Scoping a penetration test for a 50-person business
Short answer
Scope a penetration test around the question you need answered: what someone on the internet can reach (external), how far a compromised laptop or account could go (internal), or whether an application you run can be abused (web application or API). Agree targets, dates, exclusions and written authorisation first. CyberByte Security's external Penetration Test & Retest is from $9,000 ex GST; other test types are quoted separately.
Written by Muhammad Gulzar, Founder & Principal Security Consultant
Principal Security Consultant · Enterprise & government experience · 10+ years across IT, cloud & cyber
Last reviewed October 2026 · General information only, current as at the review date — not professional advice for your specific circumstances.
Who this is for
This guide is for a business of around 50 people, typically with Microsoft 365, a few cloud services, a small office network and perhaps a customer-facing application, that has been asked for a penetration test. The request might come from a client contract, a tender, an insurer or the board. The aim is to help you scope a test that answers the real question, at a price you can defend.
Start with the question, not the test type
A penetration test is a time-boxed exercise against agreed targets. The scope decides what you learn. Before talking to a provider, write down who is asking, what they want evidence of, and which systems hold the data or functions that matter most. If a client contract specifies a test type, start there.
| Test type | The question it answers | Typical targets |
|---|---|---|
| External infrastructure | What can someone on the internet reach, and can they get in? | Public IP addresses, remote access, firewalls, internet-facing servers |
| Internal network and Active Directory | If one laptop or account is compromised, how far could an attacker get? | Internal servers, file shares, Active Directory |
| Web application | Can the application be abused through authentication, access control or data exposure flaws? | Customer portals, booking or ordering systems |
| API | Can the interfaces behind an app or integration be abused? | REST or GraphQL endpoints used by apps and partners |
For a business with few on-premises systems, an external test is a practical starting point. If you run Active Directory or hold sensitive data on internal servers, an internal test answers a different and often more important question. Web application and API tests are scoped by user roles and functions, not only by the number of URLs.
What must be agreed in writing before testing
Permission is a legal matter, not a formality. Under section 478.1 of the Criminal Code, it is an offence to cause unauthorised access to, or modification of, restricted data, intending to do so and knowing it is unauthorised. Section 476.2 explains that access is unauthorised if the person is not entitled to cause it. Written authorisation from someone entitled to give it is therefore the first deliverable of any engagement. This is general information, not legal advice.
- The exact targets: IP addresses, domains, applications and user roles.
- Exclusions. In our engagements, denial-of-service testing and social engineering are excluded unless expressly agreed.
- Testing dates, permitted windows and any change freezes.
- Emergency contacts on both sides and a stop-work procedure.
- Confirmation from any hosting, software or managed service provider whose systems are in scope. Check their terms, as some publish rules for customer-initiated testing.
- How evidence and the report will be handled, retained and destroyed.
- Whether a retest is included and how long you have to use it.
Penetration test, vulnerability assessment or scan?
ASD's Information Security Manual (ISM) lists security control assessments, vulnerability scanning, vulnerability assessments and penetration tests as different kinds of security assessment. Vulnerability scanning looks for missing patches and known weaknesses. The Essential Eight sets scanning frequencies, for example a vulnerability scanner used at least daily to identify missing patches or updates in online services at Maturity Level One. A penetration test goes further: a practitioner validates findings and tries to chain them together within the agreed scope.
The two work together. Recurring automated vulnerability scanning, such as our Managed Vulnerability Management service, keeps watch between tests; the penetration test shows what the gaps would mean in practice.
How often should you test?
The ISM (September 2026) says vulnerability assessments and penetration tests are conducted for systems before deployment, before significant changes are deployed, and at least every six months thereafter. The ISM is a framework an organisation can apply using its own risk management approach, so for a private business it is a reference point rather than a mandate, unless a contract or policy applies it. Clients and insurers may set their own frequency, so check their wording. The ISM also says people performing security assessments should be independent of the system being assessed.
For organisations covered by the Privacy Act 1988, Australian Privacy Principle 11 requires reasonable steps to protect personal information, including technical and organisational measures. Independent testing is one way to check that those measures work as intended.
Questions to ask a provider
- Which parts of the test are manual, and which are tool-assisted?
- Who will perform the testing, and who reviews the report?
- How are findings rated, and will the report have an executive summary as well as technical detail?
- Is a retest included, and what does the retest letter or summary state?
- How is evidence protected during and after the engagement?
Acceptance by an insurer, auditor or client depends on their own requirements, so a report is designed to support those requests rather than guarantee them.
Cost and timeline
CyberByte Security's Penetration Test & Retest is from $9,000 ex GST for an external infrastructure test and typically runs over 2–3 weeks, with one agreed retest included. Internal, web application, API and Active Directory testing are quoted separately once the targets are known. If you first need to know what you expose to the internet, an External Attack Surface Assessment is from $5,500 ex GST. The exact fixed price for the agreed scope is confirmed in writing after a short scoping call. Project terms are 50% on commencement and 50% on delivery, and all published prices are on the packages page.
How CyberByte would approach it
We would start with a 20-minute scoping call to work out the question you need answered and the targets that answer it. Authorisation, rules of engagement, exclusions and emergency contacts would be agreed in writing before any activity. Testing would combine tool-assisted discovery with manual validation, exploitation and attack-path analysis within the agreed scope. The report would rate findings by business impact, with an executive summary and remediation steps your team or MSP could action, followed by the agreed retest once fixes were in place. More detail is on the Penetration Testing page, and the report format is on the sample deliverables page.
Ready to scope yours? Request a scoping call.
Common questions
Will a penetration test disrupt our operations?
Testing is planned to limit disruption: permitted windows, exclusions and a stop-work procedure are agreed beforehand, and denial-of-service testing is excluded unless expressly authorised. Some risk remains with any active testing, which is why those controls are agreed in writing.
Do we need an internal test as well as an external one?
It depends on what you run. If most of your systems are cloud services, an external test plus a Microsoft 365 configuration review may answer the question. If you have Active Directory or sensitive data on internal servers, an internal test shows how far a single compromised device could lead.
Who can authorise the test?
Authorisation should come in writing from someone entitled to give it for each system in scope, usually the business that owns the systems. Where an MSP, hosting or software provider operates part of the environment, their confirmation is sought too.
Will the report satisfy our client or insurer?
A clear report and retest summary are designed to support client, insurer and tender evidence requests, but each organisation sets its own requirements and acceptance is not guaranteed. Share their wording at scoping so the test covers what they ask for.
Authoritative sources
- Federal Register of Legislation — Criminal Code Act 1995, ss 476.2 and 478.1 (Compilation No. 174, 30 June 2026), accessed 2 October 2026
- ASD — Information Security Manual: Guidelines for security assurance (September 2026), accessed 2 October 2026
- ASD — Information Security Manual (ISM), accessed 2 October 2026
- ASD — Essential Eight maturity model (November 2023), accessed 2 October 2026
- OAIC — Chapter 11: APP 11 Security of personal information, accessed 2 October 2026
Request a scoping call
Talk to a senior advisor.
A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.
- 10+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide