A follow-up to our [buyer's guide to choosing a penetration testing provider], focused specifically on what drives the price you're quoted.
If you've requested a few pentest quotes as an Australian SMB, you've probably noticed the numbers don't obviously line up. One provider quotes $2,000, another might quote $18,000, for what sounds like the same thing on paper. The gap usually comes down to a handful of specific factors, not just "some providers are more expensive."
What Actually Drives Pentest Pricing?
Scope size. The number of IP addresses, domains, or applications in scope is the single biggest lever. A test covering 25 IPs costs less than one covering 50, simply because there's more surface area to manually work through. This is why providers ask detailed scoping questions before quoting rather than giving a flat number over the phone.
Manual vs automated depth. An automated scan can cover a lot of ground cheaply because it's largely unattended tooling. A manual test requires a certified tester's time for days at a stretch, which is reflected directly in the price. This is the biggest single factor separating an $80 automated assessment from a $12,000 manual engagement.
Testing type. External network testing is generally the cheapest category, since it's testing what's already internet-facing. Internal network testing, web application testing, and social engineering assessments each add complexity and time, which is why advanced engagements covering multiple types cost more than a single-scope test.
Reporting depth. A basic severity-ranked list of findings costs less to produce than a report with an executive summary, board-ready formatting, remediation prioritisation, and a live debrief session. If a provider's price seems low, check what's actually included in the deliverable.
Turnaround time. Faster delivery generally costs more, since it usually means dedicating a tester's full attention rather than fitting the work in around other engagements.
A Practical Way to Think About Which Tier You Need
Rather than asking "what's the cheapest option," a more useful question is "what decision or requirement is this testing for."
- ▸You need a compliance box ticked quickly, or want a baseline read on obvious issues. An automated security assessment (from $80) is a reasonable starting point, particularly if it's your first time testing or you're testing between full engagements.
- ▸You have a defined external footprint (a website, a handful of servers) and need a real manual test, often for cyber insurance or a specific client requirement. An external network penetration test (from $5,000 + GST) covers this without paying for scope you don't need.
- ▸You have both internal and external infrastructure, plus a couple of applications, and need broader assurance. A standard penetration test (from $12,000 + GST) is built for this middle ground.
- ▸You're in a regulated or high-scrutiny environment, dealing with sensitive data, or need to demonstrate resilience against social engineering as well as technical attacks. An advanced penetration test (from $20,000 + GST) covers the full range.
- ▸You need ongoing assurance rather than a point-in-time test, someone to own the risk register, keep reporting board-ready, and provide regular technical checks. A vCISO retainer (from $2,500/month) is a different shape of engagement entirely, continuous rather than periodic.
Is a One-Off Test or an Ongoing Retainer Better Value?
It depends on how often your environment changes and who's currently accountable for security internally. A one-off pentest gives you a point-in-time picture, useful for an annual compliance requirement or before a major launch. A vCISO retainer makes more sense if you don't have anyone internally who owns security day-to-day, since it bundles advisory time, a maintained risk register, and periodic technical checks rather than a single report that starts going stale the day it's delivered.
Many SMBs start with an annual penetration test and move to a retainer once compliance obligations, insurance requirements, or client due diligence requests become frequent enough that a once-a-year snapshot isn't keeping pace.
Do Cheaper Providers Cut Corners?
Sometimes, but not always, and it's worth being specific about where corners typically get cut rather than assuming price alone tells you. The most common shortcuts are: relabelling an automated scan as a "penetration test" without disclosing it, skipping manual validation of automated findings (leading to false positives in the report), providing a raw tool export instead of a written, contextualised report, or omitting a debrief or retest. None of these are always disqualifying on their own, but a provider unwilling to explain clearly what's included at their price point is a bigger warning sign than the price itself.
Related reading: [How to Choose a Penetration Testing Provider in Australia] · [Melbourne Penetration Testing Services for SMBs] · [Automated vs Manual Penetration Testing: Which Do SMBs Need?]
