Penetration Testing for Australian Companies
Penetration testing for Australian companies is a manual, authorised attack on your web applications, APIs, networks and cloud, scoped to a goal such as CPS 234, SOC 2 or ISO 27001. Budget Security delivers it to businesses in Sydney, Melbourne and across Australia remotely from The Hague: OSCP-certified testers, a start within 7 days of booking, and every finding in your dashboard.
Scope it yourself, see the tester-day estimate before you commit. Try the calculator or sign up.
What we test for Australian companies
You register your assets once in the platform. When you need a test, you pick the asset, the goal and a budget. The scoping engine proposes the plan: how many tester-days, which areas get depth, and exactly what a shorter scope leaves out. If the shorter plan no longer meets the goal you set, it says so before you book.
Scope options:
- Web application penetration testing: authenticated and unauthenticated, manual testing of business logic, access control and session handling.
- API penetration testing: the REST and GraphQL interfaces behind your apps, partner integrations and open-banking flows.
- External and internal network penetration testing: your internet-facing perimeter, then what an attacker can reach once inside.
- Cloud penetration testing: identity, configuration and privilege paths in AWS, Azure and Google Cloud accounts, including Sydney and Melbourne regions.
- Mobile penetration testing: iOS and Android apps and the backends they talk to.
Every engagement is manual testing by an OSCP-certified tester. Automation assists with reconnaissance. Exploitation, business logic and attack chains are human work.
Penetration testing in Sydney
Sydney is Australia's financial centre, and most of the companies that reach us from there sit in or around financial services: neobanks, payments and lending platforms, super and wealth software, insurtech, and the SaaS vendors that sell into all of them. Two things shape their scope.
First, the regulated entity's own obligations under CPS 234 (next section). Second, the supplier questionnaire: an APRA-regulated customer asking a Sydney SaaS vendor for a recent penetration test report before signing or renewing. The second case is more common than the first. The report has to satisfy the customer's security team, which means a named methodology, severity ratings with reproduction steps, and evidence that confirmed findings were retested.
A typical Sydney engagement is a grey-box test of the customer-facing web app plus its API, 3 to 5 tester-days, with the retest of fixed findings booked from the same dashboard.
Penetration testing in Melbourne
Melbourne's mix is broader: health-tech and clinical software, education technology, retail and e-commerce, logistics, and a large base of professional-services firms with internal networks that have never been tested from the inside. Two of the big four banks are headquartered here as well, so the same supplier-questionnaire dynamic as Sydney applies to Melbourne vendors.
Melbourne buyers more often ask for an internal network test alongside the external one. The question they want answered is not "can someone get in" but "what does someone reach once a laptop is compromised". That scope covers Active Directory, internal web services, file shares and the cloud identities tied to them.
For health-tech and ed-tech companies, the driver is usually a mix of the Privacy Act obligations below and a customer's ISO 27001 or SOC 2 requirement, so we scope around the systems that hold personal information first.
APRA CPS 234 and the systematic testing program
Prudential Standard CPS 234 Information Security commenced on 1 July 2019 and applies to all APRA-regulated entities, including authorised deposit-taking institutions. Its stated aim is to ensure that an APRA-regulated entity "takes measures to be resilient against information security incidents". Source: APRA, CPS 234.
The clause that matters for scoping is paragraph 27: "An APRA-regulated entity must test the effectiveness of its information security controls through a systematic testing program." Paragraph 31 adds that the entity "must review the sufficiency of the testing program at least annually or when there is a material change to information assets or the business environment." Paragraph 35 requires notifying APRA "as soon as possible and, in any case, no later than 72 hours" after becoming aware of a qualifying information security incident.
CPS 234 does not use the words "penetration test". A manual penetration test is one way to demonstrate that controls are effective, not a requirement by name. Where it fits: as the control-effectiveness test for internet-facing assets, repeated after material change, with results your testing program can point to. Our report maps each finding to the control it defeated, so the testing program has evidence rather than a scan export.
If your company is not APRA-regulated but sells to entities that are, expect their testing program to reach you through contract and assurance questionnaires.
The Essential Eight and the ISM: where a penetration test fits
The Essential Eight is published by the Australian Signals Directorate. The eight mitigation strategies are patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. The maturity model defines Maturity Level Zero through Three, from a posture with weaknesses that could facilitate compromise, up to a posture aimed at adversaries who are "adaptive and much less reliant on public tools and techniques". Source: ASD, Essential Eight Maturity Model.
The Information Security Manual is "a cyber security framework that an organisation can apply, using their risk management framework, to protect their information technology and operational technology systems from cyber threats", intended for CISOs, CIOs, cyber security professionals and IT managers. Source: ASD, Information Security Manual.
Neither document, on the pages fetched for this article, states that an organisation must commission a penetration test. ASD does note that its own experience includes "conducting penetration testing and assisting organisations to implement the Essential Eight". The practical relationship is this: the Essential Eight tells you which controls to implement, and a penetration test tells you whether an attacker can get past them as implemented. Tests that target an Essential Eight claim (for example, that administrative privileges are restricted, or that MFA covers every internet-facing service) are scoped as goal-based tests in the platform.
Privacy Act 1988 and the Notifiable Data Breaches scheme
The Privacy Act 1988 regulates how Australian Government agencies and organisations handle personal information. It covers private sector organisations with "an annual turnover of more than $3 million", plus some other designated organisations; together these are "APP entities". Source: OAIC, The Privacy Act.
Australian Privacy Principle 11.1 states: "An APP entity that holds personal information must take reasonable steps to protect the information from misuse, interference and loss, as well as unauthorised access, modification or disclosure". Source: OAIC, APP 11 guidelines.
The Notifiable Data Breaches scheme applies to "any organisation or agency the Privacy Act 1988 covers". An eligible data breach involves unauthorised access to, unauthorised disclosure of, or loss of personal information that is "likely to result in serious harm to one or more individuals", where the entity has not been able to prevent that risk with remedial action. Entities must take all reasonable steps to complete the assessment "within 30 calendar days" of becoming aware of the grounds, and must "promptly notify individuals and the Commissioner" once an eligible breach is established. Sources: OAIC, About the NDB scheme and Part 4, NDB scheme.
APP 11 does not name penetration testing. What a test gives you is a dated, independent record of the "reasonable steps" you took to find and fix the paths an attacker would use to reach personal information, before a breach forces the question.
SOC 2, ISO 27001 and PCI DSS for Australian companies selling abroad
If your customers are in the US, SOC 2 will be the report they ask for. If they are in Europe or Asia, ISO 27001. If you take card payments, PCI DSS applies wherever you are. Each framework has its own testing expectation and its own evidence format, and the same engagement can serve all three when it is scoped for it.
- SOC 2 penetration testing: evidence for the CC-series criteria your auditor will sample.
- ISO 27001 penetration testing: evidence for Annex A controls on technical vulnerability management and secure development.
- PCI DSS penetration testing: external and internal testing of the cardholder data environment and its segmentation.
Pick the framework as the goal when you scope, and the report cross-references each finding to the relevant control.
How an engagement runs from The Hague
We have no office or staff in Australia, and we say so. Testing is delivered remotely from the Netherlands by OSCP-certified testers. For most scopes that is an advantage, not a compromise.
- Time zones work for you. The Netherlands runs 8 to 10 hours behind Sydney and Melbourne depending on daylight saving. Our testers start around 6 pm your time and work through your night. Confirmed findings appear in your dashboard with reproduction steps and severity as they are verified, so your team reads them over morning coffee and fixes during the day while we are offline.
- Start within 7 days of booking. A start within 24 hours is sometimes possible, depends on tester availability, and carries an urgency fee. It is never guaranteed.
- The report lands within 48 hours after the test ends: executive summary, technical detail, remediation guidance per finding, and the compliance mapping for the goal you chose.
- Payment is due after report delivery, not when you book.
- Rescheduling a confirmed start date is not free, because the tester-days are reserved for you.
- Retests of fixed findings are booked from the dashboard, and the finding is closed in the same tracker your auditor or customer will see.
What we need from you: scope confirmation, test credentials for authenticated testing, and a written authorisation. The platform collects all three.
FAQ
Penetration testing in Australia FAQ
What does a penetration test cost in Australia?
Do you have an office in Sydney or Melbourne?
Does CPS 234 require a penetration test?
Does the Essential Eight require a penetration test?
Will your report work for an Australian customer's security questionnaire?
Can you test cloud workloads hosted in Australian regions?
How fast can you start?
What happens after the test?
Penetration testing for your Australian company, scoped by you, priced before you commit.
OSCP-certified testers. Start within 7 days. Findings in your dashboard by your morning. Report within 48 hours after the test ends.