EliteSec vs the Big Four
The Person Who Scopes Your Test Is the Person Who Runs It.
A Big Four firm has more people than I do. Everything else on this page follows from that, in both directions. Here is what each of us is good at, and the cases where I'd tell you to hire them instead.
Same Deliverable. Different Structure.
Both of us will hand you a penetration test report. The difference is who did the work, whether they are there next year, and what it costs to verify your fixes.
EliteSec
Founder‑Led, Independent
Who Runs Your Test
Me. I have led every engagement since 2019, more than a hundred of them. I scope it, I test it, I write the report.
Re-tests After You Fix Things
Five free re-tests in the 12 months after your test. You fix it, I check it, and the finding closes on evidence.
Next Year's Test
Same tester. I already know your architecture and last year's findings, so we start from what changed.
Scope
Scoped to your threat model and to what your auditors and customers are asking for. No checklist theatre.
The Report
Written by the person who found the issues. A plain-language summary for your board and your buyers' procurement teams, full detail for your engineers.
Accreditation
CREST-accredited for penetration testing. ISO 27001:2022 certified as a company. OSCP, OSWP, CISSP and CISM on the team.
Getting a Question Answered
Email me. Your engineer's question about a finding goes to the person who wrote it.
Who Owns the Firm
I do. Independent and headquartered in Canada.
The Big Four
Scale and Coverage
Who Runs Your Test
A partner scopes it. Delivery goes to whoever is available when your test starts, and that is often not the person you met.
Re-tests After You Fix Things
One re-test is the industry norm. After that, verification is a new statement of work.
Next Year's Test
Usually a new team. You walk them through the environment again, and last year's context is whatever made it into the report.
Scope
Scoped to the practice's standard offering. Efficient at volume, less sensitive to what is unusual about your system.
The Report
A house template, often assembled by a delivery team rather than the tester. Consistent, and sometimes a step removed from your stack.
Accreditation
Varies by office and practice. Sometimes the accreditation belongs to the parent company, not the team on your engagement. Ask.
Getting a Question Answered
Through your account manager. It gets answered, with a hop in between.
Who Owns the Firm
Practices get restructured and sold, and the wider market is consolidating: TELUS bought Vumetric in 2024, Kroll bought Security Compass Advisory in 2026. A change of owner can mean a change of team, tooling and price partway through a relationship.
The Other Side
When a Big Four Firm Is the Right Call
I would rather lose a deal on this page than win one I should not have. These are the cases where the Big Four firm is the better hire.
You need testing in several countries at once
Simultaneous work across regions, with local legal and language coverage, is a headcount problem. Hire the headcount.
You want a 24/7 SOC or managed detection
That is monitoring, not testing. I don't offer it. A Big Four firm with a managed services practice does.
Twenty applications, two weeks, hard deadline
Parallel testers are the only way to compress that. I will tell you so on the first call rather than take the work and thin it out.
Your vendor list is closed
Some enterprise procurement lists only admit named global vendors. If yours is one of them, it is better to know before either of us spends time on an RFP.
If none of those describe you, the trade is scale for continuity. I would take continuity, and I would say that. But the second engagement is where it shows: less setup, less re-explaining, more time spent testing.
Real Results
What Clients Say
Working with John at EliteSec was a great experience - we're a small software company, and John was able to work with our budget to provide us with penetration testing for our web application. John was professional and prompt and helped us set up for the test and then provided a detailed report complete with steps to remediate any issues that were found. Looking forward to working with John again in the future!
Charitycan
EliteSec Client
We've had great success with the team at EliteSec. Their thorough review of our products and infrastructure have identified key areas for continual improvement that had been missed by other consultants. This extra front-loaded effort ensures that the solutions they provide align with our needs, not with a cookie cutter.
Logisense
EliteSec Client
Having worked with multiple security firms for Penetration Tests in the past, I can unequivocally say that EliteSec has changed the game. Starting with a collaborative conversation with someone who actively works to understand the business, to a detailed findings report that goes against dated competitors, EliteSec has been an absolute pleasure to work with.
Gbl
EliteSec Client
Common Questions
Frequently Asked Questions
Isn't a one-person firm too small for an enterprise penetration test?
What happens if you are unavailable?
Will auditors and enterprise procurement accept a boutique's report?
Why do you make such a big deal of five re-tests?
How do I know you are the one doing the work?
When should I hire a Big Four firm instead?
Headquartered in Canada. Independent. Certified. Trusted.
CREST-accredited penetration testing, founder-led since 2019. Five free re-tests in 12 months where the norm is one. Ask for a sample report and judge the deliverable before you talk to me.
Request a Sample Report