Skip to main content
Service

Penetration testing — scoped properly, and remediated afterwards

A test is only worth what you do with the report. We scope the engagement, coordinate specialist testers, and then actually fix what they find.

16+ years

Brisbane-based since 2010

1,500+

Employees supported across SEQ

Named engineers

The same team every time

Essential Eight aligned

Microsoft Partner

Penetration test scoping, coordination with specialist testers, and — the part that matters — remediation of what the report finds.

Do you need one?

This is worth asking before spending the money, because a large share of businesses requesting a penetration test are trying to answer a question a test does not answer.

If nobody has ever scanned your environment, start there. A vulnerability assessment finds missing patches, exposed services and weak configurations quickly and cheaply. Paying a skilled tester to spend a week discovering that your firewall firmware is three years old is a very expensive way to learn something a scan reports in an hour.

If a customer or insurer has asked for a penetration test by name, you need the real thing, and the scope should be whatever satisfies their requirement.

If you have done the basics and want to know whether they hold, that is exactly what a test is for, and it will produce useful findings.

If you want to know your overall security maturity, an Essential Eight assessment answers that question better and costs less.

Scope determines everything

An unscoped test produces a report nobody can act on. The engagement needs to specify what is being tested and from what position:

External — what an attacker on the internet can reach and do, with no credentials.

Internal — what someone who is already inside can reach, whether that is a compromised workstation, a guest network connection or a contractor.

Microsoft 365 tenant — configuration, identity, conditional access and privilege paths. For a cloud-first business this is frequently the highest-value scope and the least often tested.

Application — a specific web application, its authentication and its authorisation logic.

Each answers a different question and they price differently. Choosing on the basis of what you actually need to know is the difference between a useful engagement and an expensive one.

Why we do not test our own work

We scope, coordinate and remediate. The testing is performed by specialist penetration testing providers.

This is deliberate. Offensive security is its own discipline and the people who are good at it do it full time. More importantly, a provider assessing infrastructure it configured itself is not conducting an independent test — the blind spots in the build are the blind spots in the assessment.

That does cost you the convenience of a single vendor, and it is worth knowing that is the trade we have chosen.

The report is the beginning

The most common failure in penetration testing has nothing to do with the test. It is that the report arrives, gets circulated, and nothing happens. Twelve months later the same engagement produces largely the same findings.

The remediation is the value. We take the findings, triage them by actual exploitability and business impact rather than by the severity label, work through them, and arrange a retest to verify closure — which is also what a customer asking for evidence actually wants to see.

What you get with JTIT

Concrete deliverables, not vague promises.

Scoped to answer a real question

External perimeter, internal network, Microsoft 365 tenant, or a specific application. A vague scope produces a vague report and wasted money.

The right kind of test

Most businesses asking for a penetration test actually need a vulnerability assessment first. Testing a network you have not patched is an expensive way to be told to patch.

Findings that get fixed

A report in a drawer changes nothing. We take the findings into a remediation plan and do the work, which is the part most testing engagements never reach.

Independent testers

Testing is coordinated with specialist providers rather than marked by us. Assessing our own configuration work would not be a meaningful test.

Retest to close the loop

Remediation verified by retest, so you can demonstrate the finding is actually closed rather than reported as addressed.

Evidence for tenders and insurers

Increasingly requested by enterprise customers and on cyber insurance applications, and it needs to be a real engagement with a real report.

How it works

A predictable, no-surprises process.

  1. 01

    Decide what you actually need

    An honest conversation about whether a penetration test is the right instrument, or whether a vulnerability assessment or Essential Eight review answers the question more cheaply.

  2. 02

    Scope and authorise

    Targets, methods, timing, and rules of engagement agreed in writing. Testing without written authorisation is not something anyone should do.

  3. 03

    Test

    Delivered by specialist testers, with us coordinating access and acting as the technical contact so your team is not disrupted.

  4. 04

    Remediate and retest

    Findings triaged by real risk, fixed, and verified. The report is the input to the work, not the deliverable.

Frequently asked questions

Does JTIT perform the testing itself?

We scope engagements, coordinate them, act as technical contact and remediate the findings. The testing itself is delivered with specialist penetration testing providers. There are two reasons for that: offensive security is a distinct discipline and we would rather bring in people who do it full time, and it is not meaningful for us to test configurations we implemented ourselves. If you want a single provider who both builds and tests your environment, be aware of what that independence trade-off costs you.

What is the difference between a penetration test and a vulnerability scan?

A vulnerability scan is automated and identifies known weaknesses — missing patches, outdated software, weak configurations. A penetration test is a human attempting to chain weaknesses into actual access. Scans are cheap, fast and should be run regularly. Tests are expensive, point-in-time and answer a different question. Most businesses that have never scanned should scan first, because paying a skilled human to discover that you have not patched is poor value.

How much does a penetration test cost?

It depends entirely on scope, and any figure quoted before scoping is meaningless. A focused external perimeter test on a small footprint is a fundamentally different engagement from an internal test across multiple sites or a full application assessment. What we can do is help you scope it so you are buying the test that answers your actual question.

How often should we test?

Annually is the common answer, and for many businesses it is more than they need if nothing significant has changed. What genuinely warrants a test is change: a new internet-facing application, a significant infrastructure rebuild, a merger, or a contractual requirement. Continuous vulnerability scanning and patching discipline deliver more security per dollar than an annual test for most organisations.

Will testing break anything?

Properly scoped, disruption is unlikely but not impossible, which is why rules of engagement are agreed in writing beforehand — including what is out of scope, what testing windows apply, and who to call if something does go wrong. Denial of service testing is normally excluded unless specifically requested. Anyone who tells you a test carries zero operational risk is overselling.

Related services

Most clients combine a few of these — we'll help you decide what's right for your size and risk profile.

Ready to talk?

A 30-minute consultation with an engineer, not a salesperson. You'll get an honest read on whether we're a fit.

Call Get a quote