Penetration Testing

Manual, scope-tailored offensive testing across your web apps, APIs, networks, cloud environments and corporate infrastructure. Findings ranked by real-world impact, with reports your team will actually read.

What we test

  • Web applications & APIs. Modern SPAs, REST and GraphQL APIs, authentication and authorisation flows, business logic.
  • Cloud environments. AWS, Azure and GCP configuration review, identity, network controls and exposed services.
  • Internal & external networks. From internet-facing perimeter sweeps to assumed-breach internal engagements.
  • Mobile. iOS and Android applications, including their backends and inter-process trust boundaries.

Testing for ISO 27001, SOC 2 or a customer security review? We scope compliance-driven engagements so you get exactly what your auditor needs. No more, no less.

How we work

Every engagement starts with a scoping call so we understand what success looks like for you. We agree on goals, rules of engagement and reporting expectations up front. No surprises, no scope creep.

During testing, we keep an open channel with your team. Critical findings are escalated the moment we see them. At the end of the engagement, we deliver:

  • An executive summary written for non-technical stakeholders.
  • A technical report with full reproduction steps, evidence and remediation guidance.
  • A debrief call with your engineering team to walk through the findings.
  • A free retest of fixed issues within 90 days.

Why teams choose us

Many penetration testing firms run scanners, lightly review the output, and ship a report. We don't. Every Ironbark engagement is run hands-on by an experienced offensive tester who finds the issues automated tools miss.

Our team has presented at major industry conferences, contributed to widely-used open source security tooling, and written some of the most-read content in the offensive security space. We bring that depth to every test.

FAQ

Frequently asked questions

How much does a penetration test cost in Australia?

Most Ironbark engagements run 4–15 testing days at a fixed day rate. As a guide: a focused web application or API test typically lands between AU$8,000 and AU$18,000, and an external network test between AU$6,000 and AU$12,000. We provide a fixed quote within one business day of a free scoping call.

How long does a penetration test take?

Typically 1–3 weeks from kickoff to report depending on scope. Critical findings are escalated the moment we discover them, so remediation can start before testing even finishes.

How often should we get a penetration test?

At least annually. That's the cadence ISO 27001, SOC 2 and enterprise customers expect, plus after major changes like a new product, a re-architecture or an acquisition.

What's the difference between a penetration test and a vulnerability scan?

A vulnerability scan is automated pattern-matching against known issues. A penetration test is a skilled human actively attacking your systems: chaining weaknesses, abusing business logic and proving real-world impact. If a report you paid for reads like scanner output, you bought a scan.

Who actually does the testing?

The senior tester who scopes your engagement is the one who tests it. No bait-and-switch to a junior bench. Our testers have deep backgrounds in bug bounty hunting, offensive security research and open-source security tooling used across the industry.

Contact

Talk to us

Tell us what you're trying to protect, secure or build. We'll come back with a plan.

Prefer to talk live? Book a call →

By submitting this form, you agree to our privacy policy.