A · Pentesting
Find out how someone gets in, before they do.
Penetration testing for Australian businesses, delivered through a platform where you watch findings appear in real time, hand them straight to your developers, and retest a fix the same day it ships. The testing is done by CREST-certified consultants at Blacklock, our specialist testing partner. The scoping, the translation into business risk and the follow-through are ours.
Most businesses only think about a pen test when someone asks for one.
A customer or insurer is asking for evidence
A big client sends through a security questionnaire. Your insurer wants to know when you last tested. The contract sits there waiting on an answer you do not have yet. A test that drags on for six weeks costs you the deal.
Your last report is already out of date
Annual testing gives you a snapshot of one Tuesday in March. You have shipped forty releases since. The report is a PDF in a shared drive, the findings got copied into a spreadsheet, and nobody is quite sure which ones were actually fixed.
You cannot tell what is exposed right now
Subdomains spun up for a campaign and never taken down. An old admin interface still answering on the internet. A dependency with a known flaw buried three layers into your build. None of it shows up until someone goes looking.
Testing that keeps running after the report lands.
Penetration testing is a controlled attack on your own systems. Skilled testers try to break in the way a real attacker would, then write down exactly how they did it and what to do about it.
The traditional version is a one-off exercise ending in a long document. We deliver it as a service instead, through the Blacklock platform. Automated scanning runs continuously across your web applications, APIs and infrastructure. On top of that, CREST-certified consultants do the manual work that tools cannot: business logic abuse, broken access control, chaining small weaknesses into a real attack path.
Findings land in a dashboard as they are confirmed, so your team starts fixing on day two instead of week six. Each one can go straight to Jira, Azure DevOps, GitHub or GitLab as a ticket with remediation code attached. When a developer pushes a fix, they trigger a retest on that specific vulnerability and get an answer without waiting for anyone.
You finish with three reports and a penetration test certificate you can send to the customer who asked.
How this differs from a traditional pen test.
| Traditional pen test | Testing with CyberGrape | |
|---|---|---|
| When you see findings | On delivery, weeks later | Live, as each one is confirmed |
| What you receive | One long PDF | Executive, developer and full technical reports, plus a test certificate |
| Remediation | Your team transcribes it into a spreadsheet | One-click tickets into Jira, Azure DevOps, GitHub, GitLab or Bitbucket |
| Retesting a fix | Email the tester, book time, wait | Your developer triggers it and gets the result |
| Between tests | Nothing | Continuous automated scanning of your attack surface |
| Cost model | Quoted per engagement, every time | Subscription plus scoped manual testing |
| Who owns the outcome | The report is the end of it | We stay across remediation and report progress to your board |
When you see findings
What you receive
Remediation
Retesting a fix
Between tests
Cost model
Who owns the outcome
What we can put under test.
Web applications and APIs
Authenticated and unauthenticated, including REST APIs and single page applications.
Infrastructure
External perimeter and internal networks, reached through a zero configuration VPN so no hardware is needed.
Cloud environments
AWS, Azure and Google Cloud configuration and exposure.
Mobile applications
iOS and Android, tested across the app, its APIs and its storage.
AI applications
Chatbots, copilots, agents and MCP tool workflows.
Source code (SAST)
Static analysis across 30 or more languages, wired into your CI/CD pipeline.
Software bill of materials
Every library and dependency checked for known flaws and licence problems, exportable as CycloneDX or SPDX.
Continuous vulnerability assessment
Scheduled and on demand scanning, with alerts into Slack or Teams when something changes.
If you have shipped something with AI in it, it has a new attack surface.
An AI feature accepts untrusted language, pulls in sensitive context, calls tools and sometimes acts on a user's behalf. Traditional application testing was never designed to look at any of that.
Testing here covers prompt injection, both direct and indirect. System prompt extraction. Sensitive data leaking through model output. Poisoning of the documents your retrieval pipeline trusts. For agents and MCP integrations it goes further: tool poisoning, exposed tokens and secrets, command injection through a tool that accepts a URL, unauthorised tool invocation, and whether the model can be talked into an action a human was supposed to approve.
The methodology is aligned to the OWASP Top 10 for large language models, the OWASP MCP Top 10 and MITRE ATLAS. Conventional application, API and infrastructure testing runs alongside it, because an AI feature still sits on ordinary authentication and authorisation that can be broken in ordinary ways.
Three reports, one certificate, no interpretation required.
Executive report
What was found, what it means commercially, what happens next. Written to be read by people who do not work in security.
Developer report
Each finding with steps to reproduce, evidence, remediation code for your stack, and references.
Full technical report
The complete engagement record, OWASP-aligned, suitable for an auditor or a due diligence request.
Penetration test certificate
The artefact your customer, insurer or procurement team actually asked for.
The controls that put you here.
If a framework brought you to this page, here is exactly which part of it is asking for testing, and what satisfies it. We work with both of these standards every week, so scoping against the specific control is straightforward rather than guesswork.
SMB1001:2026
Level 4, control 1.7.0.1, vulnerability scanning of internet-facing resources. Continuous scanning of your external attack surface satisfies this, and it runs year round rather than as a point-in-time exercise.
Level 5, control 1.11.0.0, penetration, vulnerability and social engineering testing. This one is specific. The test must be conducted by an external provider, at least once every year, and it must assess your workforce as well as your technology, covering phishing, vishing and physical security.
Worth being clear about something most providers will not tell you: a penetration test on its own does not close 1.11.0.0. The social engineering half has to be evidenced too. We cover that side through our human risk management service, which runs phishing simulation and awareness testing, so the two halves of the control are evidenced together rather than leaving a gap your assessor finds later.
Both Level 4 and Level 5 require third-party assessment by an accredited DSC, so the evidence needs to hold up to someone else's review.
ISO/IEC 27001:2022
The standard does not use the words penetration test in the Annex A control text. The ISO 27002 implementation guidance does, and auditors expect to see it. Three controls are in play:
- A.8.8 Management of technical vulnerabilities. Expects a running vulnerability management programme with regular scanning of internet-facing systems, severity-based remediation timelines and findings tracked to closure. Guidance points to penetration testing at least annually for significant systems.
- A.8.29 Security testing in development and acceptance. Expects security testing built into the delivery process rather than bolted on: static analysis, dynamic testing, component analysis, and penetration testing for significant systems, with security acceptance criteria enforced before go-live.
- A.5.36 Compliance with policies, rules and standards. Technical compliance checks, including vulnerability scans and penetration tests, with results documented.
Static analysis in your pipeline also supports A.8.28 Secure coding, which is useful if your development process is where your auditor has been pushing.
Testing also supports evidence requirements under SOC 2, PCI DSS, HIPAA and GDPR.
If you are already working with us on compliance, findings flow into CyberGrape GRC, our own platform, so the control, the evidence and the remediation status sit in one place instead of across three email threads.
Blacklock does the testing. We make sure it lands.
We are open about how this works, because we write it the same way into every statement of work. Blacklock Security runs the testing, on its own CREST-certified platform, with consultants holding CREST, OSCP, OSWE, OSCE, CISSP and CEH certifications. CyberGrape Pty Ltd holds the commercial relationship with you and stays accountable for the outcome.
That middle part matters more than it sounds. Scoping is where most pen tests go wrong, either paying to test things that do not matter or leaving out the one system that does. We scope against your actual risk and the control you are trying to satisfy, not a price list.
Then there is everything after the report. A list of forty findings is only useful if someone decides what gets fixed first, argues the case for the budget, chases it through your development team or your managed service provider, and explains it to your board in language that makes sense. That is the work we do as your virtual CISO, and it is the reason a test bought through us tends to end with things actually fixed.
One contract, one invoice, one person to call. Specialist capability without the specialist procurement exercise.

Tower is an insurer operating across Australia and New Zealand, and a long-standing CyberGrape client. We introduced Tower to Blacklock, scoped the engagements, and Tower has run its penetration testing through us ever since, including REST API and web application testing delivered on the Blacklock platform. The same relationship also covers third-party cyber risk monitoring. It is a fair picture of how this service works in practice: we hold the relationship and the scoping, the specialist platform does the testing, and the client deals with one party throughout.
"CyberGrape has been an excellent partner to us. Providing excellent niche products backed with great service."
Tower Insurance, ANZ general insurer. Penetration testing and third-party cyber risk monitoring delivered through CyberGrape since 2023.

Blacklock platform figures, as published by Blacklock Security
Common questions.
Penetration testing is a controlled, authorised attack on your own systems, carried out by security specialists to find weaknesses before a real attacker does. Unlike an automated scan, a penetration test includes manual work: a human tester chains small weaknesses together to see how far into your business they can get.
PTaaS, or penetration testing as a service, delivers testing through a subscription platform rather than as a one-off project. You get continuous automated scanning year round, manual expert testing when you need it, findings in a live dashboard instead of a PDF, and retesting on demand when a fix is deployed.
Only half of it. Control 1.11.0.0 requires an annual external penetration and vulnerability test, and it also requires assessment of your workforce against social engineering, covering phishing, vishing and physical security. Both halves need evidence. We cover the technical testing through Blacklock and the social engineering side through our human risk management service.
ISO/IEC 27001:2022 does not name penetration testing in the Annex A control text, but the ISO 27002 guidance for A.8.8 and A.8.29 points directly at it, and auditors expect to see testing for significant systems at least annually, with findings tracked through to closure.
At minimum once a year, and after any significant change to your systems. If you release software regularly, continuous scanning between annual manual tests closes the gap that annual-only testing leaves open.
Most engagements run from a few days to two weeks depending on how many applications, user roles and integrations are in scope. Findings appear as they are confirmed, so remediation starts before the engagement finishes.
No. Testing is scoped and scheduled with you in advance, with agreed rules of engagement and windows for anything intrusive. Destructive testing is out of scope unless you specifically ask for it in an isolated environment.
Blacklock Security, our specialist testing partner, using CREST-certified consultants and its own PTaaS platform. CyberGrape scopes the engagement, holds the commercial relationship, and manages the work that follows the report. We name our partner openly rather than white-labelling the service.
Yes. Every penetration test finishes with a certificate, alongside an executive report, a developer report and a full technical report. The certificate is what most procurement teams and insurers are asking for.
Penetration testing is priced on the size and complexity of what is being tested, so it is scoped before it is quoted. A scoping call takes about thirty minutes and ends with a fixed price and a clear statement of what is in and out of scope.
Yes. AI applications, LLM integrations, agents, RAG pipelines and MCP tool workflows can all be tested, covering prompt injection, data leakage, unsafe tool use and excessive agency, alongside the conventional application and API testing underneath.
No. We test, report and prioritise. Your IT provider or development team fixes. We can manage that handover and verify the fixes, which usually works better than asking a provider to assess its own work.
Find out what a test would actually cover.
A scoping call takes about thirty minutes. We will tell you what is worth testing, what is not, and what it costs. If the answer is that you need something else first, we will tell you that too.
Services contracted through CyberGrape Pty Ltd (Australia). Penetration testing delivered by Blacklock Security Limited.

