How to Conduct Network Pen Testing

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton and Metro Vancouver.

What is network penetration testing?

According to NIST SP 800-115 (2008), a penetration test is security testing in which evaluators mimic real-world attacks to identify methods for circumventing the security features of an application, system or network. That guide is still the document Canadian auditors quote when they ask how a test was actually run, not merely that one happened.

Network penetration testing is an authorized, scoped simulation of a real cyberattack against an organization’s network infrastructure. A Canadian SMB typically scopes 1 external test per year. Testers use the same reconnaissance and privilege-escalation techniques as criminal actors, then document each successful path with proof, business impact and a prioritized fix list.

The output is not a CVE inventory. The output is evidence: screenshots of compromised systems, captured credentials and a written narrative your CFO, auditor and insurer can all read. Fusion Computing runs every network pen test into the same remediation queue as our managed cybersecurity services, so findings become tickets the week the report lands.

Pen testing vs vulnerability scanning: key differences

According to CIS Critical Security Control 18 in CIS Controls v8.1, organizations should test the effectiveness and resiliency of enterprise assets by identifying and exploiting weaknesses across people, process and technology. A signature match satisfies none of that. Exploitation is the word CIS chose, and it is what separates the two controls.

The two controls solve different problems. Automated discovery is signature-based, runs continuously and catches known CVEs across thousands of assets. A pen test is human judgment applied to a smaller surface, chaining 2 or 3 low-severity weaknesses into breach paths no signature can describe.

Treat one as breadth and the other as depth. Most GTA firms retain a penetration testing specialist for the test and a managed provider to remediate what it finds; our guide to the top cybersecurity MSPs in the GTA sets out which category handles which job.

Our security vulnerability assessment program feeds the pen-test scope. The test then answers the question automation cannot: does any of this actually get an attacker to your data? Across our 38 Canadian SMB pen-test engagements through Q1 2026, the top finding was usually already sitting in an untriaged vulnerability report.

Criterion Vulnerability Scan Penetration Test
Approach Automated and signature-based. Human-led exploit chains.
Cadence Weekly or continuous. Annual plus trigger events.
Output A list of known CVEs. Proof of exploit plus impact.
False positives Often high. Minimal. Every finding is verified.
Business context Limited. Mapped to crown-jewel assets.
Typical Canadian SMB cost CA$2,000 to CA$8,000 per year. CA$8,000 to CA$25,000 per engagement.

Not sure which control gap is hurting you most? Book a free scoping call and our CISSP-led team will map your current testing cadence against what a Canadian insurer or auditor will ask for in 2026.

The 4 phases of network pen testing

Every credible network pen test moves through four phases: reconnaissance, scanning, exploitation and reporting. The phases run in sequence, and findings in phase 3 routinely send a tester back to phase 1. A good engagement budgets time for that loop.

Phase 1 maps the external footprint: domains, subdomains, mail records, exposed services and leaked credentials. Phase 2 turns that map into a target list and fingerprints versions. Phase 3 attempts exploitation and lateral movement under tight rules of engagement. Phase 4 converts everything into reproducible steps with severity ratings and a remediation plan ranked by business risk.

Typical Canadian SMB network penetration test timeline, kickoff through retest Recon 1 to 2 days Scan 1 day Exploit 2 to 4 days Report 3 to 5 days Retest After fixes Network pen test timeline for a Canadian SMB Signed scope to executive readout: 2 to 3 weeks end to end.
Durations reflect Fusion Computing engagements scoped for 25 to 200 seat Canadian SMBs.
Phase What happens Typical duration (SMB)
1. Reconnaissance OSINT, footprinting, credential-leak review and employee enumeration. 1 to 2 days.
2. Scanning Service fingerprinting, configuration probing and vulnerability validation. 1 day.
3. Exploitation Active exploitation, privilege escalation and data-access proof. 2 to 4 days.
4. Reporting Findings narrative, risk scoring and an executive readout. 3 to 5 business days.

PTES + NIST SP 800-115 methodology framework

The Penetration Testing Execution Standard defines seven stages from pre-engagement through reporting, and MITRE ATT&CK supplies the technique taxonomy that turns findings into detection rules. ATT&CK now catalogues roughly 264 enterprise techniques across 15 tactics, which is why a report citing technique IDs is actionable and one without them is trivia.

Two frameworks anchor reputable pen testing in Canada. PTES is the operational stage model most proposals reference. The SP 800-115 guide is what a Canadian auditor reaches for when they want to know whether a test was conducted properly or simply invoiced.

Layer MITRE ATT&CK on top and the engagement gains shared vocabulary for tactics, techniques and procedures. When a finding cites T1110 credential brute-force or T1021 remote-service abuse, your detection team can match it straight to a rule in Microsoft Defender. Without that mapping, a finding is a paragraph nobody can operationalize.

Black box vs gray box vs white box: which type fits your situation?

According to the Canadian Centre for Cyber Security National Cyber Threat Assessment 2025-2026, attackers routinely exploit internet-facing edge devices such as routers, firewalls and virtual private network appliances. That is the exact surface an unauthenticated perimeter test hits first, which is why perimeter scope is rarely the line item a Canadian SMB should cut to save money.

Engagement type controls how much information the tester starts with, and that 1 decision moves both the price and what you learn. Black box mimics an unaffiliated external attacker. Gray box mimics a compromised employee or a stolen VPN credential. White box hands over diagrams and admin access for maximum hardening coverage.

Fusion Computing recommends gray box for a first engagement at most Canadian SMBs under 200 staff. It produces the most signal per dollar because it skips low-value reconnaissance and spends billable hours on chaining instead. Reserve black box for tests that must claim no inside help. Use white box when a regulated workload needs full assurance.

Type Tester knowledge Best for Relative cost
Black box None. External view only. External perimeter and real-attacker simulation. Highest. Recon eats the budget.
Gray box User-level credentials and partial diagrams. Compromised-insider scenarios. Best SMB return. Mid-range.
White box Full architecture and admin access. Regulated workloads and deep hardening review. Lowest per finding.

“The assessment found an admin account with domain-level rights that had been inactive for four years but was still open. One phishing email away from a full breach. We never would have caught that on our own.”

Mark S., CFO at a Canadian professional-services firm. Quote shared with permission.

How much does a network penetration test cost in Canada?

According to IBM and the Ponemon Institute (2026), the average Canadian data breach now costs CA$7.11 million, and organizations without AI-assisted detection needed 154 days to identify a breach and 71 more to contain it. Priced against that, a once-a-year test is a rounding error.

Most Canadian SMB engagements land between CA$8,000 and CA$25,000. The spread is not vendor greed. It tracks how many live IPs you expose, how many internal subnets exist and whether wireless or social engineering sits in the scope. A 30-seat Toronto firm with one office rarely reaches the top of that band.

Quotes under CA$5,000 deserve a hard question: what is being exploited, and by whom? At that price the deliverable is almost always an automated scan with a cover page. We tested that assumption directly by asking three sub-CA$5,000 vendors for a redacted sample report. None contained a single chained exploit path.

Scope element Effect on the quote Worth paying for?
External IP range Baseline driver. Scales with live hosts. Always. This is the attacked surface.
Internal subnets Each additional site adds tester days. Yes for multi-site firms.
Wireless SSIDs Adds roughly one on-site day. Yes where guest and corporate WiFi share hardware.
Social engineering Adds a phishing or vishing workstream. Only after MFA is fully deployed.
Retest of closed findings Often quoted separately. Non-negotiable. Insist it is bundled.
Executive readout Usually included. Confirm it. Yes. Boards fund what they hear explained.

Budget for what follows the report as well. Remediation is where the value lands, and ongoing managed cybersecurity for a Canadian SMB runs CA$130 to CA$180 per user per month. A test that produces 14 criticals and no owner is an invoice, not a control.

Want a scoped number instead of a range? Ask Mike Pearlstein for a fixed-fee quote and we will size the IP range and subnet count before quoting anything.

Pen test scoping checklist: what a provider needs before quoting

A provider who quotes without these six inputs is guessing, and a guess becomes a change order in week two. Fusion Computing sends the same scoping pack to every Canadian SMB before pricing an engagement.

  • Live external IP addresses, plus any hosting outside Canada.
  • Internal subnets, and how many physical sites carry them.
  • Wireless, VPN and Microsoft 365 identity: in scope or out?
  • Blackout windows and named escalation contacts for the test period.
  • The compliance driver: PCI-DSS, SOC 2, OSFI or an insurance renewal.
  • Retest of closed findings: bundled into the fee or billed separately?

Set the rules of engagement in writing before anyone touches a packet. The Canadian Centre for Cyber Security baseline controls assume MFA and patch discipline are already in place. Testing before those exist produces a punch list you could have written yourself.

How often should a Canadian SMB pen test?

OSFI Guideline E-21, effective August 22, 2024, requires federally regulated institutions to run regular scenario testing proportional to the criticality of each operation. Mid-market suppliers inherit that expectation through vendor risk reviews, which is how an annual cadence reaches a 60-person Ontario firm OSFI never regulates directly.

Annual is the floor. The triggers that demand an out-of-cycle test are the ones most teams miss: a firewall migration, an Active Directory consolidation, a merger or a customer questionnaire asking for a recent report. Treat any of those as a reason to call your tester within 30 days.

Across our 38 Canadian SMB pen-test engagements through Q1 2026, more than half were triggered by a cyber-insurance renewal rather than a calendar reminder. Our engineers found weak or reused administrative credentials in 78% of the environments we scoped. The fix costs almost nothing. The exposure is enormous.

What compliance standards require pen testing?

According to the PCI Security Standards Council, PCI DSS v4.0.1 is the current standard, and clause 11.4 requires internal and external penetration testing at least annually and after any significant infrastructure change. For a Canadian retailer or SaaS vendor touching card data, that clause turns testing into a contractual obligation.

Several Canadian-relevant frameworks either mandate penetration testing or treat it as the expected evidence of due diligence. PIPEDA stops short of naming pen testing. The Office of the Privacy Commissioner still reads Principle 4.7 to require safeguards that are demonstrably current, which is difficult to argue without test results.

Sector overlays add weight. SOC 2 auditors expect annual testing under CC4.1 monitoring activities. OSFI raises the bar again for federally regulated institutions through its Integrity and Security Guideline, effective January 31, 2024, and that bar reaches mid-market vendors through third-party risk reviews.

Framework Required cadence Why it matters
PCI DSS v4.0.1 Annual, plus after significant change. Card-data environments in retail and SaaS.
SOC 2 Type II Annual auditor expectation. B2B SaaS sales and vendor risk reviews.
OSFI Guideline E-21 Risk-based, typically annual. Regulated institutions and their suppliers.
PIPEDA safeguards Reasonable and demonstrable. Any organization holding Canadian personal data.
Cyber insurance renewal Annual at the CA$5 million revenue tier. Coverage retention and premium pricing.

Assembling a renewal package or answering a customer security questionnaire? Book a consultation with our CISSP-led team and we will map what you already hold against whichever framework is in front of you.

What should a quality pen test report include?

IBM’s 2026 Canadian breach analysis puts supply-chain compromise at CA$367,899 added to the average Canadian breach, the largest single cost amplifier measured. A report that ranks findings by business impact rather than raw CVSS is what lets a board fund the fix that removes that amplifier first.

A defensible report has 6 parts. An executive summary a non-technical director can absorb in 5 minutes. A risk-rated findings table. Reproducible technical steps. Business impact beyond raw CVSS. A remediation plan ordered by risk reduction per dollar. And a verification clause so remediated items are re-checked rather than assumed.

Reports that skip the business-impact column gather dust. Reports that include it become the agenda for the next quarterly steering committee. If a vendor will not write impact statements in plain English, change vendors. Our network security testing deliverables ship with a board-readable executive readout as standard.

How to choose a Canadian penetration testing provider

According to the Office of the Privacy Commissioner of Canada, PIPEDA safeguards must be kept current and followed consistently in practice, not merely documented. Test artifacts include captured credentials and screenshots of production systems, so where those artifacts live is a PIPEDA question before it is a procurement question.

Vet four things before signing. First, certifications: OSCP at minimum for the lead tester, with GPEN, GXPN or CRTO depending on scope. Second, methodology: the proposal should name PTES, NIST SP 800-115 and MITRE ATT&CK explicitly. Third, a redacted sample report you can hand to your own auditor without apologizing for it.

Fourth, data residency. Evidence collected during a test should stay on Canadian-controlled infrastructure or sit under contractual safeguards consistent with PIPEDA. A provider who cannot say where the artifacts live should not be the provider collecting them.

Book a Consultation

Free download

The Network Security Controls Checklist (2026)

Work through the controls a pen test will probe before you commission one. Perimeter, segmentation, identity, endpoint, backup and testing, each as a verifiable yes or no, mapped to the Canadian Centre for Cyber Security baseline.




No sales call required. Want the answers verified against your environment by a CISSP-led team? Book a consultation.

Scope a Penetration Test

Scoped and reviewed by Mike Pearlstein, CISSP, from our Toronto, Hamilton and Vancouver teams.

Frequently asked questions

How much does a network penetration test cost for a Canadian SMB?

Most Canadian SMB engagements price between CA$8,000 and CA$25,000 depending on IP-range size, internal subnet count and whether wireless or social engineering is in scope. Quotes under CA$5,000 typically signal automated scanning rebadged as pen testing.

What drives a pen test quote up or down the most?

Live external IP count and internal subnet count move the number most, followed by on-site wireless work. Adding a social-engineering workstream typically adds 1 to 2 tester days. Bundling the retest of closed findings is the single best value item to negotiate.

Is a retest included, or is it billed separately?

Treat it as non-negotiable. Roughly half the Canadian proposals we review price the retest separately, which means the CA$8,000 headline is really CA$10,000. Ask for closed-finding verification within 60 days of the original report, in the same contract.

How long does a network pen test take end to end?

Plan on 2 to 3 weeks. Active testing runs 4 to 6 business days, followed by 3 to 5 for reporting. Add a week for kickoff scoping and another to verify the fixes.

Will a pen test disrupt our network or business operations?

Properly scoped tests rarely cause outages. Your rules of engagement should specify blackout windows, denial-of-service exclusions and a real-time channel so any 1 anomaly is escalated in minutes rather than hours.

What is the difference between an external and internal pen test?

An external test attacks your public perimeter from the internet. An internal test simulates an attacker who has already landed inside, through phishing, a vendor laptop or wireless. Most Canadian SMBs need both, alternating yearly if the budget is constrained.

Do businesses under 25 employees actually need pen testing?

If you handle customer data, accept payment cards, sell to enterprise buyers or carry cyber insurance above CA$1 million, yes. Threat actors target Canadian SMBs precisely because they assume nobody is testing.

Is automated pen testing as good as a human-led engagement?

No. Automated platforms are useful between annual tests for continuous validation of known fixes, but they cannot chain 2 or 3 low-severity weaknesses into a realistic attack path the way a human tester can. Use them as supplements, never as replacements.

What certifications should our pen tester actually hold?

OSCP is the working standard for hands-on testers. A CISSP-led engagement manager can speak the language of governance and risk to your board. GPEN, GXPN, CRTO and CRTL signal advanced Red Team capability for environments above 200 seats.

How do pen test results affect cyber insurance renewal?

Underwriters now use recent results as direct inputs to premium pricing and coverage limits. A current report with closed criticals frequently lowers rates. A missing or stale report often triggers exclusions at the CA$5 million revenue tier.

What is the difference between Red Team and pen testing?

A pen test enumerates and proves exploitable weaknesses across a defined scope, usually inside 2 weeks. A Red Team engagement simulates a named adversary against your full detection-and-response capability, often over 6 to 8 weeks, aiming to reach an objective without being caught.

How quickly can Fusion Computing scope and start a pen test?

Scoping calls happen within 3 business days of inquiry, with rules of engagement signed inside a week. Active testing typically begins 2 to 3 weeks after signed scope, and our team books Toronto and Hamilton on-site days first.

Related resources

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Led by a CISSP-led team, Fusion supports organizations with 10 to 150 employees from Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611