Cyber Security

How much does a penetration test cost in Australia?

BJ
Ben Jones
4 min read
The Australian market runs from under $10,000 to well past $60,000, and the cheap end is usually a scanner with a letterhead. What the ranges buy, and how to scope so the money produces findings.

Penetration testing quotes in Australia span a range wide enough to look arbitrary. It is not arbitrary. The spread reflects scope, depth and who is actually doing the work. Here is how the market prices, and how to make sure whatever you spend produces findings rather than paperwork.

The bands

Specialist penetration testers in the Australian market price their time in the order of $1,800 to $2,600 a day, and an engagement's cost is essentially days multiplied by that rate, plus reporting. In practice, a scoped external network test for a modest perimeter typically runs $8,000 to $18,000. A web application test runs $12,000 to $30,000 depending on the application's size, its authentication complexity and the depth of manual testing. An internal network and Active Directory assessment commonly lands between $15,000 and $35,000. Red team engagements are a different animal, objective-driven and measured in weeks, and they start around $60,000 and rise from there. Mobile applications, APIs and cloud configuration reviews each carry their own scoping but follow the same day-rate arithmetic.

What the cheap end actually is

Below these bands sits a product that looks like a penetration test on the invoice: a vulnerability scan, lightly triaged, wrapped in a template report. Scanners have their place, and we run them too, but a scan is not a test. The difference is a human attacker chaining findings. The low-severity information leak becomes credential access, which becomes lateral movement. That chain is what a real test buys, it is what an attacker will do to you, and no scanner reproduces it. If a quote seems impossibly good, ask how many manual testing days it contains. The answer is usually the explanation.

What moves the price

Scope dominates: the number of applications, hosts, roles and user journeys in play. Depth is next, and it is the difference between a time-boxed best effort and methodical coverage of an agreed attack surface. Tester credentials matter, because the skill floor in this industry varies enormously, which is what CREST, OSCP and their equivalents exist to signal. Reporting quality is a real cost component too. A report your engineers can act on, with reproduction steps and prioritised remediation, takes days to write well. Then there is retesting, meaning verification that your fixes actually closed the findings. It is either included, priced separately, or quietly absent. Ask which.

Spending the money well

The highest-return move costs nothing: scope the test around what you are actually defending, not what is cheapest to point a scanner at. We have written a full post on scoping a test attackers would respect. The short version is that a proper scoping conversation about your crown jewels, your likely adversaries and your last test's findings shapes an engagement worth its invoice. Annual testing plus retesting after major change is the standard cadence for most organisations, and insurers and enterprise customers increasingly expect evidence of both.

Our cyber security practice runs penetration testing, red team and retesting engagements under a CISO-led methodology, and scoping conversations are free. Tell us what you are protecting and we will tell you what testing it properly costs. Sometimes the right answer is a cheaper, narrower test, and we will say so.