Home / Pricing

How pricing works

We publish one price and the structure behind it, rather than a full price list. Packages depend on how many assets you have and which modules you select, so a complete list would either be wrong or so hedged it told you nothing.

The base package

Surface and Perimeter. Surface finds everything you expose and keeps the register current; Perimeter tests what is reachable on it without credentials, including the long jobs a one-week engagement never gets to finish.

$10,000 per year

12-month term, billed annually in advance. AUD, excluding GST. That works out to around $833 a month, though billing is annual rather than monthly.

What arrives each month

  • Validated findings, each reproduced or confirmed by a consultant
  • A written monthly report, including what changed since the last one
  • Critical and high findings notified within one business day of validation
  • Verification of fixes you have applied
  • Portal access for your team throughout
  • A review call once a quarter

The module is bounded by those deliverables rather than by a published number of hours, so the conversation stays on findings rather than timesheets. Fair use is set out in the service agreement.

What drives the price of everything else

Two factors.

How many assets are in scope. A hundred external hosts is not the same job as a hundred web applications, and neither is the same as a hundred API endpoints behind authentication. Because asset counts are not interchangeable, published bands would be misleading.

Which modules you select. The base package is unauthenticated, which is why it can be priced up front. Anything authenticated sits outside it: Network for services, Access for applications and APIs. Authenticated work costs more because it takes longer and needs more consultant judgement, and how much depends entirely on your role model and how much logic sits behind the login.

Every module other than the base package is quoted on your scope, once we understand what is in it. Final pricing is confirmed in a written proposal.

How a package is put together

Surface and Perimeter are mandatory, and they work as a pair: Surface establishes what exists, Perimeter tests what is reachable on it. We cannot test an application we have not discovered, and an unverified asset register is where missed exposure tends to hide.

The other five modules are optional and independent. Add Identity without Cloud, or People without Access, if that matches your risk. Add one later and remove it at the end of a term.

Terms are the same across all of it: a 12-month term, billed annually in advance, all figures in AUD and excluding GST, final pricing confirmed in a written proposal.

Why it costs what it does

The base package is priced against the thing it replaces. A single one-off external penetration test costs about the same amount, once.

An annual penetration test against continuous testing, at the same yearly spend. AUD, excluding GST.
Measure Annual external penetration test Continuous — base package
Testing days per year About 5 365
Time to learn about a new exposure Up to 12 months 1 business day
Covers assets deployed after testing began No Yes
Report accuracy Accurate on the day it was issued Current
Tasks that take weeks to finish, such as password spraying and content discovery Rarely completed inside a one-week test Run to completion
Cost About $10,000 a year About $10,000 a year

A penetration test tells you what was true in March. This tells you what’s true today.

Continuous, not unlimited

One thing worth clarifying: this price buys continuous coverage within a defined asset scope, with the monthly deliverables listed above. It is continuous rather than unlimited.

If your scope grows, the price changes, and we raise that with you in advance. A deep two-week engagement on a single application is a separate piece of work, scoped and quoted on its own.