A penetration test in Switzerland costs between CHF 4,500 and CHF 150,000. What determines the price? What is included at each budget level? And when is the investment worthwhile?
You have received a quote for a penetration test. CHF 12,000 from provider A, CHF 45,000 from provider B. Both promise the same thing. How does this price difference come about? The short answer: scope, depth and methodology determine the price. The long answer follows here.
Price Ranges at a Glance
The typical price ranges in Switzerland look like this. A focused web application test (one application, OWASP Top 10, 3 to 5 days) runs from CHF 4,500 to CHF 15,000. An external infrastructure test (perimeter scan, IP ranges, exposed services) costs CHF 8,000 to CHF 25,000. A comprehensive internal test with Active Directory attack paths and lateral movement ranges from CHF 15,000 to CHF 50,000. Red team engagements with social engineering and physical access start at CHF 40,000 and go up to CHF 150,000.
Three Factors That Determine the Price
First, the size of the scope: number of IP addresses, applications, locations and user roles. Second, the testing depth: automated scans with manual verification only, or full manual exploitation. Third, report quality: a reproducible report with CVSS risk ratings and concrete remediation steps costs more than an auto-generated PDF from a scanner.
Return on Investment
The ROI is measurable. The global average cost of a data breach stands at USD 4.44 million according to the IBM Cost of a Data Breach Report 2025. Even for considerably smaller incidents, the costs (business interruption, forensics, reputational damage, reporting obligations) far exceed the investment in a pentest. Many cyber insurance policies also require an annual pentest as a contractual condition and offer premium discounts.
Getting Started with MilesGuard
At MilesGuard, every pentest begins with a free scoping call. Together we define the test scope, objectives and rules of engagement. You receive a transparent fixed-price quote with no hidden costs. After the test, we deliver a prioritised report with an action plan and discuss the findings in a personal debriefing.
Quellen
- [1] goSecurity.ch
- [2] DeepStrike (deepstrike.io)
- [3] cybersecurityswitzerland.ch

