CREST Penetration Testing

Penetration Testing Australia CREST ANZ Approved Member Company

Cyber Forte is a CREST ANZ Approved Member Company providing independent penetration testing services across Australia. Our CREST-aligned security testing helps organisations identify exploitable vulnerabilities across web applications, networks, APIs, cloud environments, mobile applications and wireless infrastructure.

Our penetration testing team provides compliance-ready reporting, remediation guidance and re-testing to help organisations meet security and regulatory requirements including ISO 27001, PCI DSS, Essential Eight, SOC 2 and other assurance requirements.

crest
ISO 27001

Why Cyber Forte

CREST Certified

CREST ANZ approved, OSCP-certified testers

Manual Testing

Human-led testing finds what scanners miss

Free Re-test

Fixed findings re-tested at no extra cost

Clear Reports

Audit-ready reports with clear remediation

Get started today

Book a free consultation with our experts.

    TRUSTED BY

    Why Cyber forte

    What separates Cyber Forte from every other pen test company in Australia

    Verifiable credentials. Not marketing claims. Here’s what actually makes our penetration testing different.

    CREST ANZ Approved Member Company

    Cyber Forte is a CREST ANZ Approved Member Company, and our pen testers are CREST ANZ Accredited and OSCP-certified — the globally recognised standard for offensive security professionals in Australia and New Zealand. Multiple consultants also carry NV1/NV2 government security clearances for classified engagements.

    CREST ANZ Approved Member Company · CREST ANZ Accredited staff · Dept of Defence cleared team

    Human-led Penetration Testing — not automated scanning alone

    We never hand over a glorified Nessus scan. Every engagement involves skilled human testers who think like attackers, chain vulnerabilities, and uncover logic flaws that no automated tool can detect.

    Human-led methodology · Real-world attack simulation

    Free re-testing — included on every engagement

    Once you’ve remediated findings, we re-test at no additional charge and issue a clean report confirming all vulnerabilities have been resolved. Most competitors charge separately for this.

    Complimentary re-testing · Updated clean report provided

    Compliance-ready reports executives can read

    Our reports include an executive summary, technical findings with CVSS scores, business impact analysis, and prioritised remediation steps. Aligned to ISO 27001, PCI DSS, SOC 2, ISM, and NIST frameworks.

    CVSS scoring · Executive + technical sections · Cyber Forte is ISO 27001 certified

    ASX 50 & enterprise experience on every engagement

    Our consultants have worked with ANZ Bank, CPA Australia, Origin Energy, Australia Post and Accenture. That enterprise-grade rigour is applied to every client regardless of size.

    25+ years with ASX 50 clients

    Remediation support — not just a report and goodbye

    We hold a debrief call with your team to walk through every finding, explain severity in business terms, and guide remediation priorities. We’re available throughout remediation to answer technical questions.

    Debrief call included · Ongoing remediation Q&A support

    Team credentials​

    Client stories

    What our clients say

    "Cyber Forte has done Penetration Testing on our projects and the results are outstanding. They have found and helped fix critical security issues which other security companies were not able to find. Their attention to detail and the depth of manual testing genuinely sets them apart from every other firm we've used."

    David P. Information Security Manager, Financial Services

    "We've engaged Cyber Forte multiple times for penetration testing and they consistently deliver outstanding results. When a critical vulnerability was identified, they immediately paused testing to support urgent remediation , highlighting the value of their human-led approach. I highly recommend Cyber Forte for penetration testing, ISO 27001, NIST audits, and broader cyber security services."

    James R. APAC Cyber Security Presales Lead, Crayon

    "In a very short time after our engagement, Cyber Forte improved our security exposure, capability and maturity. During the process, Cyber Forte exceeded expectations on the professionalism, stakeholder engagement process, and deliverables. The board was genuinely impressed with how clearly the security journey was communicated."

    Michael B. CIO, Office Brands · Sydney

    "Cyber Forte is a result-oriented company which has helped us protect our business and achieve the certifications our clients require. I highly recommend them if you are looking at securing your business. They work as trusted advisors , not consultants who hand over a document and disappear."

    Sarah C. CEO, Paperchase Office National

    "Working with Cyber Forte on our ISO 27001 certification was a genuinely positive experience. They took the time to understand our specific goals and operational context. Their guidance was clear, practical, and tailored , helping us navigate the complexities of the standard with confidence. Thanks to their support, we achieved certification efficiently with a strong understanding of how to maintain compliance going forward."

    Gary K. CEO, Infocouncil · Melbourne

    "I cannot express enough how impressed I am with the managed security services provided by Cyber Forte. From the start they demonstrated a deep understanding of our unique business needs. The proactive approach in identifying and mitigating potential risks has been instrumental in safeguarding our company's digital assets. The level of expertise and attention to detail is truly commendable."

    James T. Managing Partner, Accounting Firm · Melbourne

    Transparent pricing

    How much does Penetration Testing cost in Australia?

    Below are indicative price ranges for our most requested test types. Pricing includes scoping, manual testing, executive + technical reporting, CVSS-rated findings, compliance mapping and complimentary re-testing, and is confirmed after a short scoping call.

    Web Application

    $3,500 – $10,000+

    Indicative range , final pricing depends on application size, complexity, user roles, authentication, APIs and testing requirements.

    Network (External)

    $5,000 – $10,000+

    Internet-facing infrastructure

    Most requested

    Cloud Assessment

    $4,500 – $12,000+

    AWS, Azure or GCP environment

    Red Team / Advanced

    $25,000 – $50,000+

    Full-scope adversary simulation

    Not sure which test you need?

    Tell us about your environment, we'll recommend the right scope and provide a fixed-price quote within 24 hours.

    OUR WORK

    Penetration Testing Case Studies

    Financial Services Penetration Testing

    Cyber Forte helped a leading financial services organisation uncover critical vulnerabilities through expert penetration testing, improving security posture and reducing cyber risk across its environment.

    Read More

    Healthcare Penetration Testing

    Helped a leading healthcare organisation strengthen its cybersecurity posture by identifying critical vulnerabilities through comprehensive penetration testing, improving resilience against evolving cyber threats.

    Read More

    SaaS Penetration Testing

    Strengthened application security for a leading SaaS provider by identifying critical vulnerabilities through expert penetration testing. Improved cyber resilience while helping protect customer data and meet enterprise security expectations.

    Read More

    Our methodology

    Six steps from scope to remediation verification

    A transparent, structured engagement where you know exactly what’s happening at every stage and who is doing it.

    1

    Day 1–2

    Scoping & consultation

    We meet with your team to understand your environment, technology stack, compliance requirements, and risk priorities. We define precise scope boundaries, agree on testing windows to minimise disruption, and produce a signed Rules of Engagement document before any testing begins.

    Deliverable: Signed scope document + Rules of Engagement

    2

    Day 2-3

    Planning & reconnaissance

    We map your attack surface using OSINT, passive reconnaissance, and infrastructure enumeration , identifying domains, IPs, technologies, third-party integrations, and potential entry points before active testing begins. This stage often surfaces forgotten assets your team didn’t know were exposed.

    Deliverable: Attack surface map + asset inventory

    3

    Day 3-8 (varies by scope)

    Active testing & exploitation

    CREST ANZ Accredited and OSCP-certified testers simulate real-world attacks using manual techniques combined with industry-leading tools. We chain vulnerabilities as a real attacker would, not just flag individual issues in isolation. Critical findings are reported to you immediately rather than waiting for the final report.

    Deliverable: Real-time critical alerts during testing

    4

    Day 2-3 after testing

    Reporting

    We produce a dual-audience report: an executive summary with business risk context and a detailed technical section with every finding, CVSS score, proof of concept, and step-by-step remediation guidance. All findings are mapped to relevant compliance frameworks (ISO 27001, PCI DSS, SOC 2, ISM, NIST) so your compliance team can use the report directly.

    Deliverable: Executive + technical report with CVSS ratings

    5

    Within 48h of report delivery

    Debrief & remediation guidance

    We hold a structured debrief call with your technical and business stakeholders , walking through every finding, explaining severity in plain language, and prioritising what to fix first based on exploitability and business impact. We’re available throughout your remediation period to answer technical questions.

    Deliverable: Remediation priority matrix + ongoing Q&A support

    6

    After your remediation

    Re-testing & clean report

    Once you’ve remediated the findings, we re-test every vulnerability at no additional cost and issue an updated clean report confirming all issues have been resolved. This clean report is what your auditors, clients, and compliance teams need , and most competitors charge separately for it.

    Deliverable: Clean re-test report (included at no extra cost)

    Testing types

    Penetration testing specialisations

    Web application pen testing

    OWASP Top 10 and beyond , SQL injection, XSS, CSRF, IDOR, authentication bypass, business logic flaws. For customer-facing apps, internal portals, and SaaS platforms.

    ⏱ 3–5 days

    External network pen testing

    Simulate an outside attacker targeting your internet-facing infrastructure, firewalls, VPNs, exposed services, DNS misconfigurations, and perimeter defences.

    ⏱ 5–10 days

    Internal network pen testing

    Test what an attacker can reach once inside , lateral movement, privilege escalation, Active Directory attacks, credential harvesting, and data exfiltration paths.

    ⏱ 5–8 days

    Cloud pen testing

    AWS, Azure, and GCP security assessments , IAM misconfigurations, S3/blob exposure, container escapes, serverless function vulnerabilities, and cloud-native attack paths.

    ⏱ 4–7 days

    API pen testing

    REST, GraphQL, SOAP , broken object-level authorisation, mass assignment, injection, rate-limiting failures, and API-specific logic flaws often missed by web app scans.

    ⏱ 3–6 days

    Mobile app pen testing

    iOS and Android assessment using OWASP MASVS , insecure data storage, certificate pinning bypass, reverse engineering, deeplink exploitation, and backend API testing.

    ⏱ 4–7 days

    Firewall pen testing

    Independent evaluation of your firewall ruleset , identifying overly permissive rules, bypass opportunities, misconfigurations, and gaps between documented and actual policy.

    ⏱ 2–4 days

    Wireless pen testing

    Assess your Wi-Fi infrastructure , WPA2/3 cracking attempts, rogue access point detection, guest network isolation, evil twin attacks, and RADIUS server hardening.

    ⏱ 2–3 days

    CREST ANZ

    CREST ANZ Approved Penetration Testing Company

    CREST ANZ is the independent, not-for-profit accreditation body for the offensive security industry across Australia and New Zealand. It sets the standards that member companies and individual testers must meet , covering methodology, technical competence, quality assurance, data handling and professional conduct.

    Cyber Forte is a CREST ANZ Approved Member Company. This means our organisation, not just individual staff , has been independently assessed against CREST ANZ’s standards for delivering penetration testing services. Our testers are separately CREST ANZ Accredited, meaning their technical skills have been examined and verified against the same industry benchmark.

    For customers, this combination matters because it removes the guesswork from vendor selection: engagements follow a consistent, auditable methodology; findings are technically verified rather than self-reported; and reporting is held to a standard recognised by regulators, auditors, insurers and government agencies.

    Why choose a CREST ANZ Approved Member Company?

    Independent security testing

    Testing performed independently of your development and IT teams.

    Experienced security testers

    Testing conducted by appropriately qualified and accredited professionals.

    Transparent, fixed-price scoping

    Every engagement is scoped and quoted up front, no surprise costs once testing begins.

    Compliance-ready reporting

    Reports designed to provide clear technical findings, business risk and remediation guidance.

    Retesting included

    Confirm that identified vulnerabilities have been addressed, at no extra cost.

    Security + compliance expertise

    Penetration testing integrated with ISO 27001, Essential Eight, PCI DSS, SOC 2 and broader security programs.

    Ready to book your penetration test?

    Tell us about your environment , we'll recommend the right scope and provide a fixed-price quote within 24 hours.

    Every engagement

    What's included in every penetration test

    Regardless of test type or budget, every Cyber Forte engagement is delivered to the same standard and includes the same core deliverables.

    Executive summary

    Business-language overview for boards and executives , no technical jargon required.

    Technical findings

    Full technical detail on every vulnerability identified during testing.

    Proof of concept

    Evidence demonstrating how each finding was exploited, not just theorised.

    CVSS scoring

    Findings rated Critical / High / Medium / Low / Informational using CVSS v3.1 and v4.0.

    Business impact

    What each finding actually means for your organisation, in risk and cost terms.

    Remediation guidance

    Prioritised, step-by-step guidance your team can act on immediately.

    Free re-testing

    We re-test remediated findings at no extra cost to confirm they’re resolved.

    Attestation & compliance evidence

    A Letter of Attestation and framework-mapped reporting for audits, insurers and procurement.

    Testing methodology

    Black-box, grey-box or white-box?

    The right methodology depends on what you’re trying to simulate and how much your budget covers. We recommend the approach that matches your actual threat profile.

    01

    Black-box testing

    Testers have zero prior knowledge of the target , simulating a real external attacker with no inside information. Maximum realism. Tests what an opportunistic attacker would find.

    External attacker simulation

    02

    Grey-box testing

    Testers receive limited credentials (e.g. a regular user account) , simulating a malicious insider or an attacker who has already gained initial access. Best value for most organisations.

    Insider threat simulation

    03

    White-box testing

    Full access to source code, architecture diagrams, and credentials , the most thorough approach. Finds deeply embedded vulnerabilities in high-assurance environments.

    Maximum coverage

    Compliance frameworks

    Pen testing evidence for every major framework

    Our reports are structured to satisfy auditor requirements across all major compliance frameworks. One engagement, multiple compliance needs covered.

    ISO 27001

    Required as part of ISMS. Our report maps findings to Annex A controls and satisfies certification auditor requirements.

    PCI DSS

    Req 11.4 mandates annual pen testing. We provide the segmentation testing and network-layer assessment PCI QSAs need.

    SOC 2 Type II

    Auditors expect pen testing evidence. Our reports align to CC6 and CC7 trust service criteria used in SOC 2 assessments.

    Essential Eight

    ML2/ML3 assessment requires testing evidence. Our network and application reports satisfy ACSC Essential Eight evidence requirements.

    NIST CSF

    Findings mapped to Identify, Protect, Detect, Respond functions. Used by organisations aligning to the NIST Cybersecurity Framework.

    APRA CPS 234

    Required for Australian financial institutions. Our reports satisfy APRA’s expectations for testing of information assets.

    business benefits

    Why Penetration Testing matters for your business

    Win more enterprise and government deals

    Security questionnaires and tenders increasingly ask for a recent, independent penetration test. A report and Letter of Attestation from a CREST ANZ Approved Member Company helps you get through procurement checks faster.

    Strengthen your cyber insurance position

    Insurers now ask for evidence of regular security testing at application and renewal. A current pen test report shows your risks are known, managed and independently verified.

    Find weaknesses before attackers do

    Manual testing finds chained vulnerabilities, logic flaws and forgotten assets that automated scanners miss. You learn how an attacker would get in while you still have time to close the gap.

    Meet compliance and regulatory obligations

    ISO 27001, PCI DSS, SOC 2, Essential Eight and APRA CPS 234 all expect evidence of technical testing. Framework-mapped reporting also supports your obligation under the Privacy Act to take reasonable steps to protect personal information.

    Protect customer trust and reputation

    Customers and partners want proof that their data is safe with you. Independent testing gives you that proof, backed by real exploitation evidence rather than a self-assessment.

    Spend your security budget where it counts

    Every finding is risk-rated and prioritised by business impact. Your team fixes what matters most first, instead of guessing where to invest.

    Answers

    Frequently asked questions

    Indicative pricing: web application testing $3,500–$10,000+, external network testing $5,000–$10,000+, cloud assessments $4,500–$12,000+, and red team engagements $25,000–$50,000+. See the full pricing table for API, internal network, mobile and wireless ranges. Final price depends on scope, number of targets and complexity, confirmed after a scoping call. Contact us for a tailored quote within 24 hours.

    Timeline by type: Web app testing 3–5 business days. External network 5–10 days. Internal network 5–8 days. Cloud assessment 4–7 days. API testing 3–6 days. Red team 2–4 weeks. These are testing durations only , add 2–3 days for report production and 48 hours for debrief scheduling. Testing windows can often be run outside business hours to minimise disruption.

    Black-box: testers start with zero knowledge , simulating a real external attacker. Most realistic, but may miss internal vulnerabilities. Grey-box: limited access provided (e.g. a user account) , simulates a malicious insider or compromised user. Best value for most organisations. White-box: full access to source code, architecture, and credentials , maximum coverage, highest cost. Required for PCI DSS Level 1 and high-assurance environments.

    Most organisations test at least annually. Additional testing is recommended after major system deployments, significant infrastructure changes, a security incident, mergers or acquisitions, or when new regulatory requirements apply. PCI DSS requires annual testing and after significant changes. ISO 27001 requires regular testing as part of the ISMS. Organisations handling sensitive government data often test quarterly.

    It depends on the test type. For black-box external testing we only need the target IP ranges or domains , no credentials. For grey-box testing we need test user accounts with the appropriate permission level. For white-box testing we need architecture documentation, source code access, and administrator credentials. We never require production admin access , testing can be performed against staging environments when required. All access is governed by the Rules of Engagement document signed before testing begins.

    Penetration testing can support security assurance and compliance activities across frameworks including PCI DSS, ISO 27001, Essential Eight, SOC 2 and APRA-regulated environments. Specific testing frequency and scope depend on the applicable requirements, your risk profile and the systems being assessed. Cyber Forte is itself ISO 27001 certified and a CREST ANZ Approved Member Company, and our reports are structured to support your evidence trail across these frameworks.

    ISO 27001 requires evidence of regular, competent penetration testing as part of your ISMS (typically under Annex A controls covering technical vulnerability management), but it does not mandate that testing must be CREST-certified specifically. That said, testing performed by a CREST ANZ Approved Member Company is well-regarded by auditors because the methodology, tester competence, and reporting standard are independently verified rather than self-declared , which tends to streamline the audit conversation.

    Cyber Forte provides web application, external and internal network, cloud, API, mobile application, firewall, wireless, and red team penetration testing , all delivered by our CREST ANZ Accredited and OSCP-certified testers.

    Every report includes an executive summary (business-language overview), technical findings with full proof of concept, CVSS v3.1 severity ratings, business impact analysis, prioritised step-by-step remediation guidance, and compliance framework mapping (ISO 27001, PCI DSS, SOC 2, NIST, ISM). We also issue a Letter of Attestation confirming engagement scope and outcomes , accepted as evidence for cyber insurance, procurement and tender submissions, and compliance audits.

    We design testing windows to minimise disruption , most organisations schedule testing during off-peak hours or weekends for production systems. We never conduct destructive testing without explicit written approval. For highly sensitive systems we can test against a staging/UAT environment. Our Rules of Engagement document defines exactly what we will and won't do before testing begins.

    Three verifiable differences: (1) CREST ANZ Approved Member Company with CREST ANZ Accredited and NV1/NV2-cleared staff , fewer than 5% of Australian pen test firms hold this combination. (2) Free re-testing included , most competitors charge $1,500–$5,000 separately for this. (3) 25+ years with ASX 50 clients (ANZ Bank, CPA Australia, Origin Energy, Australia Post) , that enterprise rigour applies to every engagement regardless of your size.

    Yes , and significantly. Cyber insurers increasingly require evidence of penetration testing as a condition of coverage, and organisations with recent clean pen test reports typically receive 15–30% lower premiums. Our reports are structured to satisfy cyber insurance underwriter requirements, and we can provide a letter confirming engagement scope and findings for your insurer on request.

    CREST penetration testing is security testing delivered by companies and testers accredited by CREST, an independent, not-for-profit body that sets technical and quality standards for the offensive security industry. In Australia and New Zealand, this is administered by CREST ANZ. An Approved Member Company has had its methodology, quality assurance, data handling and professional conduct independently assessed at the organisation level. Combined with individually accredited testers, this gives you assurance at both the company and tester level, which regulators, auditors, cyber insurers and government agencies increasingly expect when reviewing a vendor.

    Yes. Cyber Forte is a CREST ANZ Approved Member Company, listed in the official CREST ANZ directory. Our penetration testers are CREST ANZ Accredited and OSCP-certified, and multiple consultants hold NV1/NV2 government security clearances for classified and government engagements. Our accreditation doesn't add an automatic price premium: pricing depends on scope, number of targets and complexity. See the pricing table above or contact us for a fixed-price quote within 24 hours.

    Find your vulnerabilities before attackers do.

    Get a same-day, fixed-price penetration testing quote from a CREST ANZ Approved Member Company. CREST ANZ Accredited & OSCP-certified testers. Compliance-ready reports. Free re-testing included. No lock-in.

    CREST ANZ Approved Member Company  · Fixed-price quote within 24h  · CREST ANZ Accredited & OSCP certified  ·  Free re-testing  · Compliance-ready reports

    Our locations

    Penetration testing across all of Australia

    On-site and remote pen testing engagements available across every Australian state, territory, and New Zealand.

    You may also need

    Services that pair well with pen testing

    Many organisations combine pen testing with compliance services in a coordinated engagement , maximising shared evidence and reducing total cost.

    Best all-round

    ISO 27001 certification

    ISO 27001 requires pen testing as evidence for your ISMS. Our pen test report feeds directly into your certification audit , reducing duplication and cost when run together.

    Choose it when

    You want globally recognised proof of security that reassures customers, regulators and insurers alike.

    Australian baseline

    Essential Eight

    The ACSC’s eight mitigation strategies with maturity levels, widely used across Australian government supply chains.

    Choose it when

    You work with government or want a practical local security baseline.

    US & SaaS focus

    SOC 2

    An attestation report against trust service criteria, common for technology firms selling into the United States.

    Choose it when

    Your buyers, often American, specifically ask for a SOC 2 report.