// FAQ

Frequently asked questions

Straight answers to the questions every Australian buyer asks. If yours is not here, ask us directly.

Hands at a laptop during a scoping conversation
What is the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment is broad and mostly automated: known weaknesses, rated. A penetration test is deep and manual: a tester exploits, chains, and shows impact. VAPT means doing both, with the human in charge. Longer answer in our comparison post.

How much does a penetration test cost in Australia?

A focused test of a small web application typically starts around $6,000 to $8,000 AUD. Most single-application engagements land between $10,000 and $25,000. Large or multi-target programs run beyond that. We quote a fixed price after a short scoping conversation. See the pricing guide.

How long does a penetration test take?

Most engagements are one to three weeks of testing. Add a few days either side for scoping and reporting. If you have an audit, a customer contract or a launch, tell us early and we plan backwards from it.

Will testing break production?

We test carefully and agree rules of engagement up front. Denial-of-service is excluded unless you explicitly request it. Where the risk warrants it we test staging that mirrors production instead.

Do you use automated scanners?

Yes, for breadth. Humans for depth. Every finding in the report is manually verified. Nothing is copy-pasted from scanner output.

What do we get at the end?

A report with an executive summary, technical findings with CVSS, evidence, reproduction steps and remediation, plus a debrief. After you fix, we retest for free and issue an updated report and an attestation letter.

Can you help with ISO 27001, SOC 2, PCI DSS, CPS 234 or Essential Eight?

Yes. Testing and reporting are structured as evidence for those programs. Tell us the framework during scoping. We are not selling you the certification itself.

What do you need from us to start?

Target URLs or ranges, test accounts for each role, a technical contact, and written authorisation. The scoping questionnaire takes about fifteen minutes.

How often should we get tested?

At least annually, and after any significant change: a new application, a major feature, an infrastructure migration. Many clients pair an annual deep test with lighter checks when big releases ship.

Is our data safe with you?

Engagement data is stored encrypted, limited to the testers on your job, and deleted on an agreed schedule. We will sign your NDA before scoping. Details in the privacy notice.

Do you work outside Australia?

The practice is Australian. Data handling is onshore. If your users are here, this is the right office. If you need another jurisdiction, ask before you send production data.

Are you CREST, IRAP or ISO 27001 certified?

We do not claim those on this site. If a buyer requires a specific accreditation, say so in the enquiry and we will tell you honestly whether we can satisfy it, rather than decorate the footer with logos we have not earned.

Still deciding?

Send the target and the deadline. A scoping conversation is faster than another hour on this page.

Get a fixed quote