Website Security Audit
Full penetration testing of your web application, across all ten OWASP Top 10 categories. We test for SQL injection, cross-site scripting, broken logins, server misconfiguration, exposed data and flaws in your business logic. We work in five phases: reconnaissance, scanning, exploitation, post-exploitation and reporting. That is how a real attacker works, so you get a true picture of where you stand. The price is $500 per assessment.
Email Security Audit
A full check of your email setup. We review your SPF, DKIM and DMARC settings, test whether your domain can be spoofed, run a phishing simulation and review how well your mail server is hardened. Email is still the number one way into an Australian business, and 91% of cyber attacks start with a phishing email. We test your defences from the outside in, and find the gaps that would let someone pretend to be you or break into a staff account. The price is $300.
SPF/DKIM/DMARC validation Phishing resilience check Network Perimeter Scan
We test your network from the outside and map everything the internet can see: open ports, exposed services, weak SSL and TLS, DNS mistakes and gaps in your firewall rules. We find services that should never be public, old software with known CVEs, and default passwords that botnets exploit within hours. Our scanners check over 65,000 TCP ports and 1,000 UDP ports on each target. The price is $400.
Full Business Security Assessment
Our biggest package. It covers your website, your email, your network edge, your cloud settings and your internal security policies. It suits an organisation that wants a complete security baseline, or one getting ready for a compliance audit. You get an executive summary, technical findings scored with CVSS, and a fix list in priority order. The full assessment is $1,200, which usually saves over $800 against buying each audit on its own.
Prioritised remediation plan Ongoing Security Monitoring
Automatic scans every quarter that keep watching for new weaknesses, expired certificates, DNS changes, services that have become exposed and fresh threats. Between scans, our AI watches the public vulnerability databases and checks them against the software you actually run. If a new critical flaw hits your systems, you hear within hours. Monitoring starts at $200 per quarter.
Quarterly automated scans Compliance & Risk Assessment
A focused assessment built around the framework you have to meet. That might be APRA CPS 234 for financial services, Essential Eight maturity if you supply government, PCI DSS if you take card payments, or an ISO 27001 gap analysis. We tie every finding straight to a control in that framework, so your compliance team can track fixes without translating anything first.
Framework-aligned testing Audit preparation support