Skip to main content

IT Services

Penetration Testing

Ethical hacking to find vulnerabilities in your systems before real attackers do, with clear, actionable reports that your team can act on.

A penetration test gives you an adversarial view of your security posture. Our testers think like attackers, probing your systems, applications and people for weaknesses. The result is a prioritised list of vulnerabilities and practical remediation guidance.

Types of testing

We offer a range of penetration testing services depending on your requirements and risk profile.

  • External network penetration testing: attacking your perimeter from the internet
  • Internal network penetration testing: simulating an insider or post-breach scenario
  • Web application penetration testing: OWASP Top 10 and beyond
  • Social engineering: phishing simulations and physical security testing
  • Cloud configuration review: AWS, Azure and Google Cloud posture assessment

What you receive

Every engagement delivers a comprehensive written report and a debrief session.

  • Executive summary for leadership: risk rating and key findings
  • Technical report with full vulnerability details and evidence
  • Prioritised remediation roadmap with effort/risk ratings
  • Debrief session with your technical team
  • Optional re-test to verify remediation

Know what you are buying

A vulnerability scan is not a penetration test

Both are sold under the same words and the price gap between them is large. A scan is a useful thing to run continuously, and it is not what this page is offering. Here is the difference, so a quote can be read properly.

Who does the work

Vulnerability scan

Software, running against a database of published vulnerabilities.

Penetration test

A person, using tools, who decides what to try next based on what they find.

What it finds

Vulnerability scan

Known issues with a published signature: missing patches, outdated versions, weak ciphers.

Penetration test

The above, plus logic flaws, broken access control and chains where three harmless findings combine into one serious one.

False positives

Vulnerability scan

Common. Anything matching a signature is reported whether it is exploitable in your environment or not.

Penetration test

Findings are confirmed by exploiting them before they reach the report.

What you get

Vulnerability scan

A list, often hundreds of rows, ordered by a generic severity score.

Penetration test

Prioritised findings with evidence, business impact and remediation guidance.

How long

Vulnerability scan

Minutes to hours, and it can run continuously.

Penetration test

Days to weeks, depending on scope.

Scoping

How much do you tell the tester?

This choice affects both cost and depth more than any other, and buyers are often asked to make it without being told what it means.

Black box

No prior knowledge

The tester starts where an external attacker starts, with your public footprint and nothing else. The most realistic simulation of an opportunistic attack, and the least efficient use of the days, because time goes into discovering what a white box test is simply told.

Grey box

Limited access

Standard user credentials and a basic description of the architecture. Usually the best value for most businesses: it answers both what an outsider can reach and what one compromised staff login leads to, which is how most real breaches actually unfold.

White box

Full visibility

Architecture documentation, configuration and often source code. The deepest coverage per day spent and the best choice when you want assurance over a specific application rather than a simulation of an attack.

How a test runs

Six phases, from scope to retest

Engagements draw on the OWASP Web Security Testing Guide, the detailed methodology behind application testing, and on the Penetration Testing Execution Standard. The first phase and the last are the two that decide whether anything actually gets fixed: without agreed scope a test answers the wrong question, and without a retest nobody has confirmed the fix worked.

01

Scope and rules of engagement

What is in scope, what is explicitly out, when testing may run, and who to call to stop it immediately. Agreed and signed before anything is touched. Testing without this in writing is a risk to both sides.

02

Reconnaissance

Mapping what you actually expose: hosts, services, applications, subdomains, exposed credentials and anything published that was never meant to be. Most engagements surface assets the client did not know were reachable.

03

Exploitation

Attempting to use what was found, because a vulnerability nobody can exploit in your environment is not the same as one they can. This is the step an automated scan cannot perform, and the reason findings arrive already verified.

04

Post-exploitation

Having got in, how far does it go? Escalating privilege, moving laterally and reaching data establishes real business impact rather than a theoretical severity rating. This is where a medium finding is sometimes shown to be critical.

05

Reporting

An executive summary written for people who will not read the technical section, and a technical report with evidence, reproduction steps and remediation guidance for the people who will.

06

Retest

Verifying that the fixes actually fixed it. Remediation frequently changes behaviour without closing the underlying issue, and a finding is only closed once somebody has tried it again.

FAQ

Questions we are asked most

How often should we run a penetration test?
The common pattern is annually, plus again after any significant change: a new application, a cloud migration, a merger, or a material change to who can reach what. Annual testing alone assumes your environment sits still for twelve months, which it does not. Regular testing is also increasingly a condition of cyber insurance renewal and of onboarding as a supplier to larger organisations, so the cycle is often set by someone other than you. There is a regulatory driver as well. Under New Zealand's Privacy Act 2020, a breach that has caused or is likely to cause serious harm must be reported to the Privacy Commissioner as soon as you are practically able, and Australia's Notifiable Data Breaches scheme places a comparable duty on businesses to notify the OAIC. Testing is how you find out what that notification would have to say while you are not yet the one writing it. See Cybersecurity
What drives the cost?
Scope, mainly: how many applications and hosts are in scope, how much of the environment the tester is told in advance, and whether a retest is included. Days of skilled time is the underlying unit, so anything that reduces guesswork reduces cost. When you compare proposals, compare those three variables rather than the totals, because two quotes at very different prices are usually describing genuinely different pieces of work.
Will testing break anything or take our systems down?
The risk is managed rather than pretended away. Destructive techniques such as denial of service are excluded unless you specifically ask for them, testing windows are agreed around your operations, and a named contact on our side can halt the engagement immediately. Where a system is genuinely too fragile to touch in production, testing a staging copy is the right answer, and the report says so.
Do you test web applications against the OWASP Top 10?
Yes, and beyond it. The OWASP Top 10 is an awareness document listing the most critical categories of web application risk, currently in its 2025 edition, and it is a floor rather than a ceiling. Application testing follows the OWASP Web Security Testing Guide, which is the detailed testing methodology, so coverage includes authentication, session management, access control and business logic rather than only the headline ten. Application security is also far cheaper to deal with during a build than after one, so if a new application is in progress it is worth scoping the testing in early. See Software Development
What do you need from us to scope it?
A list of what you want tested and why, whether that is a public application, your external perimeter, the internal network or all three. If you are testing because an insurer, customer or auditor asked you to, tell us who and what they asked for, because the requirement usually dictates the scope and it is cheaper to meet it the first time than to retest against it. New Zealand and Australian insurers in particular have become more specific about what they expect a test to cover before they will renew. See Managed Security

Book a penetration test

Tell us about your environment and we'll scope the right engagement for you.