Best Penetration Testing Companies in Australia: Who Does What in 2026

By Greg Markowski / Sep 11, 2026 / Epic IT News

Search for the best penetration testing companies in Australia and you will find a dozen rankings, most of them written by the company that ranked itself first. This is not that. It is a map of how the Australian pen testing market actually breaks into tiers, who genuinely sits where, and how to pick the right type of provider for your situation. We appear in it, our tier is not the top one for every buyer, and we will tell you plainly when a different firm is the better call.

The stakes justify doing this properly. Australians lodged more than 84,700 cybercrime reports with the ASD in 2024-25, roughly one every six minutes, and the average self-reported cost of an incident for a small business climbed 14 per cent to around $56,600. Penetration testing is how you find the holes before someone else does. Choosing the wrong type of tester is how you pay enterprise prices for a report nobody actions.

The three tiers of the Australian pen testing market

Tier one: enterprise and sovereign-scale firms. These are the providers running thousands of engagements a year for government, critical infrastructure, and the big end of town. CyberCX is the largest in the market, running more than 3,000 penetration tests annually, and its acquisition by Accenture completed in February 2026. Tesserent, trading as Cyber Solutions by Thales since the Thales acquisition in 2023, is the common pick for sovereign, defence, and critical infrastructure scopes. If you are an APRA-regulated entity or a defence supplier with a formal tender, this is your tier.

Tier two: dedicated testing boutiques and research houses. Firms whose entire business is offensive security. elttam in Melbourne is the standout research house, with consultants who publish genuine offensive research. Volkis, Gridware, Sekuro, Intrix, and Borderless CS all operate here, with Intrix notable for treating AI and LLM penetration testing as a core capability and Borderless CS holding accreditation under both CREST bodies. If you need a deep, one-off, high-assurance test of a specific application or environment, and your internal team will handle the remediation, a boutique is usually the right buy.

Tier three: MSP-delivered testing. Managed service providers, including us and firms like StickmanCyber in Sydney, deliver penetration testing inside a broader security relationship. The test is not the product; the outcome is. Findings flow straight into remediation by the same team that manages your environment, and testing recurs on a schedule tied to your compliance obligations rather than as a one-off event. For SMBs pursuing SMB1001 certification (Diamond requires annual penetration testing and social engineering testing) or maintaining Essential Eight evidence, this tier usually delivers more security per dollar than a boutique report that sits in a drawer.

How the main providers compare

Same rules as our Perth cyber security companies guide: every fact below comes from the provider’s own published material or established trade press, checked in September 2026, and where something is not published, we say so rather than guess. These are firms we respect. If anything is out of date, tell us and we will correct it.

Provider Tier Published profile Best suited to
CyberCX Enterprise Largest provider in the market, 3,000+ tests per year, Accenture acquisition completed February 2026 Enterprise, government, large multi-scope programmes
Tesserent (Cyber Solutions by Thales) Enterprise CREST accredited, ISO 27001, part of Thales since 2023 Sovereign, defence, critical infrastructure
elttam Boutique Melbourne research house, consultants publish original offensive research Deep technical testing of high-value applications
Intrix Boutique Australian owned, CREST accredited, ISO 27001, AI and LLM penetration testing as a core service Application, API, and AI system testing
Borderless CS Boutique Accredited under both CREST ANZ and CREST International Regulated sectors where formal CREST accreditation is a procurement requirement
StickmanCyber MSP-delivered Sydney based, testing within a managed security portfolio Businesses wanting testing alongside managed security
Epic IT (us) MSP-delivered Perth HQ since 2003, ISO 27001, Microsoft Solutions Partner, testing with remediation included SMBs needing testing tied to SMB1001 or Essential Eight, with the fixes done, not just reported

Gridware, Volkis, Sekuro, and The Missing Link are also established names in the boutique and mid-market space and belong on any serious shortlist for one-off engagements.

The CREST trap most buyers miss

Here is the detail that catches procurement teams out. CREST International and CREST ANZ are two separate accreditation bodies whose formal relationship ended in 2019. A tender that says “CREST accredited” without specifying which body can mean two different things, and a provider accredited under one is not automatically accredited under the other. Before you shortlist on accreditation, confirm which CREST the requirement actually means, then check the provider’s status with that specific body. A handful of firms hold both; most hold one.

Accreditation also is not the whole story. It tells you the firm’s methodology and data handling have been assessed. It does not tell you whether the report will be actionable for your team, whether anyone will help you fix what is found, or whether the scope was right in the first place. We have onboarded clients holding expensive branded reports full of criticals that sat unremediated for a year because nobody owned the fix.

How to choose the right tier for your business

Ask three questions before you ask for quotes.

Who fixes what the test finds? If you have an internal security team, a boutique’s deep report is exactly what you want. If your IT is outsourced or a two-person team, buy testing from a provider who remediates, because an unactioned finding is a documented liability. That is the core of how we deliver penetration testing services: the engagement ends when the vulnerabilities are closed and retested, not when the PDF lands.

Is this a one-off or a programme? A single pre-audit test suits a boutique engagement. Annual testing tied to SMB1001 Diamond, cyber insurance renewal, or client contractual requirements suits a standing arrangement, where scoping gets faster and cheaper each year because the tester already knows your environment.

What does the budget actually buy? Pricing varies enormously with scope. Our penetration testing cost guide covers the real ranges in AUD, and our testing vs vulnerability scanning comparison explains why a $2,000 “pen test” is usually a scan with a new label. If a quote seems dramatically cheaper than the market, that is the reason.

What you should do now

Work out your tier before you shortlist. Match the three questions above to your situation. Buying from the wrong tier wastes money in both directions: enterprise firms are overkill for a 30-seat business, and an MSP is the wrong buy for an APRA-regulated red team.

Verify accreditation against the specific CREST body your requirement names. Check the provider’s listing with that body directly rather than taking a logo on a website at face value.

Get a scoped comparison. If you are an Australian SMB weighing a boutique report against testing inside a managed security agreement, we will scope both options honestly, including when a boutique is the better call. Contact us on 1300 EPIC IT for a free security gap analysis.

Frequently asked questions

Who are the best penetration testing companies in Australia?

It depends on your tier. Among the best penetration testing companies in Australia, CyberCX and Tesserent (Cyber Solutions by Thales) lead enterprise and sovereign scopes, boutiques like elttam, Intrix, Volkis, Gridware, and Borderless CS lead deep one-off technical testing, and MSP-delivered providers like Epic IT suit SMBs that need testing tied to remediation and compliance frameworks such as SMB1001.

What does CREST accreditation mean and which one do I need?

CREST accredits penetration testing firms’ methodologies, staff qualifications, and data handling. The trap: CREST International and CREST ANZ are separate bodies with no formal relationship since 2019, so a provider accredited under one is not automatically accredited under the other. Check which body your tender, insurer, or regulator means, then verify the provider with that specific body.

How much does penetration testing cost in Australia?

Genuine manual penetration testing typically runs from several thousand dollars for a tightly scoped external test to tens of thousands for broad infrastructure and application engagements. Scope drives everything: the number of IPs, applications, and environments in play. Our 2026 cost guide breaks down the real AUD ranges and what inflates them.

Should an SMB use a boutique pen testing firm or their MSP?

If you have internal security staff to action a deep report, a boutique is a strong buy. If your IT is outsourced, testing from a security-capable MSP usually delivers more, because the same team that finds the vulnerabilities closes them and retests. The worst outcome is the common one: paying for a detailed boutique report that nobody remediates.

Does SMB1001 or the Essential Eight require penetration testing?

SMB1001 requires vulnerability scanning of internet-facing systems from Platinum tier, and Diamond certification requires annual penetration testing and social engineering testing. The Essential Eight does not mandate testing directly, but penetration testing is the standard way to validate that application control, patching, and hardening controls actually work, and auditors and insurers increasingly expect it as evidence.

Weighing up penetration testing providers?

Our Perth-based team will scope your environment honestly, including telling you when a specialist firm is the better fit. Book a free security gap analysis today.

Book a Free Assessment

About the Author
Written by Greg Markowski, Founding Director of Epic IT, a CRN Fast50-recognised Microsoft Solutions Partner managing IT and cybersecurity for Perth businesses since 2003. Greg holds a Degree in Computer Science and a Diploma in Computer Systems Engineering from Edith Cowan University, and is ITIL certified.

Further Reading

Previous

The Essential Eight is 126 of the ISM's 1,143 controls

Return to News
Back to News
Next

The Future of Managed IT Services: The SaaS to AI Paradigm Shift