Feb 16, 2015

How to conduct cost effective pen testing in a SMB?

I’m sure this isn’t an issue with companies that have dozens of IT staff, but how can a small business conduct penetration testing in a cost effective, meaningful way?
Pwn Plug is a tool you can use for network penetration testing. Ars did an article about it a couple of years ago. http://arstechnica.com/business/2012/03/the-pwn-plug-is-a-little-white-box-that-can-hack-your-network/

The cheapest Pwn Plug option is $295, so you have to weigh whether that is cost effective for your business. https://www.pwnieexpress.com/
This article may of use to you:

The Top 5 Free Penetration Testing Tools

"The Top Five

Metasploit - Metasploit is an open source platform for developing and testing exploits. It's available for both Unix and Windows systems. This is a far more advanced tool than the others on this list, and requires more programming knowlege to run and use.

Nessus -Tenable Network Security offers Nessus as a free scanner for non-commercial use, with a subscription license required for commercial organizations.

Nikto - Nikto is an Open Source web server security scanning tool. Currently at version 2.03, can scan for over 3500 potential vulnerabilities, with the option for custom scans by classes of vulnerability.

Nmap - Nmap is my Swiss Army Knife for network scanning, port mapping, and OS & application discovery.

Wireshark - Wireshark is my replacement for Ethereal when sniffing and capturing network traffic and examining protocols and sessions in depth."
