Cyber security · Penetration testing

Penetration testing for Australian organisations, scoped in one call

Certified testers follow a methodology set by our CISO. You get findings your engineers can act on, we retest the fixes at no extra cost, and the price is fixed before testing starts.

A$8,000 to A$35,000Most engagements land between A$15,000 and A$25,000 depending on what is in scope. Fixed quote within one business day of a 30-minute scoping call. Prices exclude GST.
Book a 30-minute scoping call With Ben Jones, our cyber security practice lead. He will send a short agenda beforehand.

What you receive

  • Executive summaryWritten for the board, your customer or your insurer
  • Technical findings reportSeverity, evidence, reproduction steps and remediation priority for each finding
  • Findings walkthroughA call with the tester so your engineers can ask questions and plan the fixes
  • Retest and updated reportFixed findings re-tested and confirmed closed, included in the price
  • Manual testing by a personScanners find the obvious weaknesses. A tester works out what they lead to
  • Certified testersEvery engagement is run under a CISO-led methodology
  • Retesting includedFixes are verified and the report updated at no extra cost
  • Fixed scope, fixed priceAgreed in writing before testing starts

What we test

Penetration testing services and what they cost

TestWhat it coversTypical cost (ex GST)
External networkEverything of yours that faces the internet: perimeter, exposed services, remote access, email securityA$8,000 to A$18,000
Web application and APIAuthentication, authorisation between roles, input handling, business logic, the APIs behind the appA$12,000 to A$30,000
Internal network and Active DirectoryWhat an attacker or a compromised laptop can reach once inside: privilege escalation, lateral movement, domain compromiseA$15,000 to A$35,000
Cloud configuration, mobile, social engineeringMicrosoft 365, Azure and AWS configuration reviews, mobile applications, phishing simulationsScoped individually

The price is days of a tester's time plus reporting. Scope sets the days: the number of hosts, applications, roles and user journeys in play. If a quote from anyone sits far below these bands, ask how many manual testing days it contains.

How it runs

Scoping call to retest in five steps

Scoping call

Thirty minutes with Ben to cover what you need tested, who has asked for it and when you need the report. You get a fixed quote the next business day.

Rules of engagement

Scope, test windows, excluded systems and emergency contacts agreed in writing. Test accounts and access set up with your team.

Testing

Manual testing against the agreed scope. Critical findings are raised with you the day they are confirmed.

Report and walkthrough

Executive summary and technical findings, then a call with the tester so your engineers can ask questions and plan fixes.

Step five is the retest. When your fixes are in, we test the findings again and issue an updated report confirming which are closed. This is usually the document your customer or auditor asks for.

When organisations test

Who asks for a penetration test, and what they require

Customers and auditors

Evidence of testing

ISO 27001 and SOC 2 auditors expect to see recent testing without naming a method. PCI DSS requires a test at least every 12 months and after significant changes. Enterprise security questionnaires ask for the date of your last test and whether findings were retested.

Regulators

Systematic testing

APRA CPS 234 requires regulated entities to run a systematic testing programme using appropriately skilled and functionally independent specialists. The ISM expects penetration testing before deployment of significant changes and at least annually.

Change and incidents

Before a launch or after an incident

Organisations also test before a new customer portal goes live, after a cloud migration or an acquisition, and after a near miss when the board wants to know what an attacker could reach today.

Not sure which applies to you? Ben will tell you on the call, including when a narrower and cheaper test is the right answer. Our guide to penetration testing costs and scoping a test attackers would respect cover the detail.

Book the call

Choose a time

Ben Jones
Ben JonesCyber Security Practice Lead, Coder Trove

Tell Ben what prompted the search, whether that is a customer questionnaire, an audit, a launch date or a board request. He will confirm the scope and dates, and tell you if a narrower test would do the job.

You will have a fixed quote in writing the next business day.

  • No sales pitch. If a vulnerability scan is all you need, Ben will tell you on the call.
  • Your details are used to set up the call and send the quote, nothing else.

Prefer email or phone? Send a note or call +61 2 7200 2554.

Who does the work

Who does the testing

The practice

CISO-led

Our cyber security practice is led by our Chief Information Security Officer and run by Ben. The same team does Essential Eight assessments, incident response and vCISO work, so the report tells you what to fix first as well as what is wrong.

The testers

Certified and reviewed

The tester assigned to your engagement holds a recognised penetration testing certification. A senior practitioner reviews every report before it is sent to you.

The firm

Australian since 2010

Coder Trove has worked with mid-sized and enterprise organisations across Australia since 2010.

Common questions

Penetration testing questions, answered

How much does a penetration test cost?
Most of our engagements fall between A$15,000 and A$25,000. A scoped external test for a modest perimeter can be A$8,000 to A$18,000; a large web application or internal and Active Directory assessment can reach A$35,000. The quote is fixed after a 30-minute scoping call and does not move unless the scope does.
How long does it take?
Testing typically runs one to three weeks depending on scope, with the report a few days after testing ends. The dates are agreed in the rules of engagement before anything starts.
What is the difference between a vulnerability scan and a penetration test?
A scan is automated and lists known weaknesses. A penetration test has a person exploiting and chaining those weaknesses to show what an attacker could reach. We run scanners too, but a scan on its own is not a test, and we will say so if a scan is all you need.
Are your testers certified?
Yes. The tester assigned to your engagement holds a recognised penetration testing certification, and every engagement runs under a methodology set by our CISO, drawing on OWASP and PTES. Ask on the call and Ben will tell you who is assigned and what they hold.
Is retesting included?
Yes. Once you have fixed the findings, we retest them and issue an updated report confirming what is closed. There is no separate fee for the retest.
What does the report look like?
An executive summary for the board or your customer, then each finding with severity, evidence, reproduction steps and prioritised remediation your engineers can act on. Ben walks you through the report structure on the scoping call.
Will testing disrupt production?
Testing windows, excluded systems and emergency contacts are agreed in writing before we start. Critical findings are raised with you as soon as they are confirmed, not held for the report.
Do we need a penetration test for the Essential Eight, ISO 27001 or our insurer?
The Essential Eight does not require one. ISO 27001 and SOC 2 auditors expect evidence of testing without naming a method. PCI DSS requires a test at least every 12 months and after significant change, and APRA CPS 234 requires a systematic testing programme. Some insurer proposal forms ask whether you test annually. We will tell you on the call which of these applies to you.
What access do you need from us?
For an external test, the in-scope IP ranges and domains. For a web application, test accounts for each user role and a non-production environment where possible. For an internal test, a device or VPN account on the network. Your IT team or MSP spends hours on this, not days.

Related: Essential Eight assessment · Virtual CISO · Cyber security practice

Start here

Tell us what you are protecting

Thirty minutes with Ben, then a fixed quote and agreed dates in writing the next business day.

© 2026 Coder Trove Pty Ltd · ABN 87 138 515 821 · Australia