Cyber security · Penetration testing
Penetration testing for Australian organisations, scoped in one call
Certified testers follow a methodology set by our CISO. You get findings your engineers can act on, we retest the fixes at no extra cost, and the price is fixed before testing starts.
What you receive
- Executive summaryWritten for the board, your customer or your insurer
- Technical findings reportSeverity, evidence, reproduction steps and remediation priority for each finding
- Findings walkthroughA call with the tester so your engineers can ask questions and plan the fixes
- Retest and updated reportFixed findings re-tested and confirmed closed, included in the price
- Manual testing by a personScanners find the obvious weaknesses. A tester works out what they lead to
- Certified testersEvery engagement is run under a CISO-led methodology
- Retesting includedFixes are verified and the report updated at no extra cost
- Fixed scope, fixed priceAgreed in writing before testing starts
What we test
Penetration testing services and what they cost
| Test | What it covers | Typical cost (ex GST) |
|---|---|---|
| External network | Everything of yours that faces the internet: perimeter, exposed services, remote access, email security | A$8,000 to A$18,000 |
| Web application and API | Authentication, authorisation between roles, input handling, business logic, the APIs behind the app | A$12,000 to A$30,000 |
| Internal network and Active Directory | What an attacker or a compromised laptop can reach once inside: privilege escalation, lateral movement, domain compromise | A$15,000 to A$35,000 |
| Cloud configuration, mobile, social engineering | Microsoft 365, Azure and AWS configuration reviews, mobile applications, phishing simulations | Scoped individually |
The price is days of a tester's time plus reporting. Scope sets the days: the number of hosts, applications, roles and user journeys in play. If a quote from anyone sits far below these bands, ask how many manual testing days it contains.
How it runs
Scoping call to retest in five steps
Scoping call
Thirty minutes with Ben to cover what you need tested, who has asked for it and when you need the report. You get a fixed quote the next business day.
Rules of engagement
Scope, test windows, excluded systems and emergency contacts agreed in writing. Test accounts and access set up with your team.
Testing
Manual testing against the agreed scope. Critical findings are raised with you the day they are confirmed.
Report and walkthrough
Executive summary and technical findings, then a call with the tester so your engineers can ask questions and plan fixes.
Step five is the retest. When your fixes are in, we test the findings again and issue an updated report confirming which are closed. This is usually the document your customer or auditor asks for.
When organisations test
Who asks for a penetration test, and what they require
Customers and auditors
Evidence of testing
ISO 27001 and SOC 2 auditors expect to see recent testing without naming a method. PCI DSS requires a test at least every 12 months and after significant changes. Enterprise security questionnaires ask for the date of your last test and whether findings were retested.
Regulators
Systematic testing
APRA CPS 234 requires regulated entities to run a systematic testing programme using appropriately skilled and functionally independent specialists. The ISM expects penetration testing before deployment of significant changes and at least annually.
Change and incidents
Before a launch or after an incident
Organisations also test before a new customer portal goes live, after a cloud migration or an acquisition, and after a near miss when the board wants to know what an attacker could reach today.
Not sure which applies to you? Ben will tell you on the call, including when a narrower and cheaper test is the right answer. Our guide to penetration testing costs and scoping a test attackers would respect cover the detail.
Book the call
Choose a time
Tell Ben what prompted the search, whether that is a customer questionnaire, an audit, a launch date or a board request. He will confirm the scope and dates, and tell you if a narrower test would do the job.
You will have a fixed quote in writing the next business day.
- No sales pitch. If a vulnerability scan is all you need, Ben will tell you on the call.
- Your details are used to set up the call and send the quote, nothing else.
Prefer email or phone? Send a note or call +61 2 7200 2554.
Who does the work
Who does the testing
The practice
CISO-led
Our cyber security practice is led by our Chief Information Security Officer and run by Ben. The same team does Essential Eight assessments, incident response and vCISO work, so the report tells you what to fix first as well as what is wrong.
The testers
Certified and reviewed
The tester assigned to your engagement holds a recognised penetration testing certification. A senior practitioner reviews every report before it is sent to you.
The firm
Australian since 2010
Coder Trove has worked with mid-sized and enterprise organisations across Australia since 2010.
Common questions
Penetration testing questions, answered
How much does a penetration test cost?
How long does it take?
What is the difference between a vulnerability scan and a penetration test?
Are your testers certified?
Is retesting included?
What does the report look like?
Will testing disrupt production?
Do we need a penetration test for the Essential Eight, ISO 27001 or our insurer?
What access do you need from us?
Related: Essential Eight assessment · Virtual CISO · Cyber security practice
Start here
Tell us what you are protecting
Thirty minutes with Ben, then a fixed quote and agreed dates in writing the next business day.
