Produce credible technical evidence for client, audit and assurance requirements.
OSCP-led external, internal, web, API and Active Directory testing — a clear report with an executive summary, a testing summary and retest-status letter, and one agreed retest so you can evidence the fix.
- 15+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide
You walk away with
- Scoped test: external, internal, web app, API or Active Directory (agreed test type)
- Report with an executive summary — findings, business impact, clear remediation
- Testing summary and retest-status letter to support client, insurer and tender evidence requests (acceptance remains subject to the requesting organisation's own requirements)
- Prioritised remediation guidance your team can action
Is this you?
You're probably here because…
If one of these is true, this may be the right starting engagement — with senior attention, not junior hand-offs.
A client or tender requires an independent penetration test before they'll sign.
You're launching an application and need assurance before it's exposed.
Your cyber insurer or board wants evidence, not just a vulnerability scan.
You want hands-on manual testing by an OSCP-certified practitioner, not an automated scan presented as a penetration test.
What you get
Executive-ready deliverables, in business language
No 200-page data dump. Everything is prioritised and written to be acted on, with indicative effort, dependencies and cost ranges where supportable.
- Scoped test: external, internal, web app, API or Active Directory (agreed test type)
- Report with an executive summary — findings, business impact, clear remediation
- Testing summary and retest-status letter to support client, insurer and tender evidence requests (acceptance remains subject to the requesting organisation's own requirements)
- Prioritised remediation guidance your team can action
- One agreed retest included to verify and evidence the fix
Productised package
Penetration Test & Retest
Scoped after a 20-minute call. External from $9,000; internal, web, API and AD scoped to match. Report with an executive summary, a testing summary and retest-status letter, and one agreed retest.
$9,000
from · ex GST
2–3 weeks
typical timeline
How it works
A clear, documented method
Every engagement starts with written authorisation and a defined scope. Here's the path from start to deliverable.
- 01
Scope & authorise
Define targets, rules of engagement and limits. Written authorisation-to-test signed before any activity — every time.
- 02
Test
Tool-assisted discovery supports the engagement, while validation, exploitation and attack-path analysis are performed manually within the agreed scope.
- 03
Report
Findings rated by real business impact, with reproduction steps and pragmatic remediation. Written for executives as well as engineers.
- 04
Retest
Once remediation is complete, the included retest checks the agreed findings and supports an updated testing summary and retest-status letter.
Service terms
Clear terms, inclusions and boundaries
What's included, how it's billed, and what this service is — and isn't.
Authorisation & scope
- Written authorisation to test is signed before any activity begins.
- In-scope systems, exclusions, testing dates and permitted windows are defined and agreed in advance.
- Emergency contacts and a stop-work procedure are agreed before testing starts.
- Each engagement covers only the agreed test type and scope.
How we test safely
- Production-safety controls are applied throughout.
- Tool-assisted discovery supports the engagement; validation, exploitation and attack-path analysis are performed manually within the agreed scope.
- Findings are rated using a defined severity methodology.
- Denial-of-service testing is excluded unless expressly authorised; social engineering is excluded unless expressly scoped.
Reporting & retest
- Evidence is handled securely and the report is delivered encrypted.
- Report and evidence are retained for a defined retention period, then securely destroyed.
- One agreed retest is included, within a defined retest-eligibility period.
- The testing summary and retest-status letter records the agreed scope, dates and retest status at that point in time. It is not a certification, does not guarantee security or the absence of vulnerabilities, and does not guarantee insurer, client, auditor or tender acceptance.
Why CyberByte
Principal consultant-led delivery backed by 15+ years across infrastructure, cloud and cyber security in Australian enterprise and government environments.
FAQ
Questions buyers ask
Still unsure? A scoping call answers the rest in 20 minutes.
No. A scan finds known issues a tool can detect. A penetration test is manual, OSCP-led work that chains weaknesses together the way a real attacker would — the findings that actually matter. We run both; the value is in the human part.
Yes, always. One agreed retest is built into the scope so you can evidence that findings are closed, which supports an updated testing summary and retest-status letter for your client or insurer.
Every engagement has written authorisation-to-test, defined rules of engagement, scope limits and liability caps before any testing begins. Unauthorised or out-of-scope testing is never on the table.
Related services
Relevant industries
Not sure this is the right starting point?
Tell us what's prompting this and we'll recommend the smallest credible engagement.
Request a scoping callFree resource
Where do you actually stand?
Get the plain-English checklist we use to gauge readiness before an assessment. Five minutes, no jargon, no obligation.
Cyber Insurance Readiness Checklist
We'll email it straight away. Unsubscribe anytime.
Request a scoping call
Talk to a senior advisor — not a salesperson.
A 20-minute scoping call: tell us what's prompting this, and we'll tell you the smallest credible engagement that solves it. Fixed price for the agreed scope, no obligation.
- 15+ years across IT, cloud & cyber
- Enterprise & government experience
- Principal consultant-led delivery
- Independent & Australian-owned
- Melbourne-based · Australia-wide