Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security FullDisclosure
[Top] [All Lists]

RE: [Full-disclosure] Vulnerability/Penetration Testing Tools

Subject: RE: [Full-disclosure] Vulnerability/Penetration Testing Tools
Date: Wed, 18 Jan 2006 11:36:04 -0600
 
Valdis Kletnieks wrote:

Something to keep in mind however - many people make that comparison,
and don't calculate the *TOTAL* cost.

If your developer is getting paid $60K/year, the *encumbered* cost
(benefits, office, etc) is close to twice
that.  And if he's writing an in-house BidiBLAh, that's time he's *not*
writing stuff you *can't* buy 
off-the-shelf.
As a result, it breaks out as:

BidiBLAH:         $10,000

scripting clss:             $350
6 man-weeks time: $15,000

OK? Got that?  Suddenly doesn't look like such a good deal, does it?
Maybe you *should* just buy 
BidiBLAH, and have that guy coding that custom interface between two
in-house systems instead....

(And don't say "I only pay my developer $30K, so he can take 2
man-months to do it" - the kind of 
developer you can >keep for $30K is probably going to take a lot more
than twice as long as the $60K
developer.....)


I understand your point about TCO, even though you don't make a very
good case for it.  As for BidiBLAH, maybe you should look at the product
before speaking about it!  If you have used this product then please
give me your insight as to what you think and why.  Really if your
currently using this product I want to know what you think!

Now for the Math, and why your TCO argument wasn't so good,

Developer $60K/year divided by the adopted 2080 man hours year (this is
the average hours work, 40 hour week, 5 days, etc...) = $28.85/hourly,
so.....


BidiBLAH:                       $10,000
Scripting class:                $350

6 man-weeks time:               $6924.00


Like you said, "many people make that comparison, and don't calculate
the *TOTAL* cost".

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

<Prev in Thread] Current Thread [Next in Thread>