What is penetration testing, and do you need it?

A pen test is hiring someone to break in on purpose and write down how they did it. Genuinely valuable: and for most small businesses, not the thing to spend money on first.

// overview

Breaking in, with permission and a report.

Penetration testing means paying a specialist to attack your systems the way an attacker would, under a written agreement on scope. You get a report: what they got into, how, and what to fix first.

The value is that it tests reality rather than intentions. Plenty of organisations believe they're secure because the right products are installed. A test finds the forgotten server, the admin password nobody changed, the staff portal reachable from the open internet.

It's a real discipline, and the good practitioners are worth every cent. We're going to spend the rest of this page explaining why you probably shouldn't buy one yet.

// the distinction

A scan is not a pen test.

// the honest answer

Do you need one?

If you're a Toowoomba trade business, a small practice or a shop with a handful of computers: almost certainly not yet. Pen tests find sophisticated weaknesses. What actually catches businesses your size is unsophisticated, reused passwords, missing MFA, no backup, someone who clicked a link.

Buying one before fixing those is commissioning a structural survey while the front door stands open. The report will be accurate, and you'll have spent thousands learning what a health-check finds for a fraction of it.

Consider one when all of the following are honestly true:

// what we'd suggest

Start with a health-check instead.

For most businesses our size, the sensible first step is a security health-check: we review your accounts, devices, backups and network, then hand you a plain-English list of what's exposed and what to fix first.

It costs a fraction of a pen test and finds the things that actually get people. If it comes back clean and you're still concerned (or a contract demands testing) that's the right moment, and we'll point you at specialists who do it properly.

We'd rather say that than sell you something you don't need. Same reason we'll tell you when a laptop isn't worth repairing.

// questions

Good questions, straight answers.

How much does a penetration test cost in Australia?

For a small business scope, typically several thousand dollars and up, depending on how much is being tested. Anyone offering a "pen test" for a few hundred is almost certainly running an automated scan and relabelling it.

How often should one be done?

Organisations that need them typically test annually, and after any significant change to systems or infrastructure. There's little point testing a system you're about to replace.

What's a security health-check, exactly?

We review your accounts, devices, backups, network and current settings, and produce a prioritised, plain-English list: what's exposed, how bad it is, and what to do first. No jargon, no scare tactics, and no obligation to have us do the fixing.

Our insurer is asking about penetration testing. What do we tell them?

Read the wording carefully, many policies ask about vulnerability management and MFA rather than pen testing specifically. Happy to go through the questionnaire with you; they're often more answerable than they first appear.

$ inspyred --book-a-callout

Got a question about this?
Ask a human.

Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.

Hours
By Appointment · 7 days
Service area
Toowoomba & the Darling Downs
Service style
Mobile: we come to you