What we test
- Web applications & APIs. Modern SPAs, REST and GraphQL APIs, authentication and authorisation flows, business logic.
- Cloud environments. AWS, Azure and GCP configuration review, identity, network controls and exposed services.
- Internal & external networks. From internet-facing perimeter sweeps to assumed-breach internal engagements.
- Mobile. iOS and Android applications, including their backends and inter-process trust boundaries.
Testing for ISO 27001, SOC 2 or a customer security review? We scope compliance-driven engagements so you get exactly what your auditor needs. No more, no less.
How we work
Every engagement starts with a scoping call so we understand what success looks like for you. We agree on goals, rules of engagement and reporting expectations up front. No surprises, no scope creep.
During testing, we keep an open channel with your team. Critical findings are escalated the moment we see them. At the end of the engagement, we deliver:
- An executive summary written for non-technical stakeholders.
- A technical report with full reproduction steps, evidence and remediation guidance.
- A debrief call with your engineering team to walk through the findings.
- A free retest of fixed issues within 90 days.
Why teams choose us
Many penetration testing firms run scanners, lightly review the output, and ship a report. We don't. Every Ironbark engagement is run hands-on by an experienced offensive tester who finds the issues automated tools miss.
Our team has presented at major industry conferences, contributed to widely-used open source security tooling, and written some of the most-read content in the offensive security space. We bring that depth to every test.
Engagements
Choose your engagement
Every engagement is scoped to your environment and quoted fixed-price. These are the most common starting points.
Web application
Authentication, access control, business logic and the OWASP Top 10, tested by hand.
API
REST and GraphQL. BOLA/IDOR, broken auth and the data exposure your UI never shows.
External network
Deep recon of your internet-facing footprint, then manual attack, by the people who build the recon tools.
Cloud
AWS, Azure and GCP. IAM escalation paths, public exposure and assumed-breach scenarios.
ISO 27001 & compliance
Auditor-ready testing scoped to what certification actually requires. Also SOC 2 and PCI.
FAQ
Frequently asked questions
How much does a penetration test cost in Australia?
Most Ironbark engagements run 4–15 testing days at a fixed day rate. As a guide: a focused web application or API test typically lands between AU$8,000 and AU$18,000, and an external network test between AU$6,000 and AU$12,000. We provide a fixed quote within one business day of a free scoping call.
How long does a penetration test take?
Typically 1–3 weeks from kickoff to report depending on scope. Critical findings are escalated the moment we discover them, so remediation can start before testing even finishes.
How often should we get a penetration test?
At least annually. That's the cadence ISO 27001, SOC 2 and enterprise customers expect, plus after major changes like a new product, a re-architecture or an acquisition.
What's the difference between a penetration test and a vulnerability scan?
A vulnerability scan is automated pattern-matching against known issues. A penetration test is a skilled human actively attacking your systems: chaining weaknesses, abusing business logic and proving real-world impact. If a report you paid for reads like scanner output, you bought a scan.
Who actually does the testing?
The senior tester who scopes your engagement is the one who tests it. No bait-and-switch to a junior bench. Our testers have deep backgrounds in bug bounty hunting, offensive security research and open-source security tooling used across the industry.
Contact
Talk to us
Tell us what you're trying to protect, secure or build. We'll come back with a plan.