home-hero-mobile

Australian Penetration Testing and Compliance.

We specialise in CREST-accredited penetration testing and helping Australian organisations achieve ISO 27001 and ISO 42001 certification, as well as SOC 2 compliance. Delivered by our own Australian team, with fixed-price services and no offshore subcontracting.

CREST accredited penetration testing provider
CREST Accredited
CyberCert SMB1001 Gold Level 3 certified
SMB1001 Gold Level 3
Australian Cyber Awards 2025 finalist, Cyber Security Consulting Business of the Year SME
Cyber Awards 2025/2026 Finalist

compliance PACKAGES

Compliance is complex. We make it simple and get you certified.

Every client we have taken to a SOC 2 or ISO 27001 audit has passed it. With a dedicated consultant guiding you at every step, we take the complexity out of certification. Fixed monthly costs over 12 months mean no surprises. Just a clear, proven path to compliance.

Our rapid-compliance packages are designed to get you audit‑ready in 3–9 months, without the need for a full-time internal resource. Most Australian businesses do not need a shelf of cybersecurity services. They need the two or three that answer the question in front of them, sized against the cyber threats their industry actually faces, and priced so the finance conversation is short.



Why Australian Companies Choose Siege Cyber

How we compare Siege Cyber The Other Guys
Time to audit ready 3 to 9 months 9 to 18+ months
Compliance team Australian based team Inexperienced and offshore
Effort required Fully managed Guidance provided
Cost Fixed pricing, all included Hard to forecast costs
Scope Tailored to your business One size fits all approach
Certification result Every client has passed to date Unsupported outcome
Support Ongoing, you stay compliant Ends at certification
What it comes down to Dedicated team. Fixed price. With you every step of the way and beyond. Rotating consultants, inflated scope, and costs that grow as the work progresses.



Don't just take our word for it:

Our work speaks for itself, but our clients say it better...

Three client quotes praising Siege Cyber on security posture, ISO 27001 certification and SOC 2 readiness

Partner Network

PENETRATION TESTING PRICING

Uncover vulnerabilities before attackers do. Our fixed-price, CREST accredited penetration testing service identifies security gaps and provides clear, actionable recommendations to strengthen your defences.

Want to spread the cost and maintain ongoing protection? We can tailor a 12-month testing program to suit your requirements and budget. Every engagement covers the places attacks actually land: external and internal networks, web application security, APIs and cloud environments. You get identified vulnerabilities ranked by what they would let an attacker do to your business, not by a scanner score, plus a retest once you have fixed them.

Our Valued Customers

We value our relationships with our customers and are committed to providing the best service to keep their businesses protected from online threats. Your trust is our top priority.

Our team holds the certifications, so you don't have to guess

Siege Cyber is an Australian cyber security consultancy based in Brisbane, Queensland. It is a CREST-accredited company for penetration testing, listed on the CREST Australia New Zealand approved companies register, and holds SMB1001 Gold Level 3. It delivers penetration testing and fixed-price ISO 27001, SOC 2 and ISO 42001 certification programmes for organisations across Australia, and works with MSPs and advisory firms on a white-label basis. Engagements are quoted at a fixed price and delivered by an Australian team.

That accreditation is assessed and held at company level. It covers the penetration testing we deliver across Australia, and you can verify it on the CREST member register rather than taking our word for it.

Every penetration test is carried out by certified penetration testers. Every compliance engagement is led by certified ISO 27001 implementers, the highest qualification for building and delivering an ISO management system. You're not getting junior consultants learning on your time. You're getting people who've done this before, and who know what auditors expect.

Partner with Siege Cyber

We work alongside MSPs, IT providers, auditors, and advisory firms, not against them. When your clients need penetration testing or help getting ISO 27001 or SOC 2 certified, we deliver the work, you keep the relationship.

Proven track record, not promises

We've delivered hundreds of penetration tests across Australian businesses, helping them find and fix vulnerabilities before they become incidents. On the compliance side, we've guided numerous organisations through ISO 27001 and SOC 2 certification, and every single one has passed their audit.

We don't just advise. We do the work, and we get results.

threats-logo

Want the full picture before we talk?

Download the Siege Cyber datasheet to see exactly what's included, how our packages work, and what to expect. And when you're ready, we're one click away.

Common questions

What does penetration testing cost in Australia?

Siege Cyber publishes fixed prices. External network testing runs from $3,400 to $9,500, web application and API testing from $5,900 to $16,500, basic website testing from $3,400 to $6,500, and mobile application testing from $5,900 to $16,500. The figure depends on scope, which is agreed in writing before the engagement starts, and the price in the proposal is the price on the invoice.

Is Siege Cyber CREST accredited?

Yes. Siege Cyber is a CREST-accredited company for penetration testing. Accreditation is assessed and held at company level, and it can be verified on the CREST Australia New Zealand approved companies register. CREST accredits companies and certifies individuals, and accreditation is granted separately by discipline, so it is worth checking the discipline as well as the logo when comparing providers.

How long does ISO 27001 or SOC 2 certification take?

Siege Cyber's CERTIFY programmes are designed to get an organisation audit ready in three to nine months, against a typical market timeline of nine to eighteen months. The programme runs as a fixed monthly cost across a twelve month subscription at $3,750 per month, with ongoing maintenance available afterwards at $2,450 per month.

Where is Siege Cyber based and do you work outside Brisbane?

Siege Cyber is based at Level 27, 32 Turbot Street, Brisbane, Queensland, and works with clients across Australia. Testing of networks, web applications, APIs and cloud environments is delivered remotely, with on-site attendance planned into the scope where the environment genuinely requires it, such as operational technology work.

Do you work with MSPs and other IT providers?

Yes. Siege Cyber works alongside managed service providers, IT providers, auditors and advisory firms rather than competing with them. Siege Cyber delivers the penetration testing or the ISO 27001 and SOC 2 certification work, and the partner keeps the client relationship.

OUR partners Say

Latest Intelligence

How to Choose a Penetration Testing Company in Australia

How to Choose a Penetration Testing Company in Australia

Blog

There are a lot of penetration testing companies in Australia and the quotes vary wildly. What CREST accreditation does and does not tell you, six questions that get different answers, and when a test is not the right purchase yet.