// Insights

Plain-English security writing

No fear-mongering, no acronym soup. The questions Australian teams ask before they buy a test, written down so you can brief a vendor, including us.

Hands at a laptop during a scoping conversation
Buying guide / 20 Aug 2026

How to scope a web application penetration test

What to put in the rules of engagement, which roles to include, and how to avoid buying a test that misses the actual risk.

Read post >
Compliance / 6 Aug 2026

APRA CPS 234 and security testing: what actually satisfies the standard

How APRA-regulated entities should brief a pentest so the report maps to information-security control testing, not a generic scan.

Read post >
Compliance / 24 Jul 2026

Essential Eight and penetration testing: how they fit together

The ACSC maturity model is a control program. A pentest is how you find out whether those controls survive a motivated attacker.

Read post >
Compliance / 14 Jul 2026

ISO 27001 penetration testing in Australia

Where independent testing sits in Annex A, what auditors actually look for in a report, and how often to retest.

Read post >
Buying guide / 2 Jul 2026

How much does a penetration test cost in Australia?

Typical price ranges for Australian pentests, what drives the cost up or down, and how to compare quotes properly.

Read post >
Explainer / 18 Jun 2026

Penetration testing vs vulnerability scanning: what's the difference?

Both find security problems, but they answer different questions. When a scan is enough, and when you need a human attacker.

Read post >
Explainer / 28 May 2026

What is penetration testing? A plain-English guide

What actually happens during a pentest, what you get at the end, and how to tell a real one from a rebadged scan.

Read post >
Get a fixed quote