What is penetration testing, and do you need it?
A pen test is hiring someone to break in on purpose and write down how they did it. Genuinely valuable: and for most small businesses, not the thing to spend money on first.
// overview
Breaking in, with permission and a report.
Penetration testing means paying a specialist to attack your systems the way an attacker would, under a written agreement on scope. You get a report: what they got into, how, and what to fix first.
The value is that it tests reality rather than intentions. Plenty of organisations believe they're secure because the right products are installed. A test finds the forgotten server, the admin password nobody changed, the staff portal reachable from the open internet.
It's a real discipline, and the good practitioners are worth every cent. We're going to spend the rest of this page explaining why you probably shouldn't buy one yet.
// the distinction
A scan is not a pen test.
- 01
Vulnerability scan
Automated. Software checks your systems against a database of known weaknesses and produces a list. Cheap, fast, and worth running regularly. It tells you what might be a problem.
- 02
Penetration test
Human. A skilled person chains findings together, tries things a scanner can't, and demonstrates actual impact. Expensive, slow, and far more useful. It tells you what someone could actually do.
- 03
Red team exercise
Broader still. Includes social engineering, physical entry and long-running stealth, testing whether you'd even notice. Genuinely valuable for large organisations, and thorough overkill for a business with eight staff.
// the honest answer
Do you need one?
If you're a Toowoomba trade business, a small practice or a shop with a handful of computers: almost certainly not yet. Pen tests find sophisticated weaknesses. What actually catches businesses your size is unsophisticated, reused passwords, missing MFA, no backup, someone who clicked a link.
Buying one before fixing those is commissioning a structural survey while the front door stands open. The report will be accurate, and you'll have spent thousands learning what a health-check finds for a fraction of it.
Consider one when all of the following are honestly true:
- MFA is on across email and every critical system, for everyone
- You have backups you've actually restored from in a test
- Someone is responsible for applying updates, and it's genuinely happening
- Staff have had practical security training in the last year
- You're handling sensitive customer data, or a contract or insurer requires a test
- You have the budget and appetite to act on the findings: an unread report is money burnt
// what we'd suggest
Start with a health-check instead.
For most businesses our size, the sensible first step is a security health-check: we review your accounts, devices, backups and network, then hand you a plain-English list of what's exposed and what to fix first.
It costs a fraction of a pen test and finds the things that actually get people. If it comes back clean and you're still concerned (or a contract demands testing) that's the right moment, and we'll point you at specialists who do it properly.
We'd rather say that than sell you something you don't need. Same reason we'll tell you when a laptop isn't worth repairing.
// questions
Good questions, straight answers.
How much does a penetration test cost in Australia?
For a small business scope, typically several thousand dollars and up, depending on how much is being tested. Anyone offering a "pen test" for a few hundred is almost certainly running an automated scan and relabelling it.
How often should one be done?
Organisations that need them typically test annually, and after any significant change to systems or infrastructure. There's little point testing a system you're about to replace.
What's a security health-check, exactly?
We review your accounts, devices, backups, network and current settings, and produce a prioritised, plain-English list: what's exposed, how bad it is, and what to do first. No jargon, no scare tactics, and no obligation to have us do the fixing.
Our insurer is asking about penetration testing. What do we tell them?
Read the wording carefully, many policies ask about vulnerability management and MFA rather than pen testing specifically. Happy to go through the questionnaire with you; they're often more answerable than they first appear.
$ inspyred --book-a-callout
Got a question about this?
Ask a human.
Give us a call, text or email, we're available by appointment, 7 days a week. A rough idea on the phone is always free.