Pentesting (or any security testing), On Your Terms.
The first-of-its-kind: Fractional Pentesting.
Fractional access to talent is everywhere...
But what about for pentesting?
What if you need rapid access to pentest talent and expertise, but don’t want or need a full penetration test?
Say, for instance, your organization just built a new feature, and you want to make sure it’s secure before it goes live. However, that one feature is the only thing that changed - you don’t have the resources available to test it internally, but also don’t need a full pentest. Sure, you could throw a scanner at it, but even with advances in AI and machine learning, there’s no replacement for human eyes and ingenuity when it comes to thorough and effective testing.
In today’s market, you’d largely be out of luck.
If you’re purchasing from a consultancy, there’s no easy way to quickly get just four hours of a tester’s time and attention. There are a few reasons for this:
- Consultancies operate with an internal bench of pentesters - where it’s imperative that every hour of every day for every tester on the bench be billable. Any time that’s not billable, is effectively a liability for the organization. Sure, they can allocate them to QA or other activities, but a pentester inside a consultancy is most valuable when they’re… making money.
- For this reason, the bench at a consultancy is going to be booked out weeks to months in advance, making it very hard to get rapid access to testers. And there’s no guarantee that the next available tester will be the best fit for your specific need.
- For this reason, the bench at a consultancy is going to be booked out weeks to months in advance, making it very hard to get rapid access to testers. And there’s no guarantee that the next available tester will be the best fit for your specific need.
- Additionally, it’s rare to be able to book just a part of a tester’s day or week. Booking only four hours of a tester’s day leaves a gap in the rest of their day that they’re unlikely to have filled up, resulting in more un-billable hours. The same goes for something that disrupts a full week of testing, etc.
- A full pentest.
- Multiple days of testing effort.
That said, even if you insist that you know that only this one thing needs to be tested, you’re still unlikely to get rapid, short-term access to a pentester.
Long story short: the current pentest provider market isn’t really set up to solve for more agile development and pentesting needs.
Enter fractional pentesting.
Fractional pentesting is where you can get exactly the pentesting talent you need, when you need it, to the degree you need it. At a price point that won’t blow your budget in the process.
No more waiting weeks-to-months to get a feature tested. You can get it tested rapidly, efficiently, and affordably.
How?
The process is remarkably simple:
- You define your requirements (need X to test Y for Z with ABC as an artifact) via the onboarding flow - without ever having to talk to a sales rep.
- You can either specify how much time you want to see the tester test for, or a recommendation can be made around how long it’d generally take to perform that testing.
- The job goes out to 3-5 qualified testers, who then place bids on the work, along with any useful / relevant information (availability, hourly price, background, etc).
- These testers are vetted members of the security testing community that commonly work pentest jobs as their 9-5, and then moonlight with fractional tests.
- The work takes place quickly, affordably, and efficiently. You can track the progress in the platform, and see results in real-time.
- The client (you) then chooses the bid you want to accept.
- Any relevant artifacts are delivered, and the job is done within a matter of days. All without having to talk to anyone along the way.
What used to be slow and cumbersome, is now quick and easy.
What used to cost a lot, now costs a whole lot less.
All of this also means that you’re able to more efficiently and quickly secure your organization.
Fractional testing puts you in control of what you need, when you need it, at a price that isn’t extortionate.
And that’s the whole goal and point of DarkHorse anyways - to provide accessible and affordable cybersecurity to organizations of all sizes, budgets, and needs.
So, the next time you need someone to test for anywhere from two hours to ten days, you now know that there’s a better option out there.
*As a quick note, it’s essential that we also call out that fractional pentest is not a replacement for pentesting as a whole. You do still need quarterly pentests and security assessments - but for features and small pushes in-between, fractional pentesting is an invaluable tool that can save you time, money, and frustration.
Frequently asked questions about fractional testing

Fractional testing (or pentesting) is a novel way to get access to penetration testing resources for as much or as little time as is needed - free from the typical constraints associated with a full or comprehensive penetration test.
Historically, if one wanted penetration testing, they had to buy a pentest. With the introduction of fractional pentesting, that now changes. With fractional pentesting you can quickly and effectively get access to top-tier penetration testers without needing to purchase a bulky, over-sized (and often over-priced) penetration testing contract. You can setup a fractional pentest engagement within minutes, and have bids from qualified testers ready to start testing within days.
True to DarkHorse's mission to democratize crowdsourced and offensive security, we're making this as affordable and as easy to use as possible. Despite being the first-to-market with this approach, we're still going to keep this as affordable and accessible as we can.
In the same way that a slice of cake is "cake", but not a full cake, the same is true for fractional pentesting.
Fractional pentesting is 100% pentesting, but it is not a full pentest.
Say you have a fairly clean house, but your kitchen needs a deep clean. Rather than having to pay a house cleaner to spend time cleaning the whole house, what if you could have them just clean your kitchen? You're not getting a fully cleaned house, but you are getting what you want, where you need it the most. This is what fractional pentesting enables... the ability for you to choose where and how you want testing to happen. If you want a full / deep clean, we can absolutely service that via our standard penetration testing services, but the key feature here is that it's 100% up to you!
That depends. Only you know what is needed - if your auditor requires a full penetration test, then you need a full penetration test, and not fractional pentesting. However, if your auditor just wants to see proof that a specific thing was tested for a certain amount of time, then it will likely pass - but again, we cannot make any guarantees in this respect. It is your responsibility to know what the auditor wants/needs, and then based on those wants/needs, we can recommend the right product fit for you.
We have a Loom above that goes through the whole process. However, we can cover it in text here as well:
- You setup a fractional pentest engagement in the platform in minutes. This includes collecting your scope, goals, artifact requirements, notes, amount of hours of effort you need, methodology, and any desired tester qualifications. NOTE: this can also be layered on top of an existing bug bounty or vulnerability disclosure program!
- After you complete the setup process, we immediately go out and select ~5 qualified testers, based on your qualification criteria. These testers have until your defined deadline to submit their bids (along with their justification around why they should be selected).
- After bids have been submitted, you review the bids, select the one you want, and then the tester performs the specified amount and scope of work within the testing window, and that's that! Depending on your artifact requirements, they'll also provide any necessary artifacts.
- No more steps. If it sounds simple, that's because it is. As it should be.
A lot less than a full pentest, and a lot-lot-lot less than getting a pentest from a consultancy or similar. The exact amounts are determined by the testers themselves, and the associated requirements (skills, target type, testing type, artifact output, etc). We try to provide a diverse range of options, so that you're able to choose from a wide range of skill levels and costs.