Penetration testing, Sydney
Penetration testing, scoped in writing first
Testing against systems you own or are authorised to have tested. Targets, timing and limits are agreed on paper before anything is touched.
- Authority
- In writing, before the test
- Output
- A written findings report
- Rate
- $1,000 a day, plus GST
- Reply
- Within one business day
Authorisation comes before anything else
A penetration test is an attack you asked for. The only thing separating it from a criminal offence is written permission from the party entitled to give it, which is why none of the work starts until that is in hand.
Testing runs only against systems you own, or systems you are authorised to have tested. No exceptions, and no verbal go-ahead.
If a third party hosts or operates the system, their written authorisation is needed as well as yours. Their infrastructure is not tested on your say-so alone.
Targets, methods, timing, and the systems that must not be touched are written down and signed off before the test window opens.
Authorise. Scope. Test. Report.
The scope decides the length of the test, which is why it is settled before the quote.
Authorise
Written permission from you, and from anyone else who operates a system in scope, before a single packet is sent.
Scope
Targets, methods, the test window, the systems that stay untouched, and who to call if something stops responding.
Test
Work runs inside the agreed window and the agreed scope. Anything found is recorded with the steps that found it.
Report
A written report: what was tested, what was found, how to reproduce it, and what to fix first.
What can be in scope
Scope is agreed with you, so this is a starting point for that conversation. What goes in is written down, and so is what stays out.
What faces the internet
The services reachable from outside, and how far someone with no account gets against them.
Web applications
Sites and portals you own: how they handle input, sessions and permissions, and where a user can reach data that is not theirs.
Inside the network
What a device already on your network can reach, and how far a single taken account travels before something stops it.
The limits of a test result
Say this before the report is read, so nobody builds a decision on the wrong idea of what it means.
A penetration test is a point-in-time result. It describes what was reachable inside the agreed scope during the test window, and nothing outside that.
A clean report is not a guarantee. It means nothing was found in scope, in that window, by this test. A change made the next day can open something new.
Live systems can break under test. The agreed scope sets what may be touched and when, and there is a named contact for the moment something stops.
What it costs, and how to start
Every test is quoted once the scope is settled, from a rate of $1,000 a day. All prices are in AUD, plus GST. The scope is what sets how many days the test takes, which is why it is agreed first.
Reply within one business day. Send what you want tested and who owns it, and the scope and authorisation paperwork come back in writing.
Questions to settle before a test
Do I have to authorise the test in writing?
Yes. Testing runs only against systems you own or are authorised to have tested. Targets, timing, methods and limits are agreed in writing before anything starts. Without that agreement, no test happens.
What if someone else hosts the systems?
Then their written authorisation is needed as well as yours. A hosting provider or a platform vendor is a third party, and their infrastructure is not tested on your say-so alone.
Could the test break something?
It can. Any test that touches a live system carries risk. The agreed scope sets what may be touched, when, and who to call if something stops. Name the systems that must not be touched before the window opens.
What do I get at the end?
A written report: what was tested, what was found, the steps that found it, and what to do about it. Findings are ordered by what to fix first, so the report can be worked through in order.
Is a clean result a guarantee?
No. A penetration test is a point-in-time result. It describes what was reachable inside the agreed scope during the test window. A change made the next day can open something the test could never have seen.
What does a test cost?
Every test is quoted once the scope is agreed, because the scope is what sets the length. The quote is built from a rate of $1,000 a day, plus GST.