Human-led security testing

Penetration testing for Australian businesses

Human-led testing. Clear findings. Practical fixes.

From A$7,500 ex GST for one web app, its API and two user roles.

Other services have their own from price in the quote form.

Manually verified findings.

  • OSCP-certified testers
  • Written testing boundaries
  • Actionable remediation
What we test

What you get.

Manual investigation

Sign-in, authorisation and the business workflows in scope.

Verified findings

Severity rationale, reproducible evidence and remediation priorities.

Two audiences

A decision-maker summary alongside technical detail for the people fixing the issues.

A focused retest

Coverage and terms stated in the written scope.

Before testing

What we need from you

  • Assets, user roles and connected services, included deliberately.
  • The requester’s exact wording, if a customer or auditor asked for the test.
  • Written authorisation, agreed techniques and test windows.
  • Safe test data and a stop-test contact.
Use the scoping checklist
After testing

What you can act on

  • Evidence, limitations and practical remediation priorities.
  • Urgent confirmed findings raised promptly during testing.
  • A retest record of resolved, partial and outstanding items.

Reporting and retest terms are agreed in writing. The record separates verified fixes from outstanding work.

Limits matter

What this test does not cover

  • Destructive testing and denial of service, excluded by default.
  • Emergency incident response.
  • SOC 2 reporting or ISO 27001 certification.
  • A certificate of security or a promise of audit acceptance.
The deliverable

See what you will receive

A 19-page illustrative report built from synthetic findings, not a client report. It shows scope, evidence, severity rationale and the retest record.

See sample report

Six starting points

Choose the testing focus

A buyer has asked for testing evidence? Our SaaS procurement penetration testing scope covers acceptance criteria, tenant boundaries and retest records before booking.

Preparing your asset list? Use the penetration test scope builder. API teams can also use the OWASP API security self-check. Neither replaces a penetration test. Planning a cloud move? The cloud migration readiness checklist records preparation gaps without inspecting your systems.

Read the scoping guide. What a penetration test report should contain.

Individual credentials. Clear boundaries.

Our testers hold OSCP, OSWE, OSCE and OSWP from OffSec. They also hold CREST Registered Tester, eCPPT v2 and Zero-Point Red Team Operator certifications.

These are certifications held by individuals, not company accreditations. Sorami is not a CREST member company.

Full certification list. The company accreditation position, in full

From authorisation to retest

  1. Agree the scope. Confirm assets, roles and requester requirements. Agree written authorisation and stop-test contacts.
  2. Test and validate. Investigate manually with supporting tools. Raise urgent confirmed findings promptly.
  3. Report and explain. Record evidence, limitations and practical remediation priorities.
  4. Check the fixes. Retest agreed findings and record resolved, partial and outstanding items.
Questions before you book

Practical answers.

What does a penetration test cost?

From A$7,500 ex GST for one web application with its API and two user roles. The base scope covers five testing days, the report and a retest of critical and high findings. Qualified web scopes with additional applications, endpoints or cloud accounts show an indicative range. Other systems need written scope review. Fixed price once scope is agreed.

How long does a penetration test take?

Testing effort is not the same as elapsed delivery time. We agree dates after reviewing scope, access readiness and your deadline. Allow time for remediation and retesting. The estimate does not reserve dates.

Will the report satisfy a customer or auditor?

Acceptance depends on the requester’s requirements. Share their exact wording before booking so we can check scope, credentials and retest terms. A penetration test is not SOC 2 or ISO 27001 certification.

Can you test production safely?

Only with written authorisation, agreed techniques and test windows, safe data and a stop-test contact. Destructive testing and denial of service are excluded by default. This service is not emergency incident response.

Are you a CREST member company?

No. Sorami Consulting Pty Ltd is not a CREST member company. Our testers hold individual CREST Registered Tester certification, and we will confirm that position in writing for your procurement file.

Ready to price your test?

The sample report is illustrative, built from synthetic findings. It is not a client report.

Get instant quote

Last reviewed: