Penetration Testing
Goal-oriented testing by experienced testers, reported against business impact.
Penetration testing puts your defences in front of a skilled attacker under controlled conditions. We test your networks, applications and cloud environments the way a real adversary would, then report findings against business impact rather than raw CVSS.
Every engagement includes manual exploitation. A scanner tells you what is theoretically vulnerable; a tester tells you what is actually reachable and what it would cost you.
Penetration testing scopes
External network
Everything reachable from the internet, including assets you may not know you publish.
Internal network
What an attacker achieves after the first foothold — lateral movement and privilege escalation.
Web applications
Tested against the OWASP Top 10:2025 — Broken Access Control (A01), Security Misconfiguration (A02), the new Software Supply Chain Failures (A03), Injection (A05) and Security Logging and Alerting Failures (A09) — plus the business logic no generic list covers.
Cloud environments
Identity, permission and configuration weaknesses across your cloud accounts.
How an engagement runs
Scoped, executed, then proven fixed
A test that ends at the report is half a test. The retest is what turns a finding into a closed issue.
Frequently asked questions
A vulnerability assessment identifies and prioritises weaknesses across your infrastructure, broadly and largely through tooling.
A penetration test goes further: a tester manually exploits those weaknesses and chains them together to prove what an attacker could actually achieve.
At least once every 12 months, and again after any significant change.
That is not just good practice — it is the explicit requirement in PCI DSS v4.0.1, whose Requirements 11.4.2 and 11.4.3 mandate internal and external penetration testing at least once every 12 months and after any significant infrastructure or application change. Service providers must test segmentation controls every six months; everyone else annually. The v4.x future-dated requirements became mandatory on 31 March 2025.
Even outside card-handling environments, that cadence is the accepted benchmark. A "significant change" is a major application release, a cloud migration, a new authentication flow, or a new externally reachable service.
Three different depths.
A vulnerability scan is automated and broad. Tooling compares your environment against known vulnerability data and lists what might be wrong.
A vulnerability assessment adds an analyst. Scan output is triaged, false positives removed, and findings prioritised into an order you can actually work through.
A penetration test adds an adversary. A tester manually exploits weaknesses and chains them together to demonstrate what an attacker could genuinely achieve. PCI DSS treats these as separate requirements for exactly this reason — scanning sits under Requirement 11.3, penetration testing under 11.4 with its own documented methodology.
Most organisations need all three: scanning for cadence, assessment for prioritisation, testing for proof.
We test against the current OWASP Top 10, released as the 2025 edition, plus business logic specific to your application — which no generic list covers.
The 2025 ranking reflects a real shift. Broken Access Control remains number one. Security Misconfiguration rose to second. Software Supply Chain Failures entered as a new A03, and Mishandling of Exceptional Conditions is the other new category. Injection, long the headline risk, has fallen to fifth. Notably, Security Logging and Alerting Failures sits at A09 — meaning the ability to detect an attack is itself assessed as a top-ten application risk.
Engagements are scoped and scheduled to avoid disruption, with rules of engagement agreed in advance and escalation contacts on standby throughout.
More from Offensive Security
Vulnerability Scanning
Your first line of defence — automated tooling combined with expert analysis, on a cadence that meets Essential Eight.
Vulnerability Assessment
Transforming weaknesses into strengths — a defensible remediation order, not a 400-page scanner dump.
Cyber Attack Simulation
Test and strengthen your defences against realistic, chained adversary behaviour.
Ready to see your attack surface the way an attacker does?
Book a walkthrough with an Australian-based security engineer. No scripted demo, no obligation.
Both forms deliver to info@cyberti.com.au.