Penetration testing services in Canada
A penetration test service is an authorised, simulated attack on your systems by a human tester, run to find the holes an attacker would find and to prove which ones actually lead somewhere. This page covers what a test includes, what it costs, how it differs from the vulnerability scan you may already be paying for, and what you get at the end. North Star scopes and runs tests for small and mid-sized businesses across BC, Alberta and Yukon, starting at $2,500 CAD.
What is penetration testing?
Penetration testing is a controlled attack carried out with your written permission. A tester works through the same phases a real attacker would, reconnaissance, finding a way in, escalating whatever access they get, and moving sideways through the network, then stops short of causing damage and writes down exactly how far they got and how. The output is not a list of theoretical weaknesses. It is a record of what was actually reachable, ranked by what it would cost you.
| Vulnerability scan | Penetration test | Red team exercise | |
|---|---|---|---|
| Who runs it | Automated tool | A person, using tools | A team, over weeks |
| What it answers | What is potentially vulnerable | What an attacker could actually reach | Whether you would notice and respond |
| False positives | Many, and you triage them | Few, because findings are proven | Not the point |
| Typical cost | Included in a managed plan | $2,500 to $5,000 for an SMB scope | Well into five figures |
| How often | Continuously | Annually, or after a major change | Once you have a security team to test |
| Right for you when | Always. It is hygiene. | You need proof, or a customer or insurer is asking | You already pass pen tests comfortably |
Most Canadian businesses under 200 staff that ask us for a red team need a penetration test, and a fair number that ask for a penetration test are being sold a vulnerability scan with a nicer cover page. The tell is whether a human tried to exploit anything. If the deliverable is a tool export with severity ratings and no narrative of how the tester actually got in, it was a scan.
How much does a penetration test cost in Canada?
North Star scopes SMB penetration tests from $2,500 to $5,000 CAD. The figure inside that range is driven by scope rather than by company size: how many public IP addresses and hostnames are in play, whether internal network testing is included, and whether you have a web application with authenticated users behind a login.
External only, small footprint.
A handful of public IPs, a marketing website, Microsoft 365, a firewall and a VPN. This is the common shape for a business of 10 to 40 staff, and it is the test most insurers and enterprise customers are actually asking for.
External plus internal.
Adds testing from inside the network, which answers the question that matters after a phishing email lands: once someone has one workstation, what can they reach? This is where most real findings come from.
Web application with authenticated roles.
A customer portal or line-of-business app with multiple permission levels needs each role tested against the others. Broken access control between roles is the most common serious finding in a custom application.
What the price does not depend on: how many staff you have, or how many devices are in the building. A 12-person engineering firm with a custom client portal is a harder test than a 90-person operation running nothing but Microsoft 365. Anyone quoting from headcount alone has not scoped the work.
Beware quotes materially below this range. A genuine test is several days of a qualified person's time, and at Canadian rates that has a floor. Sub-$1,000 "penetration tests" are almost always an automated scan, which is a useful thing to buy but not the thing you were told you were buying, and not the thing that satisfies a customer security questionnaire.
What gets tested, and how much the tester is told
Two decisions define the engagement. The first is which surfaces are in scope. The second is how much information the tester starts with, which changes what the test proves.
The tester starts with your name.
Closest to a real opportunistic attacker, and the most time spent on reconnaissance rather than on testing. Good for proving external exposure. Weaker value per dollar, because you pay for discovery you could have handed over.
The tester gets a target list and low-level credentials.
The default, and the best value for most SMBs. Skips the guessing and spends the budget on actual testing. It also mirrors the realistic threat: an attacker who already has one stolen password.
The tester gets documentation and source.
Deepest coverage per hour, used when you want assurance rather than a simulation, or when a specific application matters more than the perimeter around it.
Surfaces normally in scope for an SMB test: internet-facing services and firewall rules, VPN and remote access, Microsoft 365 and Entra ID configuration, the internal network from a standard workstation, wireless, and any public web application. Ask for the boundary in writing. A scope that says "your network" is not a scope.
How a test is actually run
Testing follows published methodology rather than a tester's preference, so the coverage is auditable and repeatable. For web applications that means the OWASP Top 10 and the wider OWASP Testing Guide; for infrastructure it means the phases described in PTES and the technical guidance in NIST SP 800-115. Ask any provider which they follow. A provider who cannot name one is improvising.
Rules of engagement, in writing.
Scope, testing window, escalation contact, and what is explicitly off limits. Includes written authorisation, which is what separates a penetration test from an offence under the Criminal Code.
Reconnaissance and mapping.
What is exposed, what version it is running, what is reachable from where. Most tests find something here that nobody knew was on the internet.
Exploitation, then escalation.
Prove the finding is real, then find out what it leads to. A low-severity issue that chains into domain admin is not a low-severity issue, and only a human notices the chain.
Report, debrief, retest.
Findings written for the person who has to fix them and for the person who has to fund the fix. A retest after remediation confirms the holes are actually closed, and gives you a clean letter to hand a customer.
Critical findings are reported the moment they are found, not held for the report. If a tester finds an exposed remote desktop with a weak password on day one, you get a phone call on day one.
What you actually receive
The report is the product. It should be readable by a business owner and actionable by whoever runs your IT, which usually means two audiences in one document.
An executive summary that names the business risk.
What an attacker could have done, in plain language, with the findings ranked by consequence rather than by tool severity score. Suitable to put in front of a board or an insurer.
Reproduction steps and a specific fix.
Each finding with the exact request or command used, evidence, and the change that closes it. Not "harden the server", but the setting, the version, or the rule.
A summary letter you can hand over.
Customers, insurers and auditors usually want confirmation a test happened and that findings were remediated, not the technical detail. A one-page attestation covers it without circulating your vulnerabilities.
See the format before you buy: North Star publishes a real sample deliverable rather than describing one. Sample security assessment report (PDF). It is the free assessment format rather than a full penetration test, but the reporting style, scoring and remediation detail are the same.
What is actually driving Canadian SMBs to test
Almost nobody buys a penetration test because they woke up curious. In our experience there are four triggers, and knowing which one you are answering changes what you should scope.
A customer security questionnaire.
You are bidding for an enterprise or public-sector contract and the vendor assessment asks whether you conduct annual penetration testing. An external test plus the attestation letter is usually what satisfies it.
Cyber insurance.
Renewal applications increasingly ask about testing alongside MFA and backups. Answering honestly is the point: a misrepresented control is a reason for a declined claim.
SOC 2 or a framework.
SOC 2 does not mandate a penetration test by name, but auditors routinely expect one as evidence for the change-management and monitoring criteria. See what SOC 2 readiness costs in Canada.
Something already happened.
After an incident, a test tells you whether the way in is closed and whether there is another one. Scope this differently: assume compromise and look for persistence, not just perimeter holes.
PIPEDA obliges Canadian organisations to protect personal information with safeguards appropriate to its sensitivity, and to report breaches posing a real risk of significant harm. It does not require a penetration test in so many words. A test is evidence that your safeguards were assessed rather than assumed, which is a materially better position after an incident than a good intention.
What a penetration test will not do for you
Worth knowing before you spend the money, because a test bought for the wrong reason disappoints.
It is a snapshot, not monitoring.
A test tells you about the day it ran. Next week's patch, next month's new SaaS tool and next quarter's firewall change are all outside it. Testing complements continuous monitoring; it does not replace it.
It does not fix anything.
The report tells you what to change. Someone still has to change it, and the commonest waste we see is a test paid for, filed, and never remediated. Budget the fix alongside the test.
It does not prove you are secure.
It proves a competent tester did not find a way through within an agreed scope and timeframe. That is genuinely valuable and it is not the same claim, and any provider promising the stronger one is overselling.
Find out what a test would cost you
Tell us what is in scope and we will come back with a fixed price and a testing window. If a scan is genuinely what you need, we will say so.
Start with the free assessment Back to CybersecurityFrequently asked questions
How much does a penetration test cost in Canada?
North Star scopes SMB penetration tests from $2,500 to $5,000 CAD. Where you land in that range depends on scope rather than headcount: how many public IP addresses and hostnames are in play, whether internal network testing is included, and whether there is a web application with authenticated user roles. External-only testing of a small footprint sits at the lower end; a customer portal with multiple permission levels sits at the upper end. Treat quotes far below this range with suspicion, because a real test is several days of a qualified person's time and that has a floor at Canadian rates.
What is the difference between a penetration test and a vulnerability scan?
A vulnerability scan is automated and tells you what is potentially vulnerable, producing a list you then have to triage for false positives. A penetration test is run by a person who attempts to exploit what they find, so the findings are proven rather than theoretical, and who then escalates to show what that access leads to. A low-severity issue that chains into domain administrator access is not low severity, and only a human notices the chain. If a deliverable is a tool export with severity ratings and no narrative of how the tester got in, it was a scan.
How long does a penetration test take?
For a typical SMB scope, testing runs a few days, with the report following about a week later. Scoping and the rules-of-engagement paperwork happen before that, and a retest after you have remediated is usually a shorter exercise. Critical findings are not held back for the report: if a tester finds an exposed remote desktop with a weak password on day one, you get a phone call on day one.
Will a penetration test disrupt our systems?
It is not supposed to, and the rules of engagement exist to keep it that way. Denial-of-service testing is excluded by default, the testing window is agreed in advance, an escalation contact is named, and anything fragile is explicitly listed as off limits. The residual risk is not zero, because probing a system can occasionally destabilise it, which is why the window and the contact matter and why testing production is a decision made deliberately rather than by default.
What methodology do you follow?
Published methodology rather than tester preference, so coverage is auditable. Web application testing follows the OWASP Top 10 and the wider OWASP Testing Guide. Infrastructure testing follows the phases described in PTES and the technical guidance in NIST SP 800-115. It is a fair question to ask any provider, and a provider who cannot name a methodology is improvising.
Do we need a penetration test every year?
Annually is the common answer, and it is what customer security questionnaires and insurance applications usually ask about. The better trigger is material change: a new public-facing application, a migration, a merger, or a significant network redesign all change your exposure more than twelve months of calendar time does. If nothing has changed, an annual test largely confirms the last one. If a lot has changed, waiting for the anniversary is the wrong call.
Does PIPEDA require a penetration test?
Not in those words. PIPEDA requires organisations to protect personal information with safeguards appropriate to its sensitivity, and to report breaches that pose a real risk of significant harm. It does not name penetration testing as a control. What a test gives you is evidence that your safeguards were assessed rather than assumed, which is a materially stronger position after an incident than a good intention. The same logic applies to SOC 2, which does not mandate a test by name but where auditors routinely expect one as evidence.
Is a retest included after we fix the findings?
A retest is offered and worth taking. It confirms the remediation actually closed the finding rather than moved it, and it produces a clean attestation letter you can hand to a customer or an insurer. The commonest waste we see in this area is a test paid for, filed, and never remediated, so budget the fix alongside the test rather than after it.
What does a penetration test not tell us?
Three things. It is a snapshot of the day it ran, so next week's patch and next quarter's firewall change are outside it, which is why testing complements continuous monitoring rather than replacing it. It does not fix anything; the report tells you what to change and someone still has to change it. And it does not prove you are secure. It proves a competent tester did not find a way through within an agreed scope and timeframe, which is genuinely valuable and is not the same claim.