrastructure or applications. The requirement applies to your cardholder data environment, not necessarily your entire network.

Annual testing is the floor, not the ceiling. If you make significant changes to your systems during the year, you need a new test regardless of when the last one was done.
HIPAA's Security Rule doesn't use the words "penetration test," but it requires covered entities to conduct a thorough risk analysis of their electronic protected health information. In practice, regulators and auditors expect penetration testing as part of that analysis. Most healthcare businesses need it.

We recommend confirming current requirements with your compliance advisor or attorney. HHS enforcement has increased in recent years, and the cost of a breach far exceeds the cost of an assessment.
HHS proposed updates to the HIPAA Security Rule in early 2025 that would, if finalized, require annual penetration testing and vulnerability scanning for covered entities and business associates. As of mid-2026, those rules have not been finalized. The existing Security Rule risk analysis requirement still applies.

Requirements in this area are moving. We recommend confirming current obligations with your compliance advisor or attorney before assuming the proposed rules apply to your situation.
It depends on your industry. PCI DSS explicitly requires it for businesses that process card payments. HIPAA's Security Rule expects it as part of a risk analysis for healthcare businesses. Several state laws and government contracting frameworks require it as well. There is no single federal law that applies to every business.

If you're unsure what applies to you, a conversation with a compliance advisor is worth the time. We can tell you what we typically see for businesses in your industry.
SOC 2 does not explicitly require a penetration test, but auditors consistently expect one. The Security trust services criteria requires you to demonstrate that you identify and address vulnerabilities. In practice, most SOC 2 audits include penetration testing as evidence of that process.

If you are pursuing SOC 2 Type II certification, your auditor will almost certainly ask about it. Starting before your audit window opens saves time and avoids last-minute scrambling.
SOC 2 is most common for SaaS companies, managed service providers, and any business that stores or processes customer data on behalf of other businesses. Enterprise clients often require a SOC 2 report before signing a contract. It is not legally mandated, but it has become a practical requirement in many B2B sales cycles.

If your customers are asking for it or your contracts require it, that's your signal. We work with businesses preparing for SOC 2 audits that need a penetration test as part of their evidence package.
Some of it, yes. PCI DSS allows smaller merchants to complete a Self-Assessment Questionnaire rather than a full audit. But self-attestation has limits: you still need to meet the technical requirements, including vulnerability scanning by an approved vendor and, in some cases, penetration testing. The questionnaire does not replace the underlying security work, and that work has a clock on it: organizations take a median of 43 days to fully patch a known exploited vulnerability, according to Verizon's 2026 Data Breach Investigations Report, while attackers increasingly move within hours.

Many small businesses complete the questionnaire and think they're done. What it tests is whether you answered the questions correctly, not whether your environment is actually secure.
CMMC stands for Cybersecurity Maturity Model Certification, a U.S. Department of Defense requirement for companies that handle Federal Contract Information (FCI), data the government generates or provides under a contract.

CMMC Level 1 is the entry-level tier. It requires 17 basic cybersecurity practices drawn from FAR 52.204-21, focused on protecting FCI. If your business holds any DoD contracts or works as a subcontractor on a supply chain that does, Level 1 likely applies to you. Level 1 self-attestation became required for many contractors starting in 2025.

If you have questions about whether CMMC applies to your contracts, email [email protected].

Update, July 2026: The Department of War suspended CMMC Phase II (the third-party assessment requirement for Level 2 and Level 3), which had been scheduled to take effect November 10, 2026. That decision came with a 60-day review of the program, so requirements may change further. Level 1's self-assessment requirement is unaffected and remains in force. This is a developing situation, so check the DoD's official CMMC guidance for the current status.
Cyber insurance & cost savings
It can. Many carriers view penetration testing as evidence of proactive risk management and factor it into how they underwrite your policy. Businesses that can show documented security assessments often receive better rates or avoid surcharges that less-documented businesses face at renewal.

The savings vary by carrier and policy. A single test won't automatically cut your premium in half, but documented security practices consistently put you in a better position at renewal than businesses with no assessment history.
Some do, and more are moving in that direction. Cyber insurance underwriting has tightened significantly in recent years. Carriers increasingly require documented security assessments before issuing or renewing policies. A penetration test is one of the stronger forms of evidence you can provide.

Discounts vary by carrier. Check with your broker about what your specific carrier expects. What we can tell you is that our clients are better positioned at renewal than they were before the assessment.
For most small businesses, yes. A policy covers costs that would otherwise come directly out of your pocket after a breach: breach notification, legal fees, regulatory fines, and business interruption. According to IBM's Cost of a Data Breach 2024 report, the average breach costs well into six figures even for smaller organizations.

Insurance is not a substitute for security. Carriers are getting stricter about what they cover and what they exclude. A business with documented security practices is more likely to get a policy, pay less for it, and have claims honored.
Premiums for small businesses typically range from a few hundred to several thousand dollars per year, depending on your industry, revenue, the type of data you handle, and your existing security controls. Businesses that can show documented security practices generally pay less.

Getting an accurate quote means talking to a broker who specializes in cyber coverage. We're not insurance brokers, but our clients who invest in security assessments tend to be in a better position when underwriters ask about their practices.
The immediate costs include breach notification, legal fees, regulatory fines, forensic investigation, and business interruption. According to IBM's Cost of a Data Breach 2024 report, the average breach goes undetected for 194 days. That's nearly six months of exposure before anyone knows it happened.

The longer-term damage is harder to quantify: lost customers, reputational harm, and higher insurance premiums at renewal. Attackers don't discriminate by company size, and smaller businesses often have less cushion to absorb any of it.
Ready to get started?

Still have questions? Just ask.

A 30-minute call costs nothing. We'll tell you what we'd recommend for your situation, and whether you need us at all.