External exposure
Internet-facing services, remote access and reachable management interfaces.
External and internal testing with explicit host ranges and segmentation goals.
Human-led testing.
Manually verified findings.
Internet-facing services, remote access and reachable management interfaces.
Service weaknesses and controlled lateral movement from an agreed start point.
Whether the named boundaries actually separate users and sensitive systems.
Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.
External testing starts outside your network. Internal testing starts from an agreed level of access inside it. Choose based on the threat you need to assess. One does not replace the other.
From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.
Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.
Network testing answers a perimeter question. Where the estate is a cloud account rather than a subnet, cloud penetration testing is the right scope, and configuration questions are better answered by a cloud security review. If a maturity level was named, read the Essential Eight assessment page, and how to scope a penetration test covers what to send us first.
Share the assets and your reason for testing. We will confirm the approach, fee and schedule.
Last reviewed: