Home › Services › Penetration Testing
Penetration Testing for Melbourne Businesses
Find out how an attacker would get in before one does - and, unlike most pentest engagements, actually get the findings fixed. Scoped, tested and remediated by the same senior engineer, so nothing is lost in handover.
A Pentest Is Not a Vulnerability Scan
A vulnerability scan is software producing a list. A penetration test is a skilled human trying to break in - chaining small weaknesses together, testing what your staff will click, seeing how far one compromised password actually reaches. It answers the question a scan never can: what would really happen?
Melbourne businesses mostly meet pentesting the same way: a tender, a larger client's security schedule, or a cyber insurance renewal suddenly demands one. At that point most providers will happily sell you a test. The gap in the market is what happens after - a 40-page PDF of findings that nobody translates and nobody fixes.
That's the part we exist for. The engagement is scoped, tested and remediated by the same senior engineer - no handover between a testing firm and whoever is supposed to act on the report. You get a prioritised fix plan in plain English, the fixes actually implemented, and a retest to prove the holes are closed.
How an Engagement Runs
One local point of contact from scoping to retest.
Scope
What gets tested and why: external footprint, internal network, a web application, or staff phishing resilience. Driven by what your tender, client or insurer actually requires - not by what is easiest to sell. Fixed price agreed before anything starts.
Test
Testing runs under signed rules of engagement - agreed windows, in-scope systems, emergency stop contact. Production-safe methods by default, performed personally by our senior engineer.
Translate
You get the full technical report and a plain-English version: what was found, what it means for your business, and what order to fix it in. Suitable to hand straight to a client, insurer or tender panel.
Fix & Retest
Remediation quoted fixed-scope or at $180/hr ex GST - your call. Then a retest on the fixed findings, so the closing evidence exists in writing.
What Can Be Tested
Scoped to the risk that matters for your business, not a fixed menu.
| Engagement | The question it answers | Typical trigger |
|---|---|---|
| External penetration test | What can an attacker on the internet reach and exploit? | Insurers, tenders, general assurance - the most common starting point |
| Internal network test | If one machine or account is compromised, how far does it spread? | Businesses with servers, multiple sites or sensitive internal data |
| Web application test | Can your customer-facing app or portal be abused - data exposed, logins bypassed? | Anything you have built or commissioned that holds customer data |
| Phishing simulation | What do your staff click, and what happens when they do? | Cheapest test, most confronting results - pairs with staff training |
When you should NOT buy a pentest yet
If MFA isn't enforced, backups have never been restored, and patching is ad-hoc, a penetration test will simply document what everyone already suspects - expensively. The report will say: fix the basics.
In that situation an Essential Eight uplift delivers far more security per dollar, and the pentest comes afterwards as independent proof the uplift worked. Start with the free 3-minute self-assessment if you're not sure which side of that line you're on - we'd rather tell you to spend less.
Penetration Testing Questions, Answered
What Melbourne businesses ask when a tender or insurer first demands a pentest.
How much does a penetration test cost in Melbourne?
It depends entirely on scope - an external test of a small footprint is a very different job from testing a web application or an internal network. Every engagement is quoted as a fixed price before work starts, after a short scoping conversation. Remediation of findings is then either fixed-scope or $180/hr ex GST, your choice.
What is the difference between a penetration test and a vulnerability scan?
A vulnerability scan is automated software listing known weaknesses - cheap, fast, and full of noise. A penetration test is a skilled human actively trying to chain those weaknesses together to actually get in, the way a real attacker would. If a quote seems too cheap for a pentest, you are probably being sold a scan with a report template.
Who actually performs the testing?
Aaron Waltman, Support Melbourne\u2019s founder and senior engineer, performs the testing personally - the same CSDF-certified engineer who scopes the engagement, writes the plain-English report and implements the fixes. One person accountable for the whole cycle means nothing is lost between a testing firm\u2019s PDF and your actual systems.
When does a business actually need a penetration test?
The honest triggers: a tender, client contract or insurer explicitly asks for one; you handle data where a breach would be reportable; you have built or commissioned a customer-facing application; or you have finished a security uplift and want independent proof it works. If none of those apply and the basics are not yet in place, an Essential Eight uplift almost always delivers more security per dollar - and we will tell you so.
Will testing disrupt our business?
Testing is run under a signed scope with agreed time windows and rules of engagement - what is in scope, what is out, when testing happens, and an emergency stop contact. Production-safe methods are standard; anything potentially disruptive is scheduled outside business hours or against test systems.
How often should we test?
Annually is the common benchmark for businesses with a compliance driver, plus a retest after any major change - new application, migration, restructure of the network. For most Melbourne SMBs without a contractual driver, testing once and fixing what it finds beats testing often and fixing nothing.
Related Services
The pieces that usually sit alongside this work.
Been asked for a pentest?
Send us the tender clause, the insurer question or the client email that triggered this. We'll tell you what scope actually satisfies it - and quote that, not more.
Support Perth IT Pty Ltd · Melbourne, Victoria · $180/hr ex GST, one-hour minimum, then 30-minute increments · No call-out fee in metro Melbourne.