Cybersecurity
Penetration testing in Australia: scope, cost and what to ask
Penetration testing quotes for the same organisation routinely differ by a factor of three, because they are quoting different work under the same word. This page covers what the different test types actually are, what drives the price, and how to compare quotes that look nothing alike.
What it is
Four things that decide what a penetration test costs
The word covers everything from an automated scan with a cover page to a fortnight of manual work by a specialist. Both get called a penetration test.
Fit
What you are actually being asked for
Penetration testing is bought for two quite different reasons, and they justify different engagements.
A compliance or contract requirement
A client, insurer, tender or framework requires an annual test. Here the deliverable is the report and its acceptability to whoever asked. Scope should match what they specified, and buying more than that is spend without commercial return.
The report is the deliverable
A genuine assurance question
You want to know whether somebody could get in. That justifies a wider scope, a grey or white box approach, internal network testing and a retest after remediation. It costs more and it answers a different question.
The finding is the deliverable
How we help
Getting comparable quotes
We are vendor funded, so the service costs your business nothing.
Write the scope once, for everybody
Addresses, applications, whether internal is included, the approach and whether retesting is required. Issued identically to each tester, which is the only way three quotes become comparable.
Match the test to the requirement
If a client asked for an annual external test, scope that. If the board wants assurance, scope wider. Confusing the two is how organisations overspend and still fail to satisfy the requester.
Check the individual testers
Certifications belong to individuals. Establish who is doing your test and what they hold, because the person assigned is what varies between a good engagement and a scan.
Plan the remediation before the report
Findings arrive with severity ratings and no owner. Agreeing in advance who fixes what, and the retest window, is the difference between a report and an improvement.
Negotiate the retest into the price
It is far cheaper as part of the original engagement than commissioned afterwards.
Due diligence
What to ask before commissioning a penetration test
These questions separate quotes that look similar and are not.
Is this a scan or a test
Ask how many hours of manual testing are included. An engagement that is mostly automated tooling is a vulnerability assessment, which is a legitimate product at a lower price.
Who is actually testing
Named individuals and their certifications, not the firm accreditation. Ask whether the person who scoped it is the person doing it.
Exactly what is in scope
Address ranges, applications, internal network, wireless, social engineering, cloud configuration. Anything unlisted is out, and that is where quotes diverge.
Is retesting included
And for how long after the report. This is the most common exclusion and the most valuable inclusion.
What the report contains
An executive summary the board can read, technical detail your team can act on, and evidence a client or auditor will accept. Ask for a redacted sample before committing.
Rules of engagement and insurance
Testing windows, escalation contacts, what happens if something breaks, and the tester professional indemnity cover. Agree it in writing before anybody starts.
Common questions
Questions about penetration testing
What Australian organisations ask us
How much does a penetration test cost in Australia?
It depends almost entirely on scope, and quotes for the same organisation commonly differ by a factor of three because they describe different work. The variables are the number of external addresses and applications, whether internal network testing is included, the approach taken, and whether a retest after remediation is in the price. A defined scope issued identically to each tester is the only way to get comparable numbers.
What is the difference between a penetration test and a vulnerability assessment?
A vulnerability assessment runs automated tooling and reports what it finds. A penetration test has a person attempting to chain findings into an actual compromise. Assessments are cheaper and worth running regularly. Tests answer whether somebody could genuinely get in. Quotes sometimes offer the first under the name of the second, so ask how many hours of manual testing are included.
How often should we do a penetration test?
Annually is the common contractual requirement, and after any significant change to what is exposed. If the driver is a client or insurer requirement, their wording sets the frequency. If the driver is genuine assurance, continuous vulnerability scanning between annual tests gives better coverage than one test alone.
Do we need black box or white box testing?
White or grey box usually finds more real issues per dollar, because the tester is not spending budget rediscovering information you could have handed over. Black box simulates an outsider with no knowledge, which is a valid scenario and a more expensive way to reach the same findings. Black box is often chosen because it sounds more rigorous rather than because it suits the question.
Will a penetration test satisfy our compliance requirement?
Only if it matches what was asked for. Some requirements specify scope, frequency, or that the tester be independent of whoever built the system. Read the wording before scoping, because a technically excellent test of the wrong scope will not satisfy the requester.
Can you arrange penetration testing?
Yes. We write the scope, issue it identically so the quotes are comparable, check who is actually doing the testing, and make sure retesting is in the price. We are vendor funded, so the service costs your business nothing.
We are vendor funded and completely free to your business. Always focused on the right outcome.
Get three quotes that are actually comparable.
Penetration testing quotes differ by a factor of three because they describe different work. Answer six questions about what you were asked for, and we will write one scope, issue it to each tester and read the results with you.
Book a Call
Independent guidance at no cost to your business.
Read further on this
The pages and articles that answer the next question a buyer usually asks.
- Our advice on cybersecurity advisory
- Check where you stand
- Cyber security services Brisbane
- Cyber security services Melbourne
- Cyber security services Sydney
- essential-eight
- iso-27001
- mdr
- security-services-explained
- security-standards-compared
- smb1001-certification
- virtual-ciso
- the incident response pack, free download
- the IT continuity pack, free download
- connectivity and SD-WAN
- advice for IT leaders
- advice for finance leaders
- ACMA’s 2026-27 priorities, and the SMS deadline

