Most Australian penetration testing providers will not publish a price. We will. A Siege Cyber penetration test is quoted as a fixed price before the engagement starts, and the ranges below are the real ones we work to.
A single test typically lands between $3,400 and $16,500 excluding GST, depending on what is being tested and how large it is. The sections below explain what sits at each end of that range and what moves a quote up or down, so you can work out roughly where you will fall before you speak to anyone.
| Test type | Price range (ex GST) | Typical reason for testing |
|---|---|---|
| Basic website | $3,400 to $6,500 | Brochure or marketing site, WordPress, reputational risk |
| External network | $3,400 to $9,500 | Internet-facing exposure, cloud and Microsoft 365, remote access |
| Web application and API | $5,900 to $16,500 | SaaS platforms, customer portals, anything behind a login |
| Internal network | $5,900 to $16,500 | Active Directory, privilege escalation, insider threat simulation |
| Mobile application | $5,900 to $16,500 | iOS and Android apps, data storage, API endpoints |
| Custom and red team | Scoped individually | Wireless, hardware, red teaming, multi-element programmes |
All prices exclude GST. Every engagement is quoted at a fixed price, so the number on the proposal is the number you pay.
Penetration testing is priced on tester days, and tester days are driven by how much there is to test and how deep we have to go. Five things account for almost all the variation:
Whichever test you choose, the engagement includes:
Many Australian businesses need more than one test a year, either because a customer contract requires it, because they release software continuously, or because a compliance framework expects regular testing. Rather than quoting each test separately, we can build a twelve month testing programme sized to your environment and your budget, with the work scheduled across the year and the cost spread evenly.
This usually works out cheaper per test than booking them one at a time, and it means the testing calendar is already agreed when a customer asks for evidence.
If the scope turns out to be materially different from what was described, we tell you before we start, not after the invoice.
For most small and medium Australian businesses, between $3,400 and $16,500 excluding GST for a single test. A basic website test sits at the lower end. A large web application or an internal network test with Active Directory in scope sits at the upper end.
Usually because they are not quoting the same work. The three most common differences are the number of tester days, whether the testing is manual or largely automated, and whether a retest is included. Ask all three questions when you compare.
A very low quote generally means a short engagement, an automated scan, or both. That has a place, and a vulnerability scan is a reasonable thing to buy, but it should be bought knowingly. A scan finds known issues in known software. A penetration test finds the chain of small problems that a scanner cannot connect.
Most engagements run between three and ten working days of testing, with the report following shortly after. Scheduling is normally the longer lead time, so it is worth booking ahead of a customer deadline.
Annually at minimum, and after any significant change to the systems in scope. If you ship software regularly, or if you hold a certification that expects it, more often.
No. A retest after you have remediated is included in the price.
Tell us what you need tested and we will come back with a fixed price and a scope you can hold us to. If a penetration test is not the right thing to buy yet, we will say so.
Next step: Book 30 minutes with Peter for a no-obligation scoping conversation, or send us the details and we will quote it.