EliteSec vs the Big Four

The Person Who Scopes Your Test Is the Person Who Runs It.

A Big Four firm has more people than I do. Everything else on this page follows from that, in both directions. Here is what each of us is good at, and the cases where I'd tell you to hire them instead.

Same Deliverable. Different Structure.

Both of us will hand you a penetration test report. The difference is who did the work, whether they are there next year, and what it costs to verify your fixes.

Recommended

EliteSec

Founder‑Led, Independent

Who Runs Your Test

Me. I have led every engagement since 2019, more than a hundred of them. I scope it, I test it, I write the report.

Re-tests After You Fix Things

Five free re-tests in the 12 months after your test. You fix it, I check it, and the finding closes on evidence.

Next Year's Test

Same tester. I already know your architecture and last year's findings, so we start from what changed.

Scope

Scoped to your threat model and to what your auditors and customers are asking for. No checklist theatre.

The Report

Written by the person who found the issues. A plain-language summary for your board and your buyers' procurement teams, full detail for your engineers.

Accreditation

CREST-accredited for penetration testing. ISO 27001:2022 certified as a company. OSCP, OSWP, CISSP and CISM on the team.

Getting a Question Answered

Email me. Your engineer's question about a finding goes to the person who wrote it.

Who Owns the Firm

I do. Independent and headquartered in Canada.

The Big Four

Scale and Coverage

Who Runs Your Test

A partner scopes it. Delivery goes to whoever is available when your test starts, and that is often not the person you met.

Re-tests After You Fix Things

One re-test is the industry norm. After that, verification is a new statement of work.

Next Year's Test

Usually a new team. You walk them through the environment again, and last year's context is whatever made it into the report.

Scope

Scoped to the practice's standard offering. Efficient at volume, less sensitive to what is unusual about your system.

The Report

A house template, often assembled by a delivery team rather than the tester. Consistent, and sometimes a step removed from your stack.

Accreditation

Varies by office and practice. Sometimes the accreditation belongs to the parent company, not the team on your engagement. Ask.

Getting a Question Answered

Through your account manager. It gets answered, with a hop in between.

Who Owns the Firm

Practices get restructured and sold, and the wider market is consolidating: TELUS bought Vumetric in 2024, Kroll bought Security Compass Advisory in 2026. A change of owner can mean a change of team, tooling and price partway through a relationship.

The Other Side

When a Big Four Firm Is the Right Call

I would rather lose a deal on this page than win one I should not have. These are the cases where the Big Four firm is the better hire.

You need testing in several countries at once

Simultaneous work across regions, with local legal and language coverage, is a headcount problem. Hire the headcount.

You want a 24/7 SOC or managed detection

That is monitoring, not testing. I don't offer it. A Big Four firm with a managed services practice does.

Twenty applications, two weeks, hard deadline

Parallel testers are the only way to compress that. I will tell you so on the first call rather than take the work and thin it out.

Your vendor list is closed

Some enterprise procurement lists only admit named global vendors. If yours is one of them, it is better to know before either of us spends time on an RFP.

If none of those describe you, the trade is scale for continuity. I would take continuity, and I would say that. But the second engagement is where it shows: less setup, less re-explaining, more time spent testing.

Real Results

What Clients Say

"

Working with John at EliteSec was a great experience - we're a small software company, and John was able to work with our budget to provide us with penetration testing for our web application. John was professional and prompt and helped us set up for the test and then provided a detailed report complete with steps to remediate any issues that were found. Looking forward to working with John again in the future!

charitycan

Charitycan

EliteSec Client

"

We've had great success with the team at EliteSec. Their thorough review of our products and infrastructure have identified key areas for continual improvement that had been missed by other consultants. This extra front-loaded effort ensures that the solutions they provide align with our needs, not with a cookie cutter.

logisense

Logisense

EliteSec Client

"

Having worked with multiple security firms for Penetration Tests in the past, I can unequivocally say that EliteSec has changed the game. Starting with a collaborative conversation with someone who actively works to understand the business, to a detailed findings report that goes against dated competitors, EliteSec has been an absolute pleasure to work with.

gbl

Gbl

EliteSec Client

Common Questions

Frequently Asked Questions

Isn't a one-person firm too small for an enterprise penetration test?
Your buyer's security team checks two things: who accredited the tester, and whether the report holds up. CREST accreditation and ISO 27001:2022 answer the first. A sample report answers the second, and I will send you one within a business hour. Where size does matter is parallel capacity, which is covered above.
What happens if you are unavailable?
Ask any boutique this. My answer: I schedule engagements instead of overbooking them, so the dates I quote are dates I can hold. When a job needs specialist depth, I bring in people I trust and stay accountable for the result. What does not happen is your engagement quietly moving to someone you have never met.
Will auditors and enterprise procurement accept a boutique's report?
Yes. A CREST-accredited report from a small firm is a CREST-accredited report. What reviewers look for is scope, methodology, findings, severity and remediation status, in a form they recognize. My testing follows PTES and, for web and SaaS work, the OWASP Testing Guide, and I write the summary for the non-technical reader who usually screens it first.
Why do you make such a big deal of five re-tests?
Because one re-test rarely covers a real remediation cycle. Teams fix the criticals, use their single re-test, then ship three more changes before the next annual engagement. Five in twelve months means fixes get verified as they land, which is what your auditor wants to see and what closes a finding on evidence instead of a promise.
How do I know you are the one doing the work?
You will be on calls with me from the first 30 minutes. I scope it, I test it, and my name is on the report.
When should I hire a Big Four firm instead?
Multi-region testing, 24/7 monitoring, or twenty targets on one deadline. If what you need is a single well-scoped test with a report that clears procurement and a tester who remembers your system next year, that is me.

Headquartered in Canada. Independent. Certified. Trusted.

CREST-accredited penetration testing, founder-led since 2019. Five free re-tests in 12 months where the norm is one. Ask for a sample report and judge the deliverable before you talk to me.

Request a Sample Report