ServicesAssessment · advisory · evidence

Penetration Testing Services for Corporate & Government

Independent penetration testing for corporate and government in Australia — external, internal/on-site, web application and cloud testing, OWASP-aligned, with board-ready reporting and remediation retesting.

What we test

External / remote penetration testing

Your internet-facing infrastructure, perimeter, VPNs, email and exposed services — tested the way a real attacker would from outside your network.

Internal / on-site penetration testing

We come on-site and test from the inside: lateral movement, privilege escalation, network segmentation, Active Directory and what a breached device or insider could reach.

Web & software application testing

Web applications, APIs and custom software tested against the OWASP Top 10 and beyond — authentication, access control, injection and business-logic flaws.

Cloud & Microsoft 365

Misconfiguration, identity and data-exposure testing across Azure, AWS and Microsoft 365 — where much real-world exposure now lives.

Wireless & physical

Wi-Fi, long-range links and physical access controls — the layers a remote scan never sees.

Social engineering & phishing

Authorised, controlled testing of the human layer — the route attackers use most.

Specialised testing: Web application · Network & infrastructure · Cloud penetration testing.

How we work — and what you get

Every engagement follows a recognised methodology (OWASP, PTES and NIST), is scoped with you in writing up front, and is run by senior testers — not a scanner left running overnight.

  • Scoping — agreed targets, rules of engagement and timing, documented before we start.
  • Manual and automated testing — tools find the obvious; our people find the rest.
  • A board-ready report — a plain-English risk summary for leadership, plus full technical detail and reproduction steps for your engineers.
  • Prioritised remediation — findings ranked by real business risk, with practical fixes.
  • Remediation retest — we re-test fixed findings so you can prove to auditors and insurers they are closed.

Built for corporate and government

Penetration testing is now an expectation, not an extra. Regular testing is required or assumed by PCI DSS, ISO 27001, SOC 2, the ASD Essential Eight and most cyber insurers and enterprise customers. We deliver evidence that stands up to all of them — and we speak both languages: the board’s and the engineer’s.

Our government and council work draws on decades of building and securing government IT systems first-hand — networks, firewalls and infrastructure designed and built from the ground up — with a team drawn from military, government and cyber security backgrounds.

Penetration testing for compliance

Most frameworks now require or assume regular penetration testing. We scope and report each engagement to satisfy the standard you answer to.

Essential Eight

Testing that evidences your maturity against the ASD Essential Eight — the baseline for government and council.

ISO 27001

Independent security testing for your ISMS, mapped to Annex A controls for certification and surveillance audits.

PCI DSS

Annual and change-driven external and internal testing to meet PCI DSS requirement 11.

SOC 2

Penetration-testing evidence for your SOC 2 trust services criteria and customer security reviews.

Penetration testing packages

Run any engagement as a one-off, or on a recurring schedule that matches your rate of change and compliance obligations — weekly, fortnightly, monthly or quarterly.

External Scan

A focused external and perimeter penetration test of your internet-facing systems, OWASP-aligned, with a prioritised report. The fastest way to see your real exposure. Request a quote.

On-Site Penetration Test

Our testers on-site, assessing your internal network end to end — lateral movement, privilege escalation, segmentation and Active Directory — with a full report and remediation retest. Request a quote.

Recurring Testing Program

Ongoing testing on the cadence your risk demands — weekly, fortnightly, monthly or quarterly — combining regular scanning with deeper periodic tests, so new exposure is caught as it appears, not once a year. Recurring engagement.

Enterprise & Government — POA

A full-scope program across network, applications, cloud, wireless and social engineering, scoped to your environment and obligations, with executive and technical reporting. Price on application.

Book a Scoping Call   Request a Quote

Testing you can trust

Authorised & scoped

Every engagement runs to a written scope and agreed rules of engagement — nothing is touched without your sign-off.

Production-safe

We test carefully and time it to avoid disruption — no denial-of-service, no destructive testing.

Strictly confidential

Your systems, findings and reports are handled under strict confidentiality and NDA.

Evidence you can use

Clear proof, reproduction steps and a remediation retest — the evidence your auditors and insurers ask for.

Why CISO Advisory

Independent, senior and hands-on — backed by 30+ years building and securing government and enterprise systems. Every test is run by experienced people, reported in business terms, and tied to the standards that matter to your board, your auditors and your insurers.

Independent

We are not selling you the products we test. Findings have no agenda but your security.

Senior testers

Real people with deep experience — not an automated scan with a logo on it.

Methodology-driven

OWASP, PTES and NIST, aligned to the Essential Eight and your compliance obligations.

Reporting you can act on

Board-ready risk summary, full technical detail, prioritised fixes and a retest.

Frequently asked questions

What is penetration testing?
A controlled, authorised simulated attack on your systems by security professionals, to find and safely exploit weaknesses before a real attacker does — then report them with practical fixes.

How is a penetration test different from a vulnerability scan?
A scan is automated and lists potential issues. A penetration test adds skilled humans who validate, chain and exploit those issues to show real, demonstrated risk — and rule out the false alarms.

Do you test web applications and APIs?
Yes — web apps, APIs and custom software, tested against the OWASP Top 10 and the business-logic flaws scanners miss.

Do you offer on-site testing?
Yes. We perform both remote/external testing and on-site internal testing across Australia.

How often should we test?
At least annually, after significant change, and as required by PCI DSS, ISO 27001, SOC 2 and the Essential Eight. Many clients move to monthly or quarterly continuous testing.

Will testing disrupt our systems?
No — engagements are carefully scoped with agreed rules of engagement and timing to avoid impact on production.

Do you re-test after we fix the issues?
Yes — we re-test remediated findings so you have evidence they are genuinely closed.

Do you work with government?
Yes — government and councils are a core focus, backed by decades of direct government IT and security experience.

Know exactly what an attacker would find

Whether you need a one-off test, ongoing monthly assurance or a full enterprise and government program, we will scope it with you and show you precisely where you stand.

Book a Scoping Call    Request a Quote

Indicative pricing — transparent & fixed-fee
Penetration testing from $7,500

Web-application test with retest and attestation letter. Combined test plus social engineering from $12,000. Final fee confirmed in writing after a short scoping call — no hourly billing.

Indicative pricing — transparent & fixed-fee
Penetration testfrom $7,500

Authorised testing with verified, exploitable findings, retest and an attestation letter for customers and auditors. Final fee confirmed after a short scoping call.

Talk to a senior advisor — confidential, no obligation.

We respond the same business day, Australia-wide. Tell us what you need to secure.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act