Know exactly what you're paying before you sign anything.
Three fixed-fee engagement sizes. Scope is defined in writing before we start: no scope creep, no surprise invoices.
All prices in AUD + GST. International clients are GST-free.
Choose the right scope for your organisation.
All tiers include a written scope document, fixed fee, severity-ranked report, and proof-of-concept evidence on every critical finding.
Starting at
$5K AUD
Basic
+ GST · International clients GST-free
- External network penetration test
- Up to 25 IP addresses
- Optimal for small web apps
- Detailed report & risk rating
- Remediation recommendations
- Delivered in 3–5 days
Starting at
$12K AUD
Standard
+ GST · International clients GST-free
- External & internal network penetration test
- Up to 50 IPs and 2–3 web applications
- Comprehensive report & executive summary
- Remediation guidance
- Debrief session included
- Delivered in 2–3 weeks
Starting at
$20K AUD
Advanced
+ GST · International clients GST-free
- Full-scale penetration test
- External & internal network
- Web applications & APIs
- Social engineering assessments
- Delivered in 2–3 weeks
Not ready for a full engagement?
Our automated security assessment starts from $80 (same toolchain, report in 24 hours).
Internal Penetration Test & Remediation Validation
Azure-hosted Windows server infrastructure · Financial services sector · Black-box engagement
Assessment type
Internal Black-Box Pentest + Remediation Validation
Method
Living off the Land — built-in Windows tooling only
Turnaround
Initial report delivered · Validation completed in 4 days
What we found
10 findings identified across two hosts, including factory-default credentials on a live security monitoring platform, an unrestricted legacy remote access protocol transmitting credentials in cleartext, and no account lockout policy enabling unlimited brute-force attempts.
Remediation outcome
Four days after delivery, a structured validation session confirmed the environment moved from a largely unhardened state to a substantially secured posture, with documented evidence for 8 of 10 findings and a clear action plan for the remaining 2.
Resolved
Verified closed
Partially resolved
Pending client-side platform changes
Accepted risk
Documented per client instruction
The engagement demonstrated the value of pairing a penetration test with a structured remediation validation: not just identifying what's wrong, but verifying that fixes work as intended and flagging where partial remediations leave residual risk.
Aussie Pentest · Internal engagement summary · All client details anonymised
Need something specific?
Answer a few quick questions and we'll come back with a tailored quote.
Not sure which tier is right?
Book a 15-minute call: we'll work out the right scope for your environment and give you a fixed-fee quote.
No obligation · No sales pressure
