Penetration testing · Australia

Find the gaps.
Know what to fix.

An audit to prepare for. A customer to reassure. A product to launch. Get a human-led penetration test that turns technical risk into a clear plan of action.

  • OSCP-certified testers
  • Evidence your engineers can use
  • Scope agreed before testing

Web · Mobile · API · Network · Cloud · AI

Find your starting point

Which test fits your situation?

Two choices. A useful scope, not a guessed price.

01 Why are you looking?
02 What needs testing?

Choose a reason and a system to see the suggested scope. No email needed.

Scope and fee confirmed before testing.

Human-led testing.
Manually verified findings.

  • OSCP-certified testers
  • Written testing boundaries
  • Actionable remediation
Built around your next decision

More than a box to tick.

For assurance

Give the requester useful evidence.

Align the scope to an audit or customer requirement. Record what was tested, what was found and what the result does not establish.

Before you release

Find the issues worth stopping for.

Test the sign-in, data and business workflows that matter before a new feature becomes part of production.

For engineering

Make the next step clear.

Get reproducible evidence and remediation priorities, then confirm the agreed fixes with a focused retest.

From scope to fixes

A clear process. No black box.

  1. 01

    Agree the boundaries

    Systems, roles and objectives. Written authorisation, safe test windows and a stop-test contact.

  2. 02

    Test and validate

    Manual investigation supported by tools. Controlled evidence of impact, with urgent findings raised promptly.

  3. 03

    Make the findings useful

    A concise risk summary and technical detail your engineers can reproduce and act on.

  4. 04

    Check the fixes

    A focused retest of agreed findings, recording resolved, partial and outstanding items. Terms set in the scope.

The deliverable

A report for the decision-maker. And the person fixing it.

Understand the risk without losing the technical evidence. We separate confirmed findings, limitations and remediation status.

Download the illustrative report (PDF)

A 19-page illustrative example built from synthetic findings. Not a client report, and no real company, person or IP appears in it.

Explore what a useful report contains

A test report supports assurance. It is not a certificate of security or a promise of audit acceptance.

SORAMI / SECURITYReport contents

From evidence to action

  1. Executive summaryBusiness exposure and priorities
  2. Scope & limitationsAssets, access, method and coverage
  3. Technical findingsEvidence, impact and severity rationale
  4. Remediation guidancePractical fixes and next steps
  5. Retest recordWhat changed and what remains

Contents overview, not a sample client report.

People behind the testing

Technical judgement matters.

OSCP-certified testers combine methodical investigation with practical engineering context. We use automation where it helps and verify findings before reporting them.

Instant quote

Get an instant quote in 2 minutes

Answer four questions. The indicative price updates as you go. Prices are ex GST.

Indicative until we confirm scope in writing, within one business day. We use your details only to reply. See our Privacy notice.

Questions before you book

Practical answers.

What does a penetration test cost?

From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.

How long will it take?

Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.

Will this satisfy a customer or auditor?

It can provide useful evidence, but acceptance depends on the requester’s requirements. Send us their exact wording before booking. Scope, credential and retest requirements all matter. A test does not itself confer SOC 2 or ISO 27001 certification.

Is the work manual or automated?

Both have a role. Tools help with discovery and coverage; testers investigate business logic, check boundaries and manually validate findings. The result is an assessment, not an unreviewed scanner export.

Can you test production safely?

Production testing needs explicit written permission, agreed techniques, safe test data and an escalation plan. We record constraints and stop if the agreed safety conditions are not met. Destructive testing and denial of service are excluded by default.

What credentials does the team hold?

Our testers hold OSCP, OSWE, OSCE and OSWP from OffSec. The list also includes CREST Registered Tester, eCPPT v2 and Zero-Point Red Team Operator. Cloud and detection work adds AWS and CrowdStrike certifications. Every acronym is expanded on our about page.

Are you a CREST member company?

No. Sorami Consulting Pty Ltd is not a CREST member company, and CREST accreditation is a company status we do not hold. Our testers hold individual CREST Registered Tester certification, which is a different thing. If your procurement form requires a CREST member company, tell us on the scoping call and we will confirm in writing that we are not the right firm.

Request a quote

Send the starting point from this page.

Only your email is required. Scope and fee are agreed in writing.

Your enquiry

Request a quote

Only your email is required. Scope and fee are agreed in writing.

An enquiry, not an instant quote or a booking. We reply within one business day. We use your details only to reply. Our Privacy notice names every processor.

Last reviewed: