A penetration test describes one moment. Your attack surface keeps moving.

Continuous Offensive Security Testing keeps your external attack surface under test all year. A consultant directs the engagement and does the work that needs judgement, while automation runs the long jobs a one-week test never gets to finish.

The same money, spent differently

An annual penetration test and a year of continuous testing cost about the same. What changes is how long you wait to find out something has been exposed, and which jobs actually get finished. Password spraying has to run slowly to avoid locking accounts out. Content discovery across a large estate takes days per host. Neither finishes inside a testing week, so they get sampled or dropped.

An annual penetration test against continuous testing, at the same yearly spend. AUD, excluding GST.
Measure Annual external penetration test Continuous — base package
Testing days per year About 5 365
Time to learn about a new exposure Up to 12 months 1 business day
Covers assets deployed after testing began No Yes
Report accuracy Accurate on the day it was issued Current
Tasks that take weeks to finish, such as password spraying and content discovery Rarely completed inside a one-week test Run to completion
Cost About $10,000 a year About $10,000 a year

A penetration test tells you what was true in March. This tells you what’s true today.

How pricing works

Agents for coverage, humans for judgement and control

The service is never agent-only, and it is never purely manual. Agents provide coverage at a scale and frequency a human team could not sustain. Consultants direct the testing, do the work that requires judgement, and validate every finding. Humans also define and enforce the boundaries the agents operate within, which makes oversight a safety control and not only a quality control.

What the tooling handles

  • Keeps discovery and enumeration running across every in-scope asset
  • Surfaces change and new exposure between consultant passes
  • Repeats the mechanical checks at a frequency manual work cannot sustain
  • Stays inside the scope a consultant has set, and never acts outside it

What our consultants do

  • Run the testing: reconnaissance, exploitation, and chaining findings into attack paths
  • Decide where to dig deeper, and what actually matters to your business
  • Define the scope and configure the boundaries the tooling runs within
  • Confirm every finding, then write and sign the report

How the work is carried out, phase by phase

Start with a penetration test

Most clients come to us for a scoped engagement first: a web application, an API, a cloud environment, a mobile app. That is a good way to see how we work before committing to anything longer, and it is often what an auditor or a customer is asking you for.

Once the report is delivered, the external estate is usually the part that keeps moving. That is the point at which continuous coverage starts to make sense.

Seven modules, assembled to your environment

Surface and Perimeter form the base package: one finds what you expose, the other tests it. The other five are added or removed independently.

Where the service stops

Coverage is continuous within a defined asset scope, with a defined set of monthly deliverables. A few things sit outside it, and they are worth knowing up front.

  • It is not a replacement for deep point-in-time testing of a complex application.
  • It is not intrusion detection, and it is not incident response.
  • It does not remediate findings. We report and verify fixes; your team applies them.
  • It reduces the time an exposure goes unnoticed. It cannot guarantee you will not be compromised.
  • It is not monitored around the clock. Notification targets are set in business days.

How the service works in detail

Where to start

The base package covers external discovery and network testing for about $10,000 a year, billed annually. Other modules are quoted on your scope. We verify domain ownership and written authorisation before testing begins, so the first step is a conversation.