CyberGrape – cyber security certification and GRC platform for small business

A · Pentesting

Find out how someone gets in, before they do.

Penetration testing for Australian businesses, delivered through a platform where you watch findings appear in real time, hand them straight to your developers, and retest a fix the same day it ships. The testing is done by CREST-certified consultants at Blacklock, our specialist testing partner. The scoping, the translation into business risk and the follow-through are ours.

See what a test covers
Testing delivered by Blacklock Security, CREST-certifiedOWASP-aligned methodologyISO 27001:2022 certified testing partnerPenetration test certificate included

Most businesses only think about a pen test when someone asks for one.

A customer or insurer is asking for evidence

A big client sends through a security questionnaire. Your insurer wants to know when you last tested. The contract sits there waiting on an answer you do not have yet. A test that drags on for six weeks costs you the deal.

Your last report is already out of date

Annual testing gives you a snapshot of one Tuesday in March. You have shipped forty releases since. The report is a PDF in a shared drive, the findings got copied into a spreadsheet, and nobody is quite sure which ones were actually fixed.

You cannot tell what is exposed right now

Subdomains spun up for a campaign and never taken down. An old admin interface still answering on the internet. A dependency with a known flaw buried three layers into your build. None of it shows up until someone goes looking.

Testing that keeps running after the report lands.

Penetration testing is a controlled attack on your own systems. Skilled testers try to break in the way a real attacker would, then write down exactly how they did it and what to do about it.

The traditional version is a one-off exercise ending in a long document. We deliver it as a service instead, through the Blacklock platform. Automated scanning runs continuously across your web applications, APIs and infrastructure. On top of that, CREST-certified consultants do the manual work that tools cannot: business logic abuse, broken access control, chaining small weaknesses into a real attack path.

Findings land in a dashboard as they are confirmed, so your team starts fixing on day two instead of week six. Each one can go straight to Jira, Azure DevOps, GitHub or GitLab as a ticket with remediation code attached. When a developer pushes a fix, they trigger a retest on that specific vulnerability and get an answer without waiting for anyone.

You finish with three reports and a penetration test certificate you can send to the customer who asked.

How this differs from a traditional pen test.

When you see findings

Traditional pen testOn delivery, weeks later
Testing with CyberGrapeLive, as each one is confirmed

What you receive

Traditional pen testOne long PDF
Testing with CyberGrapeExecutive, developer and full technical reports, plus a test certificate

Remediation

Traditional pen testYour team transcribes it into a spreadsheet
Testing with CyberGrapeOne-click tickets into Jira, Azure DevOps, GitHub, GitLab or Bitbucket

Retesting a fix

Traditional pen testEmail the tester, book time, wait
Testing with CyberGrapeYour developer triggers it and gets the result

Between tests

Traditional pen testNothing
Testing with CyberGrapeContinuous automated scanning of your attack surface

Cost model

Traditional pen testQuoted per engagement, every time
Testing with CyberGrapeSubscription plus scoped manual testing

Who owns the outcome

Traditional pen testThe report is the end of it
Testing with CyberGrapeWe stay across remediation and report progress to your board

What we can put under test.

Web applications and APIs

Authenticated and unauthenticated, including REST APIs and single page applications.

Infrastructure

External perimeter and internal networks, reached through a zero configuration VPN so no hardware is needed.

Cloud environments

AWS, Azure and Google Cloud configuration and exposure.

Mobile applications

iOS and Android, tested across the app, its APIs and its storage.

AI applications

Chatbots, copilots, agents and MCP tool workflows.

Source code (SAST)

Static analysis across 30 or more languages, wired into your CI/CD pipeline.

Software bill of materials

Every library and dependency checked for known flaws and licence problems, exportable as CycloneDX or SPDX.

Continuous vulnerability assessment

Scheduled and on demand scanning, with alerts into Slack or Teams when something changes.

If you have shipped something with AI in it, it has a new attack surface.

An AI feature accepts untrusted language, pulls in sensitive context, calls tools and sometimes acts on a user's behalf. Traditional application testing was never designed to look at any of that.

Testing here covers prompt injection, both direct and indirect. System prompt extraction. Sensitive data leaking through model output. Poisoning of the documents your retrieval pipeline trusts. For agents and MCP integrations it goes further: tool poisoning, exposed tokens and secrets, command injection through a tool that accepts a URL, unauthorised tool invocation, and whether the model can be talked into an action a human was supposed to approve.

The methodology is aligned to the OWASP Top 10 for large language models, the OWASP MCP Top 10 and MITRE ATLAS. Conventional application, API and infrastructure testing runs alongside it, because an AI feature still sits on ordinary authentication and authorisation that can be broken in ordinary ways.

Three reports, one certificate, no interpretation required.

Executive report

What was found, what it means commercially, what happens next. Written to be read by people who do not work in security.

Developer report

Each finding with steps to reproduce, evidence, remediation code for your stack, and references.

Full technical report

The complete engagement record, OWASP-aligned, suitable for an auditor or a due diligence request.

Penetration test certificate

The artefact your customer, insurer or procurement team actually asked for.

The controls that put you here.

If a framework brought you to this page, here is exactly which part of it is asking for testing, and what satisfies it. We work with both of these standards every week, so scoping against the specific control is straightforward rather than guesswork.

SMB1001:2026

Level 4, control 1.7.0.1, vulnerability scanning of internet-facing resources. Continuous scanning of your external attack surface satisfies this, and it runs year round rather than as a point-in-time exercise.

Level 5, control 1.11.0.0, penetration, vulnerability and social engineering testing. This one is specific. The test must be conducted by an external provider, at least once every year, and it must assess your workforce as well as your technology, covering phishing, vishing and physical security.

Worth being clear about something most providers will not tell you: a penetration test on its own does not close 1.11.0.0. The social engineering half has to be evidenced too. We cover that side through our human risk management service, which runs phishing simulation and awareness testing, so the two halves of the control are evidenced together rather than leaving a gap your assessor finds later.

Both Level 4 and Level 5 require third-party assessment by an accredited DSC, so the evidence needs to hold up to someone else's review.

ISO/IEC 27001:2022

The standard does not use the words penetration test in the Annex A control text. The ISO 27002 implementation guidance does, and auditors expect to see it. Three controls are in play:

  • A.8.8 Management of technical vulnerabilities. Expects a running vulnerability management programme with regular scanning of internet-facing systems, severity-based remediation timelines and findings tracked to closure. Guidance points to penetration testing at least annually for significant systems.
  • A.8.29 Security testing in development and acceptance. Expects security testing built into the delivery process rather than bolted on: static analysis, dynamic testing, component analysis, and penetration testing for significant systems, with security acceptance criteria enforced before go-live.
  • A.5.36 Compliance with policies, rules and standards. Technical compliance checks, including vulnerability scans and penetration tests, with results documented.

Static analysis in your pipeline also supports A.8.28 Secure coding, which is useful if your development process is where your auditor has been pushing.

Testing also supports evidence requirements under SOC 2, PCI DSS, HIPAA and GDPR.

If you are already working with us on compliance, findings flow into CyberGrape GRC, our own platform, so the control, the evidence and the remediation status sit in one place instead of across three email threads.

Blacklock does the testing. We make sure it lands.

We are open about how this works, because we write it the same way into every statement of work. Blacklock Security runs the testing, on its own CREST-certified platform, with consultants holding CREST, OSCP, OSWE, OSCE, CISSP and CEH certifications. CyberGrape Pty Ltd holds the commercial relationship with you and stays accountable for the outcome.

That middle part matters more than it sounds. Scoping is where most pen tests go wrong, either paying to test things that do not matter or leaving out the one system that does. We scope against your actual risk and the control you are trying to satisfy, not a price list.

Then there is everything after the report. A list of forty findings is only useful if someone decides what gets fixed first, argues the case for the budget, chases it through your development team or your managed service provider, and explains it to your board in language that makes sense. That is the work we do as your virtual CISO, and it is the reason a test bought through us tends to end with things actually fixed.

One contract, one invoice, one person to call. Specialist capability without the specialist procurement exercise.

Tower Insurance

Tower is an insurer operating across Australia and New Zealand, and a long-standing CyberGrape client. We introduced Tower to Blacklock, scoped the engagements, and Tower has run its penetration testing through us ever since, including REST API and web application testing delivered on the Blacklock platform. The same relationship also covers third-party cyber risk monitoring. It is a fair picture of how this service works in practice: we hold the relationship and the scoping, the specialist platform does the testing, and the client deals with one party throughout.

"CyberGrape has been an excellent partner to us. Providing excellent niche products backed with great service."

Darren Beattie, Head of Information Security, Tower InsuranceGoogle review

Tower Insurance, ANZ general insurer. Penetration testing and third-party cyber risk monitoring delivered through CyberGrape since 2023.

Powered byBlacklock
CREST-certified penetration testing
ISO 27001:2022 certified
Testers hold CREST, OSCP, OSWE, OSCE, CISSP and CEH
Testing methodology aligned to OWASP, PTES and OSSTMM
150+
customers
1,000+
tests performed
120,000+
vulnerabilities reported
48,656
hours saved through PTaaS delivery
99%
customer happiness index

Blacklock platform figures, as published by Blacklock Security

CyberGrape credentials
Winner, New Zealand Reseller News Innovation Awards 2023
Finalist, ARN Innovation Awards 2026, Australia
4.8+ Google rating
Clients across Australia, New Zealand and beyond

Common questions.

Find out what a test would actually cover.

A scoping call takes about thirty minutes. We will tell you what is worth testing, what is not, and what it costs. If the answer is that you need something else first, we will tell you that too.

See all services

Services contracted through CyberGrape Pty Ltd (Australia). Penetration testing delivered by Blacklock Security Limited.