Network penetration testing

Find the path from reachable service to sensitive system.

External and internal testing with explicit host ranges and segmentation goals.

Human-led testing.
Manually verified findings.

  • OSCP-certified testers
  • Written testing boundaries
  • Actionable remediation
What we investigate

A scope with a purpose.

External exposure

Internet-facing services, remote access and reachable management interfaces.

Internal attack paths

Service weaknesses and controlled lateral movement from an agreed start point.

Segmentation

Whether the named boundaries actually separate users and sensitive systems.

Before testing

What we need from you

  • IP ranges and who owns them.
  • External or internal access requirements.
  • Critical systems and maintenance restrictions.
  • For internal work: a test connection and a named escalation contact.
Use the scoping checklist
After testing

What you can act on

  • A map of validated paths and affected hosts.
  • Starting access and business impact per path.
  • Exposure reduction priorities for infrastructure owners.

Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.

Limits matter

What this test does not cover

  • Wireless, physical access and social engineering.
  • Denial of service.
  • Unapproved third-party infrastructure.
  • Internal segmentation proof from an external test.
Questions before you book

Practical answers.

External, internal or both?

External testing starts outside your network. Internal testing starts from an agreed level of access inside it. Choose based on the threat you need to assess. One does not replace the other.

What does a penetration test cost?

From A$7,500 ex GST for one web application with its API and two user roles. That covers five testing days, the report and a retest of critical and high findings. More applications, endpoints or cloud accounts give an indicative range. The price is fixed once scope is agreed, in writing, before work starts.

How long will it take?

Testing effort and elapsed delivery time are different. We agree both after reviewing the scope, access readiness and your deadline. Leave time for remediation and a focused retest.

Network testing answers a perimeter question. Where the estate is a cloud account rather than a subnet, cloud penetration testing is the right scope, and configuration questions are better answered by a cloud security review. If a maturity level was named, read the Essential Eight assessment page, and how to scope a penetration test covers what to send us first.

Let’s scope it

Let’s define your networks test.

Share the assets and your reason for testing. We will confirm the approach, fee and schedule.

Request a quote

Last reviewed: