Skip to main content

Penetration testing, priced in days you can count

Three fixed-price packages and a scoping session that tells you which one you actually need. Manual testing by Australia-based, CREST and OSCP certified testers. Ex GST.

Sydney HQ · Australia-based testers · OSCP / OSWE / OSCE / OSWP / CREST CPSA / CREST CRT · No offshoring · No subcontracting

Fixed price, ex GST

Three packages, and one honest "it depends"

Penetration testing is sold in days of skilled human effort, so these packages are priced in days rather than in features. The scoping session confirms which one your environment actually needs.

  • Essential

    $5,900

    3 testing days

    Typically fits one target:

    • External network, up to 2 public ranges
    • or one small web application
    • or one mobile app, single platform
  • Medium

    $9,500

    5 testing days

    Typically fits:

    • External and internal network, one site
    • or one web application with API and multiple roles
    • or external network plus one web application
  • Large

    $18,500

    10 testing days

    Typically fits:

    • Multi-site internal network and Active Directory
    • or several applications and APIs
    • or a combined programme across test types
  • Custom

    Quoted

    Fixed fee after scoping

    For scope the packages do not fit:

    • Red team and adversary simulation
    • IoT, OT and embedded systems
    • AI, LLM and abuse case testing

All prices are ex GST. The package is confirmed after the scoping session, not before it.

Rated five out of five.

Engaged Cliffside to go a few pen tests. Internal, External and web application pen test. They did a wonderful job, and found issues that the previous "renowned" company had missed completely. Because of their support and honest advice, our security posture is much better than what it was six months back. Would absolutely recommend their services. Great value for money is an added bonus.

Varun Pant · Google review · Read all reviews (5.0 from 7 Google reviews) ↗(opens in new tab)

Before anything is quoted

Every engagement starts with a scoping session

Before anything is quoted or booked, a senior tester spends time with your team working out exactly what should be tested, what should not, and whether a retest is required. That session is what turns a package into a fixed fee, and occasionally it is what tells you that a smaller package is enough.

  • What is in scope

    Hosts, ranges, applications, roles, environments and the systems that stay out

  • How we test

    Black, grey or white box, and why that choice suits your risk rather than our convenience

  • Rules of engagement

    Windows, change freezes, escalation contacts, and what happens if we find something critical at 2am

  • Whether you need a retest

    Agreed up front and priced up front, not discovered after you have remediated

The honest version

If the quote looks cheap, ask what it buys

If a penetration test quote comes in under about $4,000, ask how many days of manual testing it buys. At Australian rates a genuine test is measured in days, and under $4,000 rarely buys more than two. Below that you are usually paying for an automated scan with a report template over it, or for work sent offshore.

Three questions separate the two, and you should ask us the same ones: how many hours of manual testing are included, what individual certifications the testers hold, and which country they sit in. Then get the fee fixed before work starts. That is how we quote, and it is the only model that puts scoping risk on the tester rather than on you.

In the price

Included with every engagement

These are in the package price, not extras that appear on the invoice later.

  • Findings as we discover them. High and critical issues reported the day we find them, so remediation can start before the report lands
  • Executive summary and technical report. Findings rated by business impact, not just CVSS, with specific remediation steps
  • Compliance-ready evidence. Findings mapped to ISO 27001, SOC 2, APRA CPS 234, PCI DSS or the Essential Eight
  • Debrief call. We walk your team through every finding until the remediation is understood
  • Attestation letter. A shareable statement for customers and auditors who should not receive the full report
  • Redacted report on request. For customers who need more than the letter but not your internal detail
  • Retest of critical and high findings within 90 days, confirming the fix holds and cannot be bypassed
  • A named senior tester from scoping to debrief, with no account manager in between

Rated five out of five.

Cliffside conducted a thorough penetration test and security architecture review and produced a report that was packed with actionable items and in priority order. This made it super clear to us what we needed to work on. Shout out to Adriano, Ajay, and Param who were super responsive and easy to work with throughout the engagement. Highly recommend them if you're serious about your cybersecurity.

Allan Li · Google review

Scope options

What we test

The scoping session decides which of these your environment actually needs. Most organisations do not need all of them at once.

  • Web application and API

    Authentication, session handling, authorisation and business logic flaws that scanners miss. REST, GraphQL and SOAP

  • External network

    Everything exposed to the internet, and whether initial access is achievable

  • Internal network

    Assume breach. Lateral movement, privilege escalation and Active Directory weaknesses

  • Cloud

    Azure, AWS and hybrid. IAM misconfiguration, storage permissions and cloud-native attack paths

  • Mobile application

    iOS and Android. Client-side storage, certificate pinning, API communication and authentication

  • Wireless

    WPA2 and WPA3 configuration, evil twin attacks, and whether guest really is isolated from corporate

  • Social engineering

    Phishing, vishing and physical access, assessing the human element

  • AI and abuse case

    Prompt injection, jailbreaking, data leakage, and misuse of AI features through their intended interfaces

  • IoT and OT

    Firmware, protocols and the interaction between devices and their backend

Rated five out of five.

Engaged to do a Penetration Test of a Health Services LLM. Extremely smooth setup time, test went on time, in line with budget, with excellent results and a report following within days. Tested more than the default OWASP Top 10 / basic testing, created custom checks specifically for LLMs. Recommend without hesitation

Timothy Glover · Google review

Pricing questions, answered

How do I know which package I need?
You do not need to know before you call. The scoping session works it out with you, and the package is confirmed after that, not before. If your environment sits between two packages we tell you which way it falls and why.
Is a retest included?
Critical and high findings are retested within 90 days of the report at no additional cost, confirming the fix holds and cannot be bypassed. Retesting of medium and low findings, or retesting outside that window, is quoted separately.
What if the scoping session shows we need less than we asked for?
We tell you, and quote the smaller package. Scoping you up to a package you do not need would earn more once and cost us the relationship, which is a poor trade.
Why does Australia-based delivery affect the price?
Because Australian testing days cost more than offshore ones, and we do not offshore testing or subcontract delivery to overseas providers. Cliffside is headquartered in Sydney CBD and our penetration testers are Australian residents based across multiple states. That is part of why a genuine test is measured in days at Australian rates. For APRA-regulated entities, government agencies and organisations with data sovereignty obligations, it also simplifies chain of custody and keeps offshore data handling out of your privacy impact assessment.
Can we see a sample report before we commit?
Yes. Ask at the scoping session and we will send a redacted sample so you can judge the depth of the findings and the quality of the remediation guidance before you spend anything.
Do you test AI and LLM features?
Yes. Prompt injection, jailbreaking, data leakage and hallucination exploitation, plus abuse case testing of how AI features can be misused through their intended interfaces. Our approach aligns with the OWASP LLM Top 10 and we assess against ISO 42001 where applicable.

Know what attackers would find first

Thirty minutes, no slides. We will tell you which package fits, and if none of them do, we will say that too.

Talk to us →