Statement of Work
Penetration Testing
Prepared by Starks Enterprise — starksenterprise.com · Irving "Gene" Starks Jr. · [email protected] · (980) 355-9706
Purpose & Overview
Starks Enterprise will perform controlled, methodology-driven penetration testing against Client's in-scope assets to identify exploitable weaknesses before adversaries do, delivering a findings report that engineering can act on immediately.
Scope of Work
Pre-engagement scoping, rules of engagement, and authorization documentation
External and internal network penetration testing
Web application and API penetration testing (OWASP Top 10 + business-logic abuse)
Authentication, session-management, and access-control testing
Social-engineering simulation (phishing) — optional add-on
Retest of remediated findings after Client fixes (one retest cycle included)
Deliverables
Rules-of-engagement and authorization package
Penetration testing findings report (executive + technical sections)
Reproducible proof-of-concept evidence for each finding
Retest letter confirming remediation status
Timeline
| Phase | Activities | Duration |
|---|---|---|
| Phase 1 | Scoping & rules of engagement | 1 week |
| Phase 2 | Active testing | 1-2 weeks |
| Phase 3 | Reporting & debrief | 1 week |
| Phase 4 | Retest of remediations | Within 30 days of fixes |
Pricing & Payment Terms
| Item | Timing | Fee |
|---|---|---|
| External network + web application test (one-time) | Due at kickoff | $10,000 - $22,000 |
| API or additional application (each) | Added to engagement | $4,000 - $9,000 |
| Internal network test (on-site or VPN) | Added to engagement | $6,000 - $14,000 |
| Social-engineering simulation (per campaign) | Scheduled separately | $3,500 - $7,000 |
Invoices are due net 15. Retest cycle is included within 30 days of report delivery.
Client Responsibilities & Assumptions
Client will provide written authorization and emergency contacts before testing begins.
Client will ensure in-scope systems are stable and approved production targets.
Client will notify Starks Enterprise of change freezes, audits, or events that overlap the test window.
Out of Scope
Denial-of-service / load testing
Physical security assessment
Third-party vendor systems outside Client control
Acceptance Criteria
All in-scope assets tested per the rules of engagement
Findings report delivered with severity, evidence, and remediation guidance
Debrief completed with engineering and executive stakeholders
Term & Termination
This SOW is effective upon signature by both parties and remains in effect through delivery and acceptance of all deliverables, or until terminated by either party with 30 days' written notice. Fees for work performed and expenses incurred prior to termination are non-refundable. This SOW is governed by, and incorporated into, the Master Services Agreement between Starks Enterprise and Client.