Neon cyan outline of a vertical thermometer with rounded ends on a dark background, decorative image.

Penetration testing services for Australian organisations

dotSec has provided penetration testing services to Australian government and enterprise organisations for 26 years, and is CREST-accredited through CREST ANZ. 

Our assessors don’t just test systems. They also build and defend them, rotating through roles including SOC and SIEM analyst, system hardening, IAM implementation, and EDR-evasion research. 

That operational experience means our findings come with remediation guidance that is practical, prioritised, and grounded in what it actually takes to fix things.

What is a penetration test?

A penetration test is a controlled security assessment in which a skilled assessor attempts to discover, exploit, and report on vulnerabilities in a target system. It builds on vulnerability scanning by going further: the assessor manually validates each finding, attempts real exploitation, chains individual issues into higher-impact attack paths, and assesses the actual business consequences of a successful compromise.

The result is not a list of theoretical weaknesses. It is an evidence-based assessment of what an attacker could achieve, what the associated risks are, and what to fix first. Findings are rated using CVSS v4.0 and referenced against frameworks including the OWASP Top 10:2025 and OWASP Web Security Testing Guide where applicable.

Penetration testing services

dotSec provides penetration testing across four distinct service areas. Each targets a different part of your attack surface and follows a methodology appropriate to the technology and threat landscape involved.

Web application penetration testing

Web applications are where most organisations handle customer data, process transactions, and expose business logic to the internet. They are consistently among the most targeted and most exploited components in Australian environments.

dotSec’s web application penetration tests cover authentication, access controls, input validation, API security, business logic, cryptography, and server-side configuration. Testing is informed by the OWASP Web Security Testing Guide and aligned to the OWASP Top 10:2025. We test REST, GraphQL, and SOAP APIs as part of the standard engagement scope, and can include source code review where it adds value.

Web application pen testing is dotSec’s highest-volume testing service. For entities in scope for PCI DSS v4.0.1, Requirement 11.4.1 requires application-layer penetration testing. Web application pen testing also provides evidence for security testing under ISO 27001:2022 control A.8.29 and the systematic testing program required by APRA CPS 234.

External network penetration testing

Your internet-facing infrastructure is the first thing an attacker sees. External network penetration testing determines whether your public-facing systems can withstand a targeted attack from outside your network perimeter.

dotSec’s external assessments cover network services and protocols, web applications and customer portals, email infrastructure (SPF, DKIM, DMARC), DNS configuration, VPN and remote access gateways, cloud service endpoints (AWS, Azure, GCP), and certificate and TLS configuration. Testing methodology aligns with NIST SP 800-115 and NIST SP 800-53 Rev. 5 control CA-8.

AI penetration testing

If your organisation deploys AI or LLM components, whether customer-facing chatbots, internal knowledge assistants, document processing systems, or code generation tools, those components introduce attack vectors that conventional penetration testing will not detect.

dotSec’s AI penetration testing service covers prompt injection, training data extraction, insecure output handling, data model poisoning, and guardrail bypass. Assessments are structured around the OWASP Top 10 for LLM Applications and the MITRE ATLAS framework.

AI pen testing can be combined with a web application assessment to cover both traditional application vulnerabilities and AI-specific risks in a single engagement.

Red teaming and adversary simulation

A penetration test targets a defined scope and seeks to identify vulnerabilities within it. Red teaming is broader: it simulates a motivated attacker operating across the entire environment, using multiple attack vectors, with the goal of testing your organisation’s detection and response capabilities.

dotSec’s red team engagements are structured as collaborative exercises. Our offensive specialists also actively defend against attacks through SOC and SIEM operations, which means they understand both sides of the equation. Findings are classified using MITRE ATT&CK technique references and reported with CVSS v4.0 severity ratings.

Red teaming is most valuable for organisations that already have mature security controls. If basic hygiene (patching, MFA, endpoint protection) is not yet in place, a penetration test is a more appropriate starting point. dotSec can advise on which approach suits your current maturity level.

How we test: our penetration testing methodology

dotSec’s penetration testing follows five phases. The approach is consistent with NIST SP 800-115 and, for applications, the OWASP Web Security Testing Guide.

1. Scoping and planning

Before testing starts, our assessors agree the scope, objectives and constraints of the engagement with your team. This produces a test plan and Rules of Engagement (ROE) covering:

  • what credentials or access will be provided, and any limits on their use
  • whether targets are in production or non-production environments, and what constraints that creates
  • timing restrictions, known stability concerns, and active protection systems such as WAFs or IPSs
  • how high or critical findings are notified during testing
  • which third parties, such as hosting providers or a SOC, need to be informed

Both parties sign off the plan before any testing begins.

2. Reconnaissance

Assessors gather information about the target systems, the business processes they support, information flows and the underlying technologies. This identifies the attack surface and shapes the testing strategy.

3. Testing and exploitation

Automated tools detect known vulnerability patterns quickly. Manual testing finds what they miss:

  • business logic flaws
  • chained attack paths, where individually low-risk findings combine into a high-impact exploit
  • vulnerabilities that depend on how a specific application or environment behaves
  • false positives, which are removed before they reach your remediation list

4. Analysis and reporting

Findings are verified, assessed for exploitability and business impact, and compiled into a report containing:

  • an executive summary with prioritised risks and recommended actions
  • detailed findings rated with CVSS v4.0 and referenced to OWASP and CVE identifiers where applicable
  • a risk assessment consistent with AS ISO 31000:2018 and ISO/IEC 27005:2022
  • a remediation plan prioritised against your existing controls and operational constraints

5. Debrief and retesting

We walk your stakeholders through the findings and discuss remediation options. Where retesting is included in the engagement, it confirms, once fixes are in place, whether each vulnerability has been addressed.

Penetration testing approaches

The approach depends on what you need to learn about your environment. Most engagements combine more than one.

Black-box, grey-box and white-box testing

  • Black-box: the assessor starts with no information about, or credentials on, the target. This shows what an outside attacker with no inside knowledge could achieve.
  • Grey-box: the assessor has partial information or limited access, such as a standard user account or architecture documentation. This simulates an attacker who has compromised an account or holds some inside knowledge.
  • White-box: the assessor receives full details, which may include administrative credentials, source code, API definitions such as OpenAPI files, and network diagrams. This gives the broadest coverage in the time available.

The PCI Security Standards Council’s penetration testing guidance notes that PCI DSS penetration tests are typically performed as white-box or grey-box assessments.

External and internal testing

  • External: the assessor works from the internet against publicly accessible systems: web applications, APIs, firewalls, remote access gateways and cloud services. See external network penetration testing.
  • Internal: the assessor works from inside the network, simulating an attacker who has breached the perimeter or compromised an internal account, for example through phishing. This shows how far an attacker could move laterally and what they could reach.

We recommend the combination of approaches during scoping, based on your objectives, regulatory requirements and risk profile.

Why dotSec’s pen testers are different

Most pen testing firms employ testers who only test. dotSec’s assessors also build and operate secure systems. They rotate through roles across the business, including SOC and SIEM analysis, system hardening and secure configuration, identity and access management, and EDR-evasion and assumed-breach research.

This matters because a tester who has built and maintained secure infrastructure produces different findings from one who has only attacked it. They understand what remediation actually involves, which recommendations are practical to implement, and how to prioritise findings in a way that reflects operational reality rather than theoretical severity.

dotSec has applied this approach across federal government systems, APRA-aligned cryptographic services, data-exfiltration detection for a national law firm, and IAM platforms for major utilities.

How penetration testing supports compliance

Most governance, risk management, and compliance frameworks require or strongly recommend regular penetration testing:

  • PCI DSS v4.0.1 requires penetration testing at least annually and after significant changes (Requirement 11.4), plus specific protections for public-facing web applications (Requirement 6.4). dotSec is a PCI QSA company and a PCI DSS-compliant service provider.
  • ISO 27001:2022 Annex A controls A.8.25 (Secure development life cycle), A.8.26 (Application security requirements), A.8.28 (Secure coding) and A.8.29 (Security testing in development and acceptance) support regular security testing as part of an ISMS.
  • APRA CPS 234 (paragraph 27) requires APRA-regulated entities to test the effectiveness of their information security controls through a systematic testing program, with the nature and frequency of testing commensurate with factors including the criticality and sensitivity of the information asset.
  • The ACSC Essential Eight maturity model addresses application patching and administrative privilege restriction, both of which are informed by pen test findings.
  • NIST SP 800-53 Rev. 5 control CA-8 (Penetration Testing) is part of the high-impact baseline in NIST SP 800-53B.

Whether compliance is the primary driver or not, penetration testing provides an evidence-based view of how well your security controls actually perform under adversarial conditions.

Beyond the pen test: from findings to action

Pen test findings are only valuable if they lead to action. dotSec provides services across the full remediation cycle:

Accelerating pen tests with AI

dotSec’s AI-augmented penetration testing approach uses machine learning to accelerate reconnaissance, attack surface mapping, and vulnerability correlation. Automated discovery reduces the time spent on reconnaissance, and vulnerability correlation helps identify findings that manual-only approaches might miss within the same testing window.

AI augmentation extends the scope of what a testing engagement can cover without extending the timeline. It builds on the same NIST SP 800-115 and OWASP methodologies as conventional testing, with machine learning models layered on top for speed and coverage.

Penetration testing FAQ

How much does a penetration test cost in Australia?

There is no fixed price. Cost depends on the scope, the complexity of the environment, the testing approach (black-box, grey-box or white-box) and whether retesting is included. A single web application costs considerably less than an engagement covering internal networks, external infrastructure, APIs and cloud services. We provide a scope and quote after an initial consultation, so the price reflects the work actually required.

It depends on scope. A focused web application test may take several days; an engagement covering multiple environments can take several weeks. Timelines are agreed during scoping, and testing is scheduled with your operational teams to minimise disruption.

dotSec is CREST-accredited through CREST ANZ. Our assessors hold hands-on offensive certifications including OSCP (Offensive Security Certified Professional) and BSCP (Burp Suite Certified Practitioner), alongside CISM, CISA, CDPSE and PCI QSA. They also rotate through operational roles in SOC and SIEM analysis, system hardening and identity and access management.

What next?

If your organisation needs a penetration test, whether for compliance, risk reduction, or as part of a broader security improvement programme, dotSec can scope an engagement to match your requirements.

Not sure which type of test you need? dotSec can advise based on your environment, maturity level, and compliance obligations.

Premier Australian cyber security specialists