GetPentest

How to get a penetration test funded

You are not trying to convince anyone that security matters. They already agree, in the abstract, and they still have not approved the money. The argument that works is not about risk, it is about the specific thing that is blocked until this happens.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Lead with the deal, the audit or the renewal that is waiting, not with the vulnerabilities you suspect. A budget holder approves a $20,000 CAD line to unblock a $400,000 CAD contract in about four minutes. The same person will defer a request framed as reducing risk indefinitely, because reducing risk has no date on it and their quarter does.

One page The memo that gets approved

The blocked thing What to lead with, not the risk

4 to 8 weeks Lead time, which is your deadline argument

Find the trigger, because there almost always is one

Before writing anything, work out which of these is true. Each produces a different memo and a different urgency.

Triggers, and the argument each one supports
TriggerThe sentence that funds itWho signs
An enterprise contract clause"This deal cannot close until we produce an annual independent test"Whoever owns the revenue number
A SOC 2 or ISO 27001 audit window"Our own policy commits us to annual testing and the auditor will test us against it"Finance, or whoever sponsored the audit
PCI DSS"Requirement 11.4 is not optional and our assessor will check it"Finance, usually without argument
Insurance application or renewal"The application asks and we have to answer honestly"Finance or the risk owner
A customer security questionnaire"Three prospects asked this quarter and we answered no each time"Sales leadership, who feel this immediately
A major architecture change"We rewrote authorisation and nobody outside the team has looked at it"Engineering leadership
An incident or near miss"We fixed the path we found. Nobody has checked for its neighbours"Anyone, briefly

The customer questionnaire row is the most under-used. If your sales team has answered "no" to a testing question on any recent security review, that is evidence a budget holder can act on. Ask sales for the examples and they will usually make the argument for you.

The one-page memo

  1. What is blocked. One sentence naming the deal, the audit, the renewal or the clause, with the date it bites.
  2. What we are buying. The surface, the number of tester days, and the deliverables: report, attestation letter, retest. Not a vendor name yet.
  3. What it costs. A CAD range from a real basis, with the arithmetic shown. Days times $1,500 to $2,800 CAD, per penetration testing cost in Canada.
  4. What happens if we do not. The specific consequence, not a generic breach scenario. The deal slips a quarter. The auditor issues an exception. The renewal is priced worse.
  5. Why now. Lead times are four to eight weeks and the compliance window needs 90 days of remediation room after the report.
  6. The recurring cost. Say it is annual. A budget holder who discovers that next year approves nothing twice.

One page. If it runs longer, the extra is background for an appendix nobody will read. Attach the scope document from the scoping questionnaire to show your working.

Do not lead with fear

Breach cost statistics are the weakest available argument and every executive has seen them. They describe other companies, they come from vendors selling something, and they invite the reasonable response that it has not happened to us. Win the argument on fear and you set up next year's request to fail, because nothing bad happened in the meantime. Win it on the blocked thing, which is checkable and recurs.

The objections you will get

What you will hear, and the answer
ObjectionAnswer
"We already run vulnerability scanning"Scanning finds known flaws in known software. It cannot find one customer reaching another customer's data, because it does not know whose data is whose. If the contract says penetration test, scanning does not satisfy it
"Our cloud provider handles security"They secure the platform. Your authorisation model, your roles and your tenancy are yours, and that is where the findings are
"Can we do it internally?"You can test internally and should. You cannot produce independent evidence about yourself, and independence is the word in the contract
"Can we get it cheaper?"Yes, by reducing scope honestly, not by discounting. A $4,000 CAD quote is about two tester days
"Can it wait until next quarter?"Only if the blocked thing can. Add four to eight weeks of lead time and 90 days of remediation room to whatever date you were given
"What if it finds something terrible?"Then we found it before a customer or an attacker did, which is the entire purchase. A report with findings and closed tickets is stronger evidence than a thin report
"We did one two years ago"It describes a system that no longer exists, and every contract and framework says annual

The last objection is the good one: what will we do with the findings. A budget holder who has paid for a report nobody acted on is right to ask. Commit to a ticket per finding within five working days and to using the included retest, and put the retest deadline in the memo. The retest planner produces the dates.

If nothing is blocked, say so

Sometimes there is no trigger: no contract clause, no audit, no questionnaire, no insurer, no architecture change. Then the recommendation is not a penetration test. It is continuous external scanning at $2,000 to $5,000 CAD a year, multi-factor authentication everywhere, and tested backups, which is where the money buys the most protection at that stage. Saying so builds the credibility you will spend next year when there is a trigger, and it beats asking for $25,000 CAD and being refused. The ordering argument is on cyber insurance and penetration testing.

After the yes

Approval decays, so move. Build the scope document first so every firm quotes the same thing, get three quotes, and ask each firm the same questions from questions to ask a penetration testing vendor. Then report back to whoever approved it, once, with what was found and what was closed. That five-minute follow-up makes next year's request routine instead of a negotiation.

Get a number you can put in the memo

Describe the scope and get a CAD range with the tester-day arithmetic shown.

Price a scope

Common questions

How do I convince my boss we need a penetration test?

Lead with the specific thing that is blocked: a contract clause, an audit window, an insurance renewal or a customer questionnaire you have been answering no to. Put it in a one-page memo with a CAD range showing tester days times a day rate, the date the requirement bites, and the four to eight week lead time. Do not lead with breach statistics.

What should the budget request actually say it costs?

A range with the arithmetic visible rather than a single number: the tester days for your surface multiplied by $1,500 to $2,800 CAD a day, plus reporting and the retest. A range you can defend survives scrutiny better than a precise figure you cannot explain, and it prevents the follow-up question that stalls the approval.

My boss says our vulnerability scanner is enough. Is it?

It depends entirely on what asked for the test. If a contract or an auditor said penetration test, scanning does not satisfy it and answering that it does is a representation you do not want to make. If nothing has asked and you have a small perimeter with a simple authorisation model, your boss may be right and the scan is the correct purchase.

How do I justify the recurring annual cost?

Say it is annual in the first request. Contracts and frameworks say annual, an expired test counts as no test in a renewal review, and a budget holder who learns about the recurrence a year later treats the whole line as untrustworthy. Framing it as an annual cost of selling to enterprise customers is both true and easier to approve than a surprise.

What if the test finds something serious?

That is the purchase working. A report with real findings and a ticket trail showing they were closed and independently verified is stronger evidence for an auditor or a customer than a thin report with nothing in it. The failure mode is not finding problems, it is finding them and leaving them open past the retest window.