Skip to main content
    PENETRATION TESTING/AUSTRALIA
    ·By Budget Security

    Penetration Testing for Australian Companies

    Penetration testing for Australian companies is a manual, authorised attack on your web applications, APIs, networks and cloud, scoped to a goal such as CPS 234, SOC 2 or ISO 27001. Budget Security delivers it to businesses in Sydney, Melbourne and across Australia remotely from The Hague: OSCP-certified testers, a start within 7 days of booking, and every finding in your dashboard.

    Scope it yourself, see the tester-day estimate before you commit. Try the calculator or sign up.

    What we test for Australian companies

    You register your assets once in the platform. When you need a test, you pick the asset, the goal and a budget. The scoping engine proposes the plan: how many tester-days, which areas get depth, and exactly what a shorter scope leaves out. If the shorter plan no longer meets the goal you set, it says so before you book.

    Scope options:

    Every engagement is manual testing by an OSCP-certified tester. Automation assists with reconnaissance. Exploitation, business logic and attack chains are human work.

    Penetration testing in Sydney

    Sydney is Australia's financial centre, and most of the companies that reach us from there sit in or around financial services: neobanks, payments and lending platforms, super and wealth software, insurtech, and the SaaS vendors that sell into all of them. Two things shape their scope.

    First, the regulated entity's own obligations under CPS 234 (next section). Second, the supplier questionnaire: an APRA-regulated customer asking a Sydney SaaS vendor for a recent penetration test report before signing or renewing. The second case is more common than the first. The report has to satisfy the customer's security team, which means a named methodology, severity ratings with reproduction steps, and evidence that confirmed findings were retested.

    A typical Sydney engagement is a grey-box test of the customer-facing web app plus its API, 3 to 5 tester-days, with the retest of fixed findings booked from the same dashboard.

    Penetration testing in Melbourne

    Melbourne's mix is broader: health-tech and clinical software, education technology, retail and e-commerce, logistics, and a large base of professional-services firms with internal networks that have never been tested from the inside. Two of the big four banks are headquartered here as well, so the same supplier-questionnaire dynamic as Sydney applies to Melbourne vendors.

    Melbourne buyers more often ask for an internal network test alongside the external one. The question they want answered is not "can someone get in" but "what does someone reach once a laptop is compromised". That scope covers Active Directory, internal web services, file shares and the cloud identities tied to them.

    For health-tech and ed-tech companies, the driver is usually a mix of the Privacy Act obligations below and a customer's ISO 27001 or SOC 2 requirement, so we scope around the systems that hold personal information first.

    APRA CPS 234 and the systematic testing program

    Prudential Standard CPS 234 Information Security commenced on 1 July 2019 and applies to all APRA-regulated entities, including authorised deposit-taking institutions. Its stated aim is to ensure that an APRA-regulated entity "takes measures to be resilient against information security incidents". Source: APRA, CPS 234.

    The clause that matters for scoping is paragraph 27: "An APRA-regulated entity must test the effectiveness of its information security controls through a systematic testing program." Paragraph 31 adds that the entity "must review the sufficiency of the testing program at least annually or when there is a material change to information assets or the business environment." Paragraph 35 requires notifying APRA "as soon as possible and, in any case, no later than 72 hours" after becoming aware of a qualifying information security incident.

    CPS 234 does not use the words "penetration test". A manual penetration test is one way to demonstrate that controls are effective, not a requirement by name. Where it fits: as the control-effectiveness test for internet-facing assets, repeated after material change, with results your testing program can point to. Our report maps each finding to the control it defeated, so the testing program has evidence rather than a scan export.

    If your company is not APRA-regulated but sells to entities that are, expect their testing program to reach you through contract and assurance questionnaires.

    The Essential Eight and the ISM: where a penetration test fits

    The Essential Eight is published by the Australian Signals Directorate. The eight mitigation strategies are patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. The maturity model defines Maturity Level Zero through Three, from a posture with weaknesses that could facilitate compromise, up to a posture aimed at adversaries who are "adaptive and much less reliant on public tools and techniques". Source: ASD, Essential Eight Maturity Model.

    The Information Security Manual is "a cyber security framework that an organisation can apply, using their risk management framework, to protect their information technology and operational technology systems from cyber threats", intended for CISOs, CIOs, cyber security professionals and IT managers. Source: ASD, Information Security Manual.

    Neither document, on the pages fetched for this article, states that an organisation must commission a penetration test. ASD does note that its own experience includes "conducting penetration testing and assisting organisations to implement the Essential Eight". The practical relationship is this: the Essential Eight tells you which controls to implement, and a penetration test tells you whether an attacker can get past them as implemented. Tests that target an Essential Eight claim (for example, that administrative privileges are restricted, or that MFA covers every internet-facing service) are scoped as goal-based tests in the platform.

    Privacy Act 1988 and the Notifiable Data Breaches scheme

    The Privacy Act 1988 regulates how Australian Government agencies and organisations handle personal information. It covers private sector organisations with "an annual turnover of more than $3 million", plus some other designated organisations; together these are "APP entities". Source: OAIC, The Privacy Act.

    Australian Privacy Principle 11.1 states: "An APP entity that holds personal information must take reasonable steps to protect the information from misuse, interference and loss, as well as unauthorised access, modification or disclosure". Source: OAIC, APP 11 guidelines.

    The Notifiable Data Breaches scheme applies to "any organisation or agency the Privacy Act 1988 covers". An eligible data breach involves unauthorised access to, unauthorised disclosure of, or loss of personal information that is "likely to result in serious harm to one or more individuals", where the entity has not been able to prevent that risk with remedial action. Entities must take all reasonable steps to complete the assessment "within 30 calendar days" of becoming aware of the grounds, and must "promptly notify individuals and the Commissioner" once an eligible breach is established. Sources: OAIC, About the NDB scheme and Part 4, NDB scheme.

    APP 11 does not name penetration testing. What a test gives you is a dated, independent record of the "reasonable steps" you took to find and fix the paths an attacker would use to reach personal information, before a breach forces the question.

    SOC 2, ISO 27001 and PCI DSS for Australian companies selling abroad

    If your customers are in the US, SOC 2 will be the report they ask for. If they are in Europe or Asia, ISO 27001. If you take card payments, PCI DSS applies wherever you are. Each framework has its own testing expectation and its own evidence format, and the same engagement can serve all three when it is scoped for it.

    Pick the framework as the goal when you scope, and the report cross-references each finding to the relevant control.

    How an engagement runs from The Hague

    We have no office or staff in Australia, and we say so. Testing is delivered remotely from the Netherlands by OSCP-certified testers. For most scopes that is an advantage, not a compromise.

    • Time zones work for you. The Netherlands runs 8 to 10 hours behind Sydney and Melbourne depending on daylight saving. Our testers start around 6 pm your time and work through your night. Confirmed findings appear in your dashboard with reproduction steps and severity as they are verified, so your team reads them over morning coffee and fixes during the day while we are offline.
    • Start within 7 days of booking. A start within 24 hours is sometimes possible, depends on tester availability, and carries an urgency fee. It is never guaranteed.
    • The report lands within 48 hours after the test ends: executive summary, technical detail, remediation guidance per finding, and the compliance mapping for the goal you chose.
    • Payment is due after report delivery, not when you book.
    • Rescheduling a confirmed start date is not free, because the tester-days are reserved for you.
    • Retests of fixed findings are booked from the dashboard, and the finding is closed in the same tracker your auditor or customer will see.

    What we need from you: scope confirmation, test credentials for authenticated testing, and a written authorisation. The platform collects all three.

    Penetration testing in Australia FAQ

    What does a penetration test cost in Australia?
    Budget Security charges $985 per tester-day for US clients (€849 per day for EU clients). Clients outside the US and EU, including Australia, are quoted in USD. A typical first engagement, a web application plus its API, runs 3 to 5 tester-days, so $2,955 to $4,925, report and one retest included. At current exchange rates that is roughly A$1,500 per tester-day, approximate and invoiced in USD. The exact figure for your scope is on the [pentest pricing calculator](/pentest-pricing/).
    Do you have an office in Sydney or Melbourne?
    No. Testing is delivered remotely from The Hague, Netherlands. We do not have local staff in Australia. Remote testing covers web, API, cloud, external network and VPN-connected internal network scopes. Scopes that require a tester physically on site are outside what we offer in Australia.
    Does CPS 234 require a penetration test?
    Not by name. Paragraph 27 of CPS 234 requires an APRA-regulated entity to "test the effectiveness of its information security controls through a systematic testing program". A penetration test is a recognised way to test control effectiveness for internet-facing systems, and our report is written to slot into that program as evidence.
    Does the Essential Eight require a penetration test?
    The Essential Eight is a set of eight mitigation strategies with a maturity model. The ASD pages fetched for this article do not state that a penetration test is required. A test is how you verify the controls hold against an attacker, which is a separate question from whether they are implemented.
    Will your report work for an Australian customer's security questionnaire?
    Yes. The report names the methodology, rates each finding by severity with reproduction steps, records which findings were retested and closed, and is delivered through a dashboard your customer's assessor can be given read access to.
    Can you test cloud workloads hosted in Australian regions?
    Yes. Cloud penetration testing covers configuration, identity and privilege escalation paths in your accounts regardless of region. Data residency of your workloads is unchanged by the test; our testers access your environment over authorised, logged connections only.
    How fast can you start?
    Within 7 days of booking in most cases. A faster start within 24 hours is possible when a tester is available and carries an urgency fee. It is not guaranteed.
    What happens after the test?
    The report is delivered within 48 hours after the test ends. You fix the findings on your schedule, then book the retest from the dashboard. Payment is due after the report is delivered.
    NEXT STEP

    Penetration testing for your Australian company, scoped by you, priced before you commit.

    OSCP-certified testers. Start within 7 days. Findings in your dashboard by your morning. Report within 48 hours after the test ends.