Cybersecurity

Penetration testing in Australia: scope, cost and what to ask

Penetration testing quotes for the same organisation routinely differ by a factor of three, because they are quoting different work under the same word. This page covers what the different test types actually are, what drives the price, and how to compare quotes that look nothing alike.

What it is

Four things that decide what a penetration test costs

The word covers everything from an automated scan with a cover page to a fortnight of manual work by a specialist. Both get called a penetration test.

01

Scanning and testing are different products

A vulnerability assessment runs automated tooling against your systems and reports what it finds. A penetration test has a human attempting to chain those findings into an actual compromise. The first is cheap and worth doing regularly. The second is what a serious requirement means, and quotes frequently offer the first under the name of the second.

02

Scope drives the price more than anything

Number of external addresses, applications, whether internal network testing is included, whether the tester starts with credentials, and whether social engineering is in play. A quote without a defined scope is not comparable to anything.

03

Black, grey and white box are different engagements

Black box means no prior knowledge, which spends budget on reconnaissance. White box gives the tester documentation and credentials, which finds more real issues per dollar. Grey box sits between. For most organisations grey or white box returns more value, and black box is chosen because it sounds more rigorous.

04

The retest is the part that matters

A report full of findings you have not fixed is not an improved security position. Establish whether retesting after remediation is included, and within what window, because it is a common exclusion and the fix is where the value is.

Fit

What you are actually being asked for

Penetration testing is bought for two quite different reasons, and they justify different engagements.

A compliance or contract requirement

A client, insurer, tender or framework requires an annual test. Here the deliverable is the report and its acceptability to whoever asked. Scope should match what they specified, and buying more than that is spend without commercial return.

The report is the deliverable

A genuine assurance question

You want to know whether somebody could get in. That justifies a wider scope, a grey or white box approach, internal network testing and a retest after remediation. It costs more and it answers a different question.

The finding is the deliverable

How we help

Getting comparable quotes

We are vendor funded, so the service costs your business nothing.

01

Write the scope once, for everybody

Addresses, applications, whether internal is included, the approach and whether retesting is required. Issued identically to each tester, which is the only way three quotes become comparable.

02

Match the test to the requirement

If a client asked for an annual external test, scope that. If the board wants assurance, scope wider. Confusing the two is how organisations overspend and still fail to satisfy the requester.

03

Check the individual testers

Certifications belong to individuals. Establish who is doing your test and what they hold, because the person assigned is what varies between a good engagement and a scan.

04

Plan the remediation before the report

Findings arrive with severity ratings and no owner. Agreeing in advance who fixes what, and the retest window, is the difference between a report and an improvement.

05

Negotiate the retest into the price

It is far cheaper as part of the original engagement than commissioned afterwards.

Due diligence

What to ask before commissioning a penetration test

These questions separate quotes that look similar and are not.

Is this a scan or a test

Ask how many hours of manual testing are included. An engagement that is mostly automated tooling is a vulnerability assessment, which is a legitimate product at a lower price.

Who is actually testing

Named individuals and their certifications, not the firm accreditation. Ask whether the person who scoped it is the person doing it.

Exactly what is in scope

Address ranges, applications, internal network, wireless, social engineering, cloud configuration. Anything unlisted is out, and that is where quotes diverge.

Is retesting included

And for how long after the report. This is the most common exclusion and the most valuable inclusion.

What the report contains

An executive summary the board can read, technical detail your team can act on, and evidence a client or auditor will accept. Ask for a redacted sample before committing.

Rules of engagement and insurance

Testing windows, escalation contacts, what happens if something breaks, and the tester professional indemnity cover. Agree it in writing before anybody starts.

Common questions

Questions about penetration testing

What Australian organisations ask us

How much does a penetration test cost in Australia?

It depends almost entirely on scope, and quotes for the same organisation commonly differ by a factor of three because they describe different work. The variables are the number of external addresses and applications, whether internal network testing is included, the approach taken, and whether a retest after remediation is in the price. A defined scope issued identically to each tester is the only way to get comparable numbers.

What is the difference between a penetration test and a vulnerability assessment?

A vulnerability assessment runs automated tooling and reports what it finds. A penetration test has a person attempting to chain findings into an actual compromise. Assessments are cheaper and worth running regularly. Tests answer whether somebody could genuinely get in. Quotes sometimes offer the first under the name of the second, so ask how many hours of manual testing are included.

How often should we do a penetration test?

Annually is the common contractual requirement, and after any significant change to what is exposed. If the driver is a client or insurer requirement, their wording sets the frequency. If the driver is genuine assurance, continuous vulnerability scanning between annual tests gives better coverage than one test alone.

Do we need black box or white box testing?

White or grey box usually finds more real issues per dollar, because the tester is not spending budget rediscovering information you could have handed over. Black box simulates an outsider with no knowledge, which is a valid scenario and a more expensive way to reach the same findings. Black box is often chosen because it sounds more rigorous rather than because it suits the question.

Will a penetration test satisfy our compliance requirement?

Only if it matches what was asked for. Some requirements specify scope, frequency, or that the tester be independent of whoever built the system. Read the wording before scoping, because a technically excellent test of the wrong scope will not satisfy the requester.

Can you arrange penetration testing?

Yes. We write the scope, issue it identically so the quotes are comparable, check who is actually doing the testing, and make sure retesting is in the price. We are vendor funded, so the service costs your business nothing.

We are vendor funded and completely free to your business. Always focused on the right outcome.

Get three quotes that are actually comparable.

Penetration testing quotes differ by a factor of three because they describe different work. Answer six questions about what you were asked for, and we will write one scope, issue it to each tester and read the results with you.

Book a Call

Independent guidance at no cost to your business.

Read further on this

The pages and articles that answer the next question a buyer usually asks.