Penetration testing
Penetration testing services, from scope to retest
A specialist testing partner tries to break in under rules we agree with you, and we manage the engagement from scoping to report. Because we also run IT and security, we can fix what the test finds and arrange the retest.

- ISO27001 and 9001 certified ourselves, audited externally by Compass Assurance Services
- 150+Organisations protected by Austin SecureShield
- 300+Client organisations that trust us with their IT
- 15Years operating as a Perth based, Australian owned IT provider
Trusted by security conscious businesses across WA








01What we can test
Four places attackers try first
Most engagements cover one or two of these. We help you choose based on what a client, insurer or tender has asked for and where your real exposure sits.
External network
Your public addresses, firewalls, VPNs and anything else an attacker can reach from the internet.
Managed network servicesInternal network
What an attacker could reach after getting onto one laptop or plugging into the office network.
Network servicesWeb applications
Customer portals and web apps, tested for the common flaws attackers use to reach data or accounts.
Software developmentMicrosoft 365 and Azure
Tenant configuration, identity and sharing settings, where a single mistake can expose the whole business.
Managed Microsoft 365Want to test how staff respond to phishing? Simulations run through our security awareness training.
Security awareness training02Scan, test or audit
A pen test is not a vulnerability scan
The three are often confused, and they answer different questions. Most businesses need scanning all the time and a pen test at key moments.
| Compare | Vulnerability scanningAutomated, ongoing | Penetration testThis page | Cyber security auditReview of settings |
|---|---|---|---|
| What it does | Checks for known vulnerabilities and missing patches | A tester tries to exploit weaknesses and chain them together, as a real attacker would | Reviews settings, accounts, devices, backups and policies |
| How often | Continuously, with results reviewed and fixed | Point in time, for example yearly or after a major change | Once, then through quarterly reviews |
| Who runs it | Austin, using ConnectSecure | A specialist testing partner, managed by Austin | Austin |
| What you get | A running list of vulnerabilities and their fixes | Findings with evidence and severity, then fixes and a retest | An Essential Eight score and a plan in order of risk |
| How it is priced | Included in every SecureShield plan | Fixed quote after a scoping call. Not part of any plan | Starts with a scoping call |
Swipe the table sideways to compare all three.
Never had a security review? An audit first makes a pen test better value.
Cyber security audit03How it runs
One engagement, managed end to end
You deal with us from the first call to the retest. We manage the partner, the schedule and the report.
- Step 1
Scoping call and fixed quote
We agree what is tested, what is off limits and why the test is needed, then send a fixed quote.
- Step 2
Rules of engagement
Dates, test windows, contacts and a way to stop the test are agreed in writing before anything starts.
- Step 3
Testing
The specialist partner runs the test in the agreed window while our engineers stay on hand in case anything needs attention.
- Step 4
Report, fix and retest
We walk you through the findings in plain English, fix what is in our remit and arrange a retest to confirm the fixes hold.




Have a project in mind?
Send us the outline. A technical consultant will scope it with you and come back with a fixed price.
04Why a managed test
Findings that get fixed, not filed
A pen test report is only worth what happens next. This is where a managed engagement differs from hiring a tester on your own.
One accountable team
You have one contact for scoping, scheduling, questions and the report. We handle the testing partner for you.
No juggling providersFixed by the people who run your IT
Findings go straight to the engineers who look after your systems, so fixes are planned properly and nothing sits in a PDF.
Remediation quoted up frontChecking between tests
SecureShield vulnerability scanning keeps looking for new weaknesses after the test, so you are not waiting a year to find the next one.
Included in every plan05Is it a fit
When a pen test is the right call
We would rather point you to the right service than sell you a test you do not need yet.
A strong fit Penetration test
- +A client, insurer or tender asks for a penetration test report
- +You have launched a new portal, web app or remote access system
- +You have finished an Essential Eight uplift and want to know it holds
- +You have made a major change to your network or cloud setup
Probably another option We will say so
- ×You have never had a security review, so start with a cyber security audit
- ×You want continuous checking, which vulnerability scanning in SecureShield covers
- ×You know the basics such as MFA and patching are missing, so fix those first
06What you receive
A report for the board and the engineers
Directors need to know what the findings mean for the business. Engineers need enough detail to fix them.
Executive summary
What was tested, what was found and what it means for the business, in plain English you can share with a client or insurer.
Technical findings
Each finding with evidence, a severity rating and the steps to fix it, ranked so the worst problems are dealt with first.
Retest results
Confirmation of which findings are fixed after remediation, so you can show the gap is closed rather than just reported.
Related services and industries
07Recognised and certified
A top 50 MSP in Australia, three years running
Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.


ISO 27001
Information securityOur information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.
How we protect your data
ISO 9001
Quality managementSupport tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.
08Questions
Penetration testing questions
What people ask before they book a test. Anything else, call 1300 787 429.
01What is the difference between a vulnerability scan and a penetration test?
A scan is automated and looks for known weaknesses such as missing patches. A penetration test is done by a skilled tester who tries to exploit weaknesses and link them together to see how far an attacker could get. Scanning runs all the time on SecureShield. A pen test is a point in time engagement.
02How much does a penetration test cost?
It depends on what is tested and how deeply. You get a fixed quote after a scoping call, before any work starts. Penetration testing is not part of any SecureShield plan. It is a separate, one off engagement with no ongoing contract.
03Will testing disrupt our systems or staff?
Tests are planned to keep risk low: agreed windows, systems that are off limits, named contacts and a way to stop the test. Our engineers stay on hand while it runs. Staff only need to be involved if the scope includes phishing simulation.
04Who does the testing and are they CREST accredited?
Testing is delivered by a specialist testing partner and managed by Austin. CREST ANZ is a not for profit body that approves testing companies and certifies individual testers. If a client or tender requires CREST, tell us at the scoping call and we will confirm the credentials for your engagement.
05How often should we test?
Common triggers are a client or insurer requirement, a new system facing the internet or a major change to your network. Some contracts set a yearly test. Between tests, vulnerability scanning in SecureShield keeps checking for new weaknesses.
06Can you fix what the test finds?
Yes. We quote remediation after the report, fix what is in our remit and arrange a retest. If you have your own IT team or another provider, we can hand the findings to them instead.
09Penetration testing
Test it before
someone else does.
Get a fixed price pen test quote. Tell us what needs testing and why, and we will scope it, quote it and manage it through to the retest.