Penetration testing, priced in days you can count
Three fixed-price packages and a scoping session that tells you which one you actually need. Manual testing by Australia-based, CREST and OSCP certified testers. Ex GST.
Sydney HQ · Australia-based testers · OSCP / OSWE / OSCE / OSWP / CREST CPSA / CREST CRT · No offshoring · No subcontracting
Fixed price, ex GST
Three packages, and one honest "it depends"
Penetration testing is sold in days of skilled human effort, so these packages are priced in days rather than in features. The scoping session confirms which one your environment actually needs.
Essential
$5,900
3 testing days
Typically fits one target:
- External network, up to 2 public ranges
- or one small web application
- or one mobile app, single platform
Medium
$9,500
5 testing days
Typically fits:
- External and internal network, one site
- or one web application with API and multiple roles
- or external network plus one web application
Large
$18,500
10 testing days
Typically fits:
- Multi-site internal network and Active Directory
- or several applications and APIs
- or a combined programme across test types
Custom
Quoted
Fixed fee after scoping
For scope the packages do not fit:
- Red team and adversary simulation
- IoT, OT and embedded systems
- AI, LLM and abuse case testing
All prices are ex GST. The package is confirmed after the scoping session, not before it.
Rated five out of five.
Engaged Cliffside to go a few pen tests. Internal, External and web application pen test. They did a wonderful job, and found issues that the previous "renowned" company had missed completely. Because of their support and honest advice, our security posture is much better than what it was six months back. Would absolutely recommend their services. Great value for money is an added bonus.
Before anything is quoted
Every engagement starts with a scoping session
Before anything is quoted or booked, a senior tester spends time with your team working out exactly what should be tested, what should not, and whether a retest is required. That session is what turns a package into a fixed fee, and occasionally it is what tells you that a smaller package is enough.
What is in scope
Hosts, ranges, applications, roles, environments and the systems that stay out
How we test
Black, grey or white box, and why that choice suits your risk rather than our convenience
Rules of engagement
Windows, change freezes, escalation contacts, and what happens if we find something critical at 2am
Whether you need a retest
Agreed up front and priced up front, not discovered after you have remediated
The honest version
If the quote looks cheap, ask what it buys
If a penetration test quote comes in under about $4,000, ask how many days of manual testing it buys. At Australian rates a genuine test is measured in days, and under $4,000 rarely buys more than two. Below that you are usually paying for an automated scan with a report template over it, or for work sent offshore.
Three questions separate the two, and you should ask us the same ones: how many hours of manual testing are included, what individual certifications the testers hold, and which country they sit in. Then get the fee fixed before work starts. That is how we quote, and it is the only model that puts scoping risk on the tester rather than on you.
In the price
Included with every engagement
These are in the package price, not extras that appear on the invoice later.
- Findings as we discover them. High and critical issues reported the day we find them, so remediation can start before the report lands
- Executive summary and technical report. Findings rated by business impact, not just CVSS, with specific remediation steps
- Compliance-ready evidence. Findings mapped to ISO 27001, SOC 2, APRA CPS 234, PCI DSS or the Essential Eight
- Debrief call. We walk your team through every finding until the remediation is understood
- Attestation letter. A shareable statement for customers and auditors who should not receive the full report
- Redacted report on request. For customers who need more than the letter but not your internal detail
- Retest of critical and high findings within 90 days, confirming the fix holds and cannot be bypassed
- A named senior tester from scoping to debrief, with no account manager in between
Rated five out of five.
Cliffside conducted a thorough penetration test and security architecture review and produced a report that was packed with actionable items and in priority order. This made it super clear to us what we needed to work on. Shout out to Adriano, Ajay, and Param who were super responsive and easy to work with throughout the engagement. Highly recommend them if you're serious about your cybersecurity.
Scope options
What we test
The scoping session decides which of these your environment actually needs. Most organisations do not need all of them at once.
Web application and API
Authentication, session handling, authorisation and business logic flaws that scanners miss. REST, GraphQL and SOAP
External network
Everything exposed to the internet, and whether initial access is achievable
Internal network
Assume breach. Lateral movement, privilege escalation and Active Directory weaknesses
Cloud
Azure, AWS and hybrid. IAM misconfiguration, storage permissions and cloud-native attack paths
Mobile application
iOS and Android. Client-side storage, certificate pinning, API communication and authentication
Wireless
WPA2 and WPA3 configuration, evil twin attacks, and whether guest really is isolated from corporate
Social engineering
Phishing, vishing and physical access, assessing the human element
AI and abuse case
Prompt injection, jailbreaking, data leakage, and misuse of AI features through their intended interfaces
IoT and OT
Firmware, protocols and the interaction between devices and their backend
Rated five out of five.
Engaged to do a Penetration Test of a Health Services LLM. Extremely smooth setup time, test went on time, in line with budget, with excellent results and a report following within days. Tested more than the default OWASP Top 10 / basic testing, created custom checks specifically for LLMs. Recommend without hesitation
Pricing questions, answered
How do I know which package I need?
Is a retest included?
What if the scoping session shows we need less than we asked for?
Why does Australia-based delivery affect the price?
Can we see a sample report before we commit?
Do you test AI and LLM features?
Know what attackers would find first
Thirty minutes, no slides. We will tell you which package fits, and if none of them do, we will say that too.
Talk to us →