Penetration testing company: how to hire and what to evaluate

O pentest market in Brazil has grown rapidly, and with it, the number of providers offering the service with very different proposals and prices.

Hiring a pentest company without clear criteria is just as risky as not hiring one: the test may be superficial, the report may not lead to any concrete action, and the company may remain exposed without realizing it.

This article is not a list of providers. It is a guide for anyone who needs to understand what to evaluate before signing any contract.

What Is a Pentest and What Is It Used For

Pentest, or penetration testing, is a controlled simulation of a cyberattack carried out with formal authorization from the contracting company. The goal is to identify technical vulnerabilities before malicious actors can exploit them.

A qualified pentest company does more than just find vulnerabilities. It documents them, classifies them by severity, and indicates the path to remediation. The value of the service lies less in the test itself and more in what the organization is able to do with what was found.

Pentest Is Not a Security Audit

This distinction is often overlooked and is worth making clear before any engagement. A pentest simulates the attacker: it attempts to compromise the environment through real attack paths to discover what can be exploited right now. A security audit evaluates the organization’s controls, processes, and compliance posture.

The two services complement each other, but they answer different questions. A pentest tells you what an attacker could do today. An audit tells you why the environment reached its current state.

Types of Pentests and When to Use Each

The choice of format depends on what the company wants to discover. The three main models differ according to the amount of information the tester receives before beginning.

  • Black Box: the tester receives no prior information about the environment, simulating an external attacker without privileged access. It indicates the actual exposure of the perimeter, but may leave internal vulnerabilities beyond reach
  • Gray Box: the tester receives partial information, such as credentials for a regular user. This is the format most commonly contracted by companies today because it combines an external and internal perspective in a single engagement
  • White Box: the tester has full access to the architecture and source code. It is the most comprehensive model, recommended by OWASP for identifying complex vulnerabilities that do not appear in external tests

In addition to the testing method, the scope defines the target: web applications, network infrastructure, APIs, cloud environments, mobile applications, or third-party vendor access.

What to Evaluate in a Pentest Company Before Hiring

This is the step most companies skip when they go straight to comparing prices. The points below make a difference in the quality of what will be delivered.

  • Certifications of the professionals who will perform the test, such as OSCP, CEH, GPEN, and GWAPT, which indicate verifiable technical training
  • The methodology used and whether it is aligned with industry-recognized frameworks, such as the OWASP Testing Guide, PTES, or NIST SP 800-115
  • Verifiable track record: experience in your industry, verifiable case studies, and available references
  • Whether the delivered report includes an executive version separate from the technical version
  • Whether a re-test is included to validate fixes within a contracted window, a practice that in 2026 is already considered standard in the market
  • Whether the company has an active CNPJ and issues invoices, a basic requirement for internal compliance
  • Whether the contract includes a formal NDA covering access to the environment and the vulnerabilities identified during the test

What the Contract Needs to Include

Before signing with any pentest company, the contract needs to precisely define the scope of the assets to be tested and the execution window with specific dates. Providers that resist formalizing these points deserve extra attention.

In addition, the document should cover the format and delivery deadline for the report, the re-test policy, and responsibilities in the event of an incident during the execution of the test. A poorly defined pentest can result in service interruptions or exposure of data that was not anticipated.

What the Report Needs to Contain

A quality report has two layers. The executive layer is aimed at leadership, with a risk overview in business language and clear prioritization of what needs to be addressed first. The technical layer details each vulnerability found, its severity classification, the evidence collected, and the remediation path.

A report that is not actionable is of no use. Companies that receive the document, file it away, and continue operating in the same way completely undermine the value of the investment. The pentest is the diagnosis. Remediation is the action taken, and it needs a deadline and an owner, like any other risk that needs an owner.

When and How Often to Hire

The market recommendation is to conduct a pentest at least once a year, or after significant changes to the infrastructure and the launch of new systems. Security incidents are also an obvious trigger, but ideally, you should not wait for them.

The LGPD does not explicitly require pentesting, but a recent test report documenting identified and remediated vulnerabilities can serve as evidence of due diligence before the ANPD in the event of an incident. Sectors with more specific regulations have concrete requirements: the Central Bank of Brazil, under BCB Resolution 538/2025 and CMN Resolution 5,274/2025, requires annual penetration testing by an independent professional for financial institutions. PCI DSS 4.0 requires external and internal testing for companies that process card data.

It is worth remembering that the scope of the test should include vendor access and third-party integrations, which are frequently overlooked vectors and represent a significant attack surface.

Who Should Lead This Engagement Within the Company

Hiring a pentest company requires the involvement of someone who understands the technical environment and can define the scope precisely. It also requires someone who has the authority to approve third-party access to the environment and someone who will turn the report into decisions with deadlines and assigned owners.

In companies without an internal CISO, this role is often filled by a CISO as a Service or a specialized consultancy. Delegating this engagement to the operational IT team without strategic support increases the risk of an incomplete scope and a report that goes without follow-up.

Is a Pentest Worth What It Costs?

The service is only as good as the company conducting it and the process the organization has in place to make use of what was discovered. Choosing a provider based on the lowest price without evaluating methodology, certifications, and report format is a way of investing in security without actually obtaining security.

The question worth asking before hiring is not how much the pentest costs. It is what risk the company is accepting by not knowing its own vulnerabilities.

How STWBrasil Can Help

STWBrasil conducts pentests with a certified team, a structured methodology, and a report in both executive and technical formats, with re-testing included.

If your company needs to assess its security posture or meet regulatory requirements, contact STWBrasil to understand the appropriate scope for your environment.

Leading company in information security. The digital protection of your company is our priority. We rely on state-of-the-art technology used by highly specialized professionals.

(11) 3939-0827
R. São Bento, 365 – 8o Andar – Centro Histórico de São Paulo, São Paulo – SP,
CNPJ: 05.089.825/0001-48.

Copyright ©️ 2023 – All rights reserved. Check out our  Privacy Policy.