How to Choose a Penetration Testing Company in Australia
Blog

How to Choose a Penetration Testing Company in Australia

There are a lot of companies in Australia offering penetration testing, and from the outside most of their websites say the same things. This page is an attempt at the guide we would want if we were buying rather than selling: what actually separates providers, what the credentials mean, and the questions that get you a useful answer.

We are one of those companies, so read this with that in mind. We have tried to write the version that is still useful if you go elsewhere.

The Three Kinds of Provider

Almost every Australian penetration testing company falls into one of three groups, and knowing which you are talking to explains most of what follows.

Specialist testing firms. Testing is the product. Usually smaller, usually accredited, and the people who scope the work are close to the people who do it. You get depth and continuity. You will not get a single vendor for everything.

Large consultancies and the big four. Brand, scale, and a report your board will recognise. You will often be sold by a partner and delivered by a team you meet on day one, and price reflects overhead as much as effort. Genuinely the right answer when the audience for the report is a regulator or a listed company board.

Managed service providers and resellers adding testing. Convenient, often cheaper, and the place to be most careful. If the same organisation built or runs your environment, its test of that environment is not independent, and any reviewer who matters will say so.

What CREST Accreditation Actually Tells You

CREST is the credential that comes up most, and it is widely misunderstood, including by providers who advertise it.

CREST accredits companies. CREST certifies individuals. They are different things. “CREST certified company” is not a category that exists, however often you see it written. A company holds accreditation; a tester holds certification.

Accreditation is granted by discipline, separately. Penetration testing, vulnerability assessment, intelligence led penetration testing, threat intelligence, incident response and security operations centres are assessed individually. A company accredited for penetration testing is not automatically accredited for incident response. If a provider says “CREST accredited” without naming the discipline, ask which one.

It is verifiable. The CREST member register is public. You do not have to take a logo on a website as evidence, and checking takes a minute.

What it covers. To hold it, a company has to put its methodology, reporting standards, data handling, scoping process and quality and complaints processes in front of an assessor, and re-evidence them to keep it. It is not a guarantee of a good test. It is a floor under the process, and a floor is worth a lot when you cannot assess the work yourself.

Siege Cyber is a CREST-accredited company for penetration testing, and you can check that on the register rather than taking our word for it. We have written more about what CREST accreditation means in practice.

Six Questions That Separate Providers

These are the questions that produce different answers from different companies. Most of the others produce the same answer from everyone.

1. What proportion of the test is manual?

This is the single most useful question. Scanners find known issues in known software. They do not find business logic flaws, broken access control between user roles, or the chain of three small problems that together let someone read another customer’s data. If the answer is vague, the proportion is low.

2. Can I see a redacted report?

Ask before you sign, not after. A useful report has reproduction steps, evidence, business impact in your language rather than a CVSS score alone, and remediation specific enough for your engineers to act on. If it opens with a heat map and closes with a risk rating, your engineering team will not be able to use it and your auditor will not be satisfied by it.

3. Who is testing, and do they work for you?

Named individuals, their certifications, and whether they are employees or subcontractors. Subcontracting is not automatically bad, but you should know, because it affects continuity, data handling and who you can talk to afterwards.

4. Is a retest included, and for how long?

You will need evidence that findings were fixed, not just found. If the retest is quoted separately, add it to the price before you compare.

5. How do you handle our findings?

A penetration test report is a shopping list if it leaks. Ask where it is stored, how it is transmitted, who inside the provider can read it, and how long it is retained.

6. Who explains the results?

A debrief with the person who did the testing is worth more than fifty extra pages. If the only contact after delivery is an account manager, you have bought a document rather than an engagement.

Comparing Quotes Without Comparing Apples and Oranges

Quotes for what looks like the same job routinely differ by a factor of three, and it is almost always scope rather than greed.

Before comparing the numbers, make sure each quote covers the same count of applications, user roles, API endpoints, external IP addresses, internal subnets and cloud accounts. Then ask each provider how many tester days they have allowed. Days are comparable in a way that dollars are not, and a provider who will not tell you has told you something.

For indicative bands by test type, we keep an Australian penetration testing pricing guide current.

Does Location Matter?

Less than most city-specific pages imply, with two real exceptions.

Operational technology environments are the first. If the test involves a plant, a port, a grid or anything where a mistake has a physical consequence, being in the room matters and should be scoped in rather than added later.

The second is where the buyer’s own procurement rules favour local suppliers, which happens in state government and some defence-adjacent work. Otherwise, for network, web application, API and cloud testing, the tester’s competence matters considerably more than the tester’s postcode, and the same time zone is usually as local as you need.

We are Brisbane based and test for clients around the country. If you want the local view, we have written guides for Brisbane, Sydney and Melbourne.

When the Test Is Not the Right Purchase Yet

Worth saying, since nobody selling testing says it. If you already know you have unpatched internet-facing systems, no multi-factor authentication on remote access and no asset inventory, a penetration test will confirm that expensively. Close the known gaps first and test afterwards, when the answer is not already obvious.

Equally, if the test exists because a customer or an auditor is going to read the report, buying the cheapest option is false economy. A report that does not survive that reading gets done again.

Where Testing Sits Inside Compliance

Most Australian penetration tests are bought because of a framework rather than because of curiosity. ISO 27001 expects assurance that technical controls work. SOC 2 auditors expect evidence of testing against the relevant criteria. APRA CPS 234 requires systematic testing at a frequency you can justify. Essential Eight maturity tells you controls are configured, not that they hold.

If that is what is driving your test, say so during scoping. It changes what should be in scope and what the report needs to contain, and a provider who does not ask is about to give you a document that does not answer the question you are actually being asked.

Talking to Us

If you want a quote, the fastest route is a short scoping conversation. We will ask what is in scope, what is driving the test and who will read the report. If a smaller piece of work would answer the question, we will tell you that instead.

Get in touch, or read more about our CREST accredited penetration testing.

Siege Cyber is a CREST-accredited company for penetration testing, working with businesses across Australia on fixed-price testing and compliance. Talk to us. Get a Fixed-Price Quote.