Find out where an attacker could gain access, what they could reach and which fixes deserve attention first. Aegentra scopes manual penetration testing around your applications, APIs or networks, then translates the findings into practical work for your technical team and clear decisions for your business.
External network testing from
A$4,500 + GST
For an agreed small external perimeter. Application, API and internal-network testing are quoted separately.
Australian business support. Testing arrangements and the assigned team are confirmed in your proposal.
/ Choose your scope
Test the service your customers actually use
A customer portal, a public firewall and an internal network expose different risks. Start with the asset and the question you need answered—not a bundle that assumes every environment is the same.
Web applicationsSelected
Can one user reach another customer's information?
Assess agreed user roles, sign-in and session handling, access controls and important business workflows. A meaningful scope identifies the application, roles, integrations and features to test—not just its homepage URL.
Tell us the application, environment, user roles and sensitive workflows. Use test accounts and synthetic data where practical.
API coverage is included only where those endpoints and roles are explicitly in scope.
APIsSelected
Does the API enforce the permissions your business expects?
Examine the agreed endpoints, authentication model, object-level permissions and exposed information. Include the difference between an ordinary user, an administrator and a separate customer organisation where relevant.
Tell us the API type, approximate endpoint count, authentication method and roles. Share specifications through the agreed secure channel.
An application test does not automatically cover every API, integration or tenant boundary.
External networksSelected
What can someone reach from outside your organisation?
Assess the agreed internet-facing hosts and services, such as remote-access gateways, exposed administration interfaces and public servers. Manual validation helps distinguish a scanner warning from a weakness that can be demonstrated within the authorised scope.
Tell us the approximate number of active public IP addresses, exposed services and hosting arrangements. Confirm which systems you own or are authorised to test.
This is not an internal-network test or an authenticated review of every hosted application.
Internal networksSelected
What could an agreed internal starting point reach?
Evaluate selected identity, privilege and network boundaries from the access position defined in the scope. The proposal records the environment, permitted actions and systems that must remain outside the test.
Tell us the locations, network boundaries, identity platform and proposed access arrangements.
Social engineering, wireless testing, physical access and disruption testing require separate agreement.
Not sure which test you need? Bring the buyer requirement, planned release or risk concern. We will help define an appropriate scope.
Prepare your testing brief
Penetration-testing scoping worksheet
Aegentra · 03 9956 9399 · Contact@aegentra.com.au
Use this to prepare a scoping discussion. This worksheet is not authorisation to test, a contract or an automated quotation. Do not put passwords, tokens, personal records, private keys or vulnerability evidence in it.
The business question
What prompted the test: a release, customer request, assurance programme, material change or concern? Who will read the report? What decision must it support?
The environment
Which type of scope is involved: external network, internal network, web application or API? Describe its approximate size without listing sensitive targets in a public form. How many user roles or customer boundaries exist? Is production or a representative test environment proposed?
The buyer requirement
Does your customer specify a report age, testing approach, scope, tester qualification, accredited provider, remediation status or retest evidence? Attach the exact requirement through an agreed secure channel rather than paraphrasing it as “we need a pentest certificate”.
Permission and restrictions
Who owns the systems and can authorise testing? Are hosting providers, managed services, shared environments or other third parties involved? Which actions or systems are excluded? What change windows, operational risks and stop conditions must be considered?
Access and preparation
Can you provide appropriate test accounts, roles, test data and relevant documentation? Who will arrange them securely? Are any releases or infrastructure changes planned during the testing window?
Findings and follow-through
Who receives urgent findings? Who can approve remediation? Who needs the executive summary and technical discussion? What retest evidence does the buyer expect, and when can your team realistically implement fixes?
Quotation checks
Ask the proposal to identify the actual targets, depth of manual work, assigned testing responsibilities, limitations, reporting, retest terms, delivery dates, client dependencies, fee and tax treatment. Confirm any subcontractor or specialist delivery arrangement before booking.
Next step: Contact Aegentra to agree a scope. No testing starts until the required written authorisation and engagement terms are in place.
/ Scope and pricing
A clear starting price. A written boundary.
Indicative prices in Australian dollars, excluding GST. Your fixed-fee quote depends on the agreed scope, complexity and testing depth.
Small external network test
A small set of internet-facing systems. Excludes a full authenticated application assessment.
A$4,500–A$6,500+ GST
Small authenticated web-application test
One application with limited functionality and user roles. API coverage is explicitly agreed in the scope.
A$6,500–A$10,000+ GST
Small internal network test
One straightforward environment, with agreed systems, identity infrastructure and testing objectives.
A$6,500–A$12,000+ GST
Combined application and external infrastructure testing
One small application and its agreed internet-facing infrastructure. More complex scopes may exceed this range.
A$10,000–A$18,000++ GST
Small external-perimeter test
FromA$4,500 + GST
A$4,950 including Australian GST.
Designed for a limited external perimeter of up to five active public IP addresses with a straightforward set of exposed services. The number of addresses alone does not determine suitability: service complexity, access requirements and testing depth are assessed before we confirm the fixed fee.
A written target list, rules of engagement and testing window.
Automated discovery supported by manual investigation and authorised validation.
An executive summary and technical findings with evidence, risk priorities and remediation guidance.
A findings discussion with your nominated technical contact.
One retest round of originally reported High and Critical findings on the same in-scope assets, requested within 30 days of the final report, with an updated status record.
The starting package excludes authenticated web-application and API testing, internal networks, source-code review, phishing, denial-of-service testing and hands-on remediation. New assets, material application changes, assessment work outside the agreed scope or further retest rounds require a revised scope. Finding more weaknesses within the agreed initial assessment does not itself change the fixed fee. Retest scheduling is agreed separately; findings that remain unresolved are recorded as open.
What changes the quote?
The main drivers are active targets and exposed services, application features, user roles, APIs, environment complexity, access arrangements, reporting requirements and the depth of retesting. We confirm these before work starts. A smaller asset count does not necessarily mean a simpler test.
/ Controlled delivery
Agree the boundaries. Test. Explain. Verify.
Agree
Confirm the business question, targets, exclusions, access, owner permissions and third-party conditions. Record the testing window, escalation contacts, stop conditions and how sensitive evidence will be handled. Testing starts only after written authorisation.
Test
Investigate the agreed environment with tools and manual techniques appropriate to its risks. Validate findings within the permitted limits. If testing uncovers a concern needing urgent attention, use the agreed escalation route rather than waiting for the final report.
Explain
Connect technical findings to the information, services and business processes at risk. Explain what was tested, what could not be tested and what your team should do next.
Verify
After your team implements the fixes, the agreed retest checks the original findings. Record what is resolved, still open or not retested. A retest is not a fresh assessment of every subsequent change.
Testing can affect systems. The engagement is planned to manage disruption, not to promise that disruption is impossible.
/ Useful evidence
A report your engineers can fix—and your leadership can understand
The executive summary explains the main exposure and business decisions. The technical report records affected assets, supporting evidence, the basis for severity, remediation recommendations and testing limitations. Your team can use it to assign work and track the remaining risk without treating every scanner result as equally important.
From finding to verified fix
Illustrative example—not an Aegentra client finding.
A test user can reach a record belonging to a different customer in the agreed test environment.
Customer information may be disclosed across an account boundary. The actual severity depends on the information and access demonstrated.
Apply server-side access checks consistently and add tests that verify customer separation.
Repeat the agreed access checks after the change and document whether the original weakness remains.
Detailed evidence belongs in the client's controlled report, not on this public page. This example does not provide a real target or a record of an actual breach.
/ Threat context
Current evidence. Practical reasons to test.
New vulnerabilities and configuration mistakes can change an organisation's exposure between assessments. Testing helps examine the agreed environment; patching, monitoring and incident response remain ongoing responsibilities.
NDB notifications received
View chart data
NDB notifications received by calendar year
Calendar year
Notifications
2024
1,112
2025
1,205
Data breach notifications reported to Australia's privacy regulator
The OAIC recorded 1,112 notifications in 2024 and 1,205 in 2025—an increase of approximately 8%, using the figures in its July 2026 release.
These are notifications received under Australia's Notifiable Data Breaches scheme, not a count of all cyberattacks. They include causes beyond cyber intrusion. The chart does not measure the effectiveness of penetration testing.
ASD's ACSC reported active exploitation affecting Adobe Commerce and Magento Open Source and urged affected organisations to follow vendor mitigation advice. Our takeaway: maintain an accurate view of exposed applications and verify remediation. Do not delay urgent patching while waiting for a penetration test.
An ACSC advisory highlighted the exploitation of exposed management services, weak configurations and known vulnerabilities in network devices. Our takeaway: include the external services and administrative interfaces that actually support your business when agreeing the test scope.
Sources checked 22 September 2026. These are selected official advisories, not a live attack feed or evidence that Aegentra clients were affected.
/ Beyond the test
Connect the findings to the work that follows
A useful penetration test gives your organisation a defined set of findings to address. Aegentra can scope related security uplift and governance work separately, so the test results feed into accountable remediation rather than becoming a report that nobody owns.
ISO 27001
Testing evidence can inform technical risk assessment, treatment decisions and control evaluation within your ISMS. A penetration test is not an ISO 27001 internal audit and does not issue an ISO certificate. Your system scope, risks and contractual requirements determine the testing you need.
An appropriately scoped test and its remediation record can support evidence considered during SOC 2 readiness. Confirm the expected coverage and timing with the independent CPA firm. A penetration-test report is not a SOC 2 report and does not guarantee a favourable examination outcome.
Where findings concern your Microsoft 365 environment, agree the configuration or access changes your business needs. Remediation is a separate workstream; a test does not automatically include changing production systems or ongoing monitoring.
Before booking, your proposal identifies the testing lead, delivery responsibilities, relevant experience and qualification evidence, including any specialist delivery partner. Ask us to explain how that experience matches the systems you need tested.
Is a vulnerability scan the same as a penetration test?
No. Scanning can identify known weaknesses at scale. A penetration test adds human investigation, authorised validation and analysis of how the findings affect the agreed environment. Ask what manual work, evidence and limitations are included—not just which tools are used.
Should the test use production or a test environment?
Choose the environment during scoping. A representative test environment can reduce operational risk, while production may have configurations or integrations that differ. Record those differences, permitted actions and limitations before testing begins.
How long will the engagement take?
The proposal separates preparation, active testing, reporting and any retest window. Target complexity, access, change restrictions and client availability affect the schedule. We confirm dates after scoping rather than offering a universal completion promise.
How often should we test?
Set a schedule based on risk, significant changes, contractual requirements and your assurance programme. A major release, new integration or material infrastructure change may warrant testing outside the regular cycle. An annual calendar entry alone does not prove that current changes have been assessed.
Will a clean report guarantee security or win a tender?
No. Testing is limited to an agreed scope, approach and point in time. A buyer may require particular coverage, evidence, tester qualifications or an accredited provider. Check those requirements before commissioning the work; a report on the wrong scope may not satisfy them.
Can you test systems hosted by another provider?
Only where the necessary permissions and provider conditions are satisfied. Confirm ownership, permitted testing and shared infrastructure before authorisation. Control of an application does not automatically give permission to test every underlying platform.
/ Let's talk
Tell us what needs testing
Share the type of system, approximate size, reason for testing and any customer deadline. We will clarify the proposed scope, reporting needs and delivery arrangements before quoting. Do not send passwords, access tokens or sensitive customer records through the enquiry form.