CREST Penetration Testing
Cyber Forte is a CREST ANZ Approved Member Company providing independent penetration testing services across Australia. Our CREST-aligned security testing helps organisations identify exploitable vulnerabilities across web applications, networks, APIs, cloud environments, mobile applications and wireless infrastructure.
Our penetration testing team provides compliance-ready reporting, remediation guidance and re-testing to help organisations meet security and regulatory requirements including ISO 27001, PCI DSS, Essential Eight, SOC 2 and other assurance requirements.
Why Cyber Forte
CREST Certified
CREST ANZ approved, OSCP-certified testers
Manual Testing
Human-led testing finds what scanners miss
Free Re-test
Fixed findings re-tested at no extra cost
Clear Reports
Audit-ready reports with clear remediation
Get started today
Book a free consultation with our experts.



























Why Cyber forte
Verifiable credentials. Not marketing claims. Here’s what actually makes our penetration testing different.
Cyber Forte is a CREST ANZ Approved Member Company, and our pen testers are CREST ANZ Accredited and OSCP-certified — the globally recognised standard for offensive security professionals in Australia and New Zealand. Multiple consultants also carry NV1/NV2 government security clearances for classified engagements.
CREST ANZ Approved Member Company · CREST ANZ Accredited staff · Dept of Defence cleared team
We never hand over a glorified Nessus scan. Every engagement involves skilled human testers who think like attackers, chain vulnerabilities, and uncover logic flaws that no automated tool can detect.
Human-led methodology · Real-world attack simulation
Once you’ve remediated findings, we re-test at no additional charge and issue a clean report confirming all vulnerabilities have been resolved. Most competitors charge separately for this.
Complimentary re-testing · Updated clean report provided
Our reports include an executive summary, technical findings with CVSS scores, business impact analysis, and prioritised remediation steps. Aligned to ISO 27001, PCI DSS, SOC 2, ISM, and NIST frameworks.
CVSS scoring · Executive + technical sections · Cyber Forte is ISO 27001 certified
Our consultants have worked with ANZ Bank, CPA Australia, Origin Energy, Australia Post and Accenture. That enterprise-grade rigour is applied to every client regardless of size.
25+ years with ASX 50 clients
We hold a debrief call with your team to walk through every finding, explain severity in business terms, and guide remediation priorities. We’re available throughout remediation to answer technical questions.
Debrief call included · Ongoing remediation Q&A support
Client stories
"Cyber Forte has done Penetration Testing on our projects and the results are outstanding. They have found and helped fix critical security issues which other security companies were not able to find. Their attention to detail and the depth of manual testing genuinely sets them apart from every other firm we've used."
"We've engaged Cyber Forte multiple times for penetration testing and they consistently deliver outstanding results. When a critical vulnerability was identified, they immediately paused testing to support urgent remediation , highlighting the value of their human-led approach. I highly recommend Cyber Forte for penetration testing, ISO 27001, NIST audits, and broader cyber security services."
"In a very short time after our engagement, Cyber Forte improved our security exposure, capability and maturity. During the process, Cyber Forte exceeded expectations on the professionalism, stakeholder engagement process, and deliverables. The board was genuinely impressed with how clearly the security journey was communicated."
"Cyber Forte is a result-oriented company which has helped us protect our business and achieve the certifications our clients require. I highly recommend them if you are looking at securing your business. They work as trusted advisors , not consultants who hand over a document and disappear."
"Working with Cyber Forte on our ISO 27001 certification was a genuinely positive experience. They took the time to understand our specific goals and operational context. Their guidance was clear, practical, and tailored , helping us navigate the complexities of the standard with confidence. Thanks to their support, we achieved certification efficiently with a strong understanding of how to maintain compliance going forward."
"I cannot express enough how impressed I am with the managed security services provided by Cyber Forte. From the start they demonstrated a deep understanding of our unique business needs. The proactive approach in identifying and mitigating potential risks has been instrumental in safeguarding our company's digital assets. The level of expertise and attention to detail is truly commendable."
Transparent pricing
Below are indicative price ranges for our most requested test types. Pricing includes scoping, manual testing, executive + technical reporting, CVSS-rated findings, compliance mapping and complimentary re-testing, and is confirmed after a short scoping call.
Web Application
Indicative range , final pricing depends on application size, complexity, user roles, authentication, APIs and testing requirements.
Network (External)
Internet-facing infrastructure
Most requested
Cloud Assessment
AWS, Azure or GCP environment
Red Team / Advanced
Full-scope adversary simulation
Tell us about your environment, we'll recommend the right scope and provide a fixed-price quote within 24 hours.
OUR WORK
Cyber Forte helped a leading financial services organisation uncover critical vulnerabilities through expert penetration testing, improving security posture and reducing cyber risk across its environment.
Helped a leading healthcare organisation strengthen its cybersecurity posture by identifying critical vulnerabilities through comprehensive penetration testing, improving resilience against evolving cyber threats.
Strengthened application security for a leading SaaS provider by identifying critical vulnerabilities through expert penetration testing. Improved cyber resilience while helping protect customer data and meet enterprise security expectations.
Our methodology
A transparent, structured engagement where you know exactly what’s happening at every stage and who is doing it.
1
Day 1–2
We meet with your team to understand your environment, technology stack, compliance requirements, and risk priorities. We define precise scope boundaries, agree on testing windows to minimise disruption, and produce a signed Rules of Engagement document before any testing begins.
Deliverable: Signed scope document + Rules of Engagement
2
Day 2-3
We map your attack surface using OSINT, passive reconnaissance, and infrastructure enumeration , identifying domains, IPs, technologies, third-party integrations, and potential entry points before active testing begins. This stage often surfaces forgotten assets your team didn’t know were exposed.
Deliverable: Attack surface map + asset inventory
3
Day 3-8 (varies by scope)
CREST ANZ Accredited and OSCP-certified testers simulate real-world attacks using manual techniques combined with industry-leading tools. We chain vulnerabilities as a real attacker would, not just flag individual issues in isolation. Critical findings are reported to you immediately rather than waiting for the final report.
Deliverable: Real-time critical alerts during testing
4
Day 2-3 after testing
We produce a dual-audience report: an executive summary with business risk context and a detailed technical section with every finding, CVSS score, proof of concept, and step-by-step remediation guidance. All findings are mapped to relevant compliance frameworks (ISO 27001, PCI DSS, SOC 2, ISM, NIST) so your compliance team can use the report directly.
Deliverable: Executive + technical report with CVSS ratings
5
Within 48h of report delivery
We hold a structured debrief call with your technical and business stakeholders , walking through every finding, explaining severity in plain language, and prioritising what to fix first based on exploitability and business impact. We’re available throughout your remediation period to answer technical questions.
Deliverable: Remediation priority matrix + ongoing Q&A support
6
After your remediation
Once you’ve remediated the findings, we re-test every vulnerability at no additional cost and issue an updated clean report confirming all issues have been resolved. This clean report is what your auditors, clients, and compliance teams need , and most competitors charge separately for it.
Deliverable: Clean re-test report (included at no extra cost)
Testing types
OWASP Top 10 and beyond , SQL injection, XSS, CSRF, IDOR, authentication bypass, business logic flaws. For customer-facing apps, internal portals, and SaaS platforms.
⏱ 3–5 days
Simulate an outside attacker targeting your internet-facing infrastructure, firewalls, VPNs, exposed services, DNS misconfigurations, and perimeter defences.
⏱ 5–10 days
Test what an attacker can reach once inside , lateral movement, privilege escalation, Active Directory attacks, credential harvesting, and data exfiltration paths.
⏱ 5–8 days
AWS, Azure, and GCP security assessments , IAM misconfigurations, S3/blob exposure, container escapes, serverless function vulnerabilities, and cloud-native attack paths.
⏱ 4–7 days
REST, GraphQL, SOAP , broken object-level authorisation, mass assignment, injection, rate-limiting failures, and API-specific logic flaws often missed by web app scans.
⏱ 3–6 days
iOS and Android assessment using OWASP MASVS , insecure data storage, certificate pinning bypass, reverse engineering, deeplink exploitation, and backend API testing.
⏱ 4–7 days
Independent evaluation of your firewall ruleset , identifying overly permissive rules, bypass opportunities, misconfigurations, and gaps between documented and actual policy.
⏱ 2–4 days
Assess your Wi-Fi infrastructure , WPA2/3 cracking attempts, rogue access point detection, guest network isolation, evil twin attacks, and RADIUS server hardening.
⏱ 2–3 days
CREST ANZ
CREST ANZ is the independent, not-for-profit accreditation body for the offensive security industry across Australia and New Zealand. It sets the standards that member companies and individual testers must meet , covering methodology, technical competence, quality assurance, data handling and professional conduct.
Cyber Forte is a CREST ANZ Approved Member Company. This means our organisation, not just individual staff , has been independently assessed against CREST ANZ’s standards for delivering penetration testing services. Our testers are separately CREST ANZ Accredited, meaning their technical skills have been examined and verified against the same industry benchmark.
For customers, this combination matters because it removes the guesswork from vendor selection: engagements follow a consistent, auditable methodology; findings are technically verified rather than self-reported; and reporting is held to a standard recognised by regulators, auditors, insurers and government agencies.
Testing performed independently of your development and IT teams.
Testing conducted by appropriately qualified and accredited professionals.
Every engagement is scoped and quoted up front, no surprise costs once testing begins.
Reports designed to provide clear technical findings, business risk and remediation guidance.
Confirm that identified vulnerabilities have been addressed, at no extra cost.
Penetration testing integrated with ISO 27001, Essential Eight, PCI DSS, SOC 2 and broader security programs.
Tell us about your environment , we'll recommend the right scope and provide a fixed-price quote within 24 hours.
Every engagement
Regardless of test type or budget, every Cyber Forte engagement is delivered to the same standard and includes the same core deliverables.
Business-language overview for boards and executives , no technical jargon required.
Full technical detail on every vulnerability identified during testing.
Evidence demonstrating how each finding was exploited, not just theorised.
What each finding actually means for your organisation, in risk and cost terms.
Prioritised, step-by-step guidance your team can act on immediately.
We re-test remediated findings at no extra cost to confirm they’re resolved.
A Letter of Attestation and framework-mapped reporting for audits, insurers and procurement.
Testing methodology
The right methodology depends on what you’re trying to simulate and how much your budget covers. We recommend the approach that matches your actual threat profile.
01
Testers have zero prior knowledge of the target , simulating a real external attacker with no inside information. Maximum realism. Tests what an opportunistic attacker would find.
External attacker simulation
02
Testers receive limited credentials (e.g. a regular user account) , simulating a malicious insider or an attacker who has already gained initial access. Best value for most organisations.
Insider threat simulation
03
Full access to source code, architecture diagrams, and credentials , the most thorough approach. Finds deeply embedded vulnerabilities in high-assurance environments.
Maximum coverage
Compliance frameworks
Our reports are structured to satisfy auditor requirements across all major compliance frameworks. One engagement, multiple compliance needs covered.
Required as part of ISMS. Our report maps findings to Annex A controls and satisfies certification auditor requirements.
Req 11.4 mandates annual pen testing. We provide the segmentation testing and network-layer assessment PCI QSAs need.
Auditors expect pen testing evidence. Our reports align to CC6 and CC7 trust service criteria used in SOC 2 assessments.
ML2/ML3 assessment requires testing evidence. Our network and application reports satisfy ACSC Essential Eight evidence requirements.
Findings mapped to Identify, Protect, Detect, Respond functions. Used by organisations aligning to the NIST Cybersecurity Framework.
Required for Australian financial institutions. Our reports satisfy APRA’s expectations for testing of information assets.
business benefits
Security questionnaires and tenders increasingly ask for a recent, independent penetration test. A report and Letter of Attestation from a CREST ANZ Approved Member Company helps you get through procurement checks faster.
Insurers now ask for evidence of regular security testing at application and renewal. A current pen test report shows your risks are known, managed and independently verified.
Manual testing finds chained vulnerabilities, logic flaws and forgotten assets that automated scanners miss. You learn how an attacker would get in while you still have time to close the gap.
ISO 27001, PCI DSS, SOC 2, Essential Eight and APRA CPS 234 all expect evidence of technical testing. Framework-mapped reporting also supports your obligation under the Privacy Act to take reasonable steps to protect personal information.
Customers and partners want proof that their data is safe with you. Independent testing gives you that proof, backed by real exploitation evidence rather than a self-assessment.
Every finding is risk-rated and prioritised by business impact. Your team fixes what matters most first, instead of guessing where to invest.
Answers
Indicative pricing: web application testing $3,500–$10,000+, external network testing $5,000–$10,000+, cloud assessments $4,500–$12,000+, and red team engagements $25,000–$50,000+. See the full pricing table for API, internal network, mobile and wireless ranges. Final price depends on scope, number of targets and complexity, confirmed after a scoping call. Contact us for a tailored quote within 24 hours.
Timeline by type: Web app testing 3–5 business days. External network 5–10 days. Internal network 5–8 days. Cloud assessment 4–7 days. API testing 3–6 days. Red team 2–4 weeks. These are testing durations only , add 2–3 days for report production and 48 hours for debrief scheduling. Testing windows can often be run outside business hours to minimise disruption.
Black-box: testers start with zero knowledge , simulating a real external attacker. Most realistic, but may miss internal vulnerabilities. Grey-box: limited access provided (e.g. a user account) , simulates a malicious insider or compromised user. Best value for most organisations. White-box: full access to source code, architecture, and credentials , maximum coverage, highest cost. Required for PCI DSS Level 1 and high-assurance environments.
Most organisations test at least annually. Additional testing is recommended after major system deployments, significant infrastructure changes, a security incident, mergers or acquisitions, or when new regulatory requirements apply. PCI DSS requires annual testing and after significant changes. ISO 27001 requires regular testing as part of the ISMS. Organisations handling sensitive government data often test quarterly.
It depends on the test type. For black-box external testing we only need the target IP ranges or domains , no credentials. For grey-box testing we need test user accounts with the appropriate permission level. For white-box testing we need architecture documentation, source code access, and administrator credentials. We never require production admin access , testing can be performed against staging environments when required. All access is governed by the Rules of Engagement document signed before testing begins.
Penetration testing can support security assurance and compliance activities across frameworks including PCI DSS, ISO 27001, Essential Eight, SOC 2 and APRA-regulated environments. Specific testing frequency and scope depend on the applicable requirements, your risk profile and the systems being assessed. Cyber Forte is itself ISO 27001 certified and a CREST ANZ Approved Member Company, and our reports are structured to support your evidence trail across these frameworks.
ISO 27001 requires evidence of regular, competent penetration testing as part of your ISMS (typically under Annex A controls covering technical vulnerability management), but it does not mandate that testing must be CREST-certified specifically. That said, testing performed by a CREST ANZ Approved Member Company is well-regarded by auditors because the methodology, tester competence, and reporting standard are independently verified rather than self-declared , which tends to streamline the audit conversation.
Cyber Forte provides web application, external and internal network, cloud, API, mobile application, firewall, wireless, and red team penetration testing , all delivered by our CREST ANZ Accredited and OSCP-certified testers.
Every report includes an executive summary (business-language overview), technical findings with full proof of concept, CVSS v3.1 severity ratings, business impact analysis, prioritised step-by-step remediation guidance, and compliance framework mapping (ISO 27001, PCI DSS, SOC 2, NIST, ISM). We also issue a Letter of Attestation confirming engagement scope and outcomes , accepted as evidence for cyber insurance, procurement and tender submissions, and compliance audits.
We design testing windows to minimise disruption , most organisations schedule testing during off-peak hours or weekends for production systems. We never conduct destructive testing without explicit written approval. For highly sensitive systems we can test against a staging/UAT environment. Our Rules of Engagement document defines exactly what we will and won't do before testing begins.
Three verifiable differences: (1) CREST ANZ Approved Member Company with CREST ANZ Accredited and NV1/NV2-cleared staff , fewer than 5% of Australian pen test firms hold this combination. (2) Free re-testing included , most competitors charge $1,500–$5,000 separately for this. (3) 25+ years with ASX 50 clients (ANZ Bank, CPA Australia, Origin Energy, Australia Post) , that enterprise rigour applies to every engagement regardless of your size.
Yes , and significantly. Cyber insurers increasingly require evidence of penetration testing as a condition of coverage, and organisations with recent clean pen test reports typically receive 15–30% lower premiums. Our reports are structured to satisfy cyber insurance underwriter requirements, and we can provide a letter confirming engagement scope and findings for your insurer on request.
CREST penetration testing is security testing delivered by companies and testers accredited by CREST, an independent, not-for-profit body that sets technical and quality standards for the offensive security industry. In Australia and New Zealand, this is administered by CREST ANZ. An Approved Member Company has had its methodology, quality assurance, data handling and professional conduct independently assessed at the organisation level. Combined with individually accredited testers, this gives you assurance at both the company and tester level, which regulators, auditors, cyber insurers and government agencies increasingly expect when reviewing a vendor.
Yes. Cyber Forte is a CREST ANZ Approved Member Company, listed in the official CREST ANZ directory. Our penetration testers are CREST ANZ Accredited and OSCP-certified, and multiple consultants hold NV1/NV2 government security clearances for classified and government engagements. Our accreditation doesn't add an automatic price premium: pricing depends on scope, number of targets and complexity. See the pricing table above or contact us for a fixed-price quote within 24 hours.
Get a same-day, fixed-price penetration testing quote from a CREST ANZ Approved Member Company. CREST ANZ Accredited & OSCP-certified testers. Compliance-ready reports. Free re-testing included. No lock-in.
CREST ANZ Approved Member Company · Fixed-price quote within 24h · CREST ANZ Accredited & OSCP certified · Free re-testing · Compliance-ready reports
You may also need
Many organisations combine pen testing with compliance services in a coordinated engagement , maximising shared evidence and reducing total cost.
Best all-round
ISO 27001 requires pen testing as evidence for your ISMS. Our pen test report feeds directly into your certification audit , reducing duplication and cost when run together.
Choose it when
You want globally recognised proof of security that reassures customers, regulators and insurers alike.
Australian baseline
The ACSC’s eight mitigation strategies with maturity levels, widely used across Australian government supply chains.
Choose it when
You work with government or want a practical local security baseline.
US & SaaS focus
An attestation report against trust service criteria, common for technology firms selling into the United States.
Choose it when
Your buyers, often American, specifically ask for a SOC 2 report.
Insights
or reach us directly
Cyber Forte acknowledges the Bunurong People of the Kulin Nation as the traditional custodians of the land on which we work. We pay our respects to Elders past, present and emerging.
Cyber Forte Pty Limited | ABN: 14 636 444 838