Not all penetration testing is the same, even when two providers quote the same price for what looks like the same service. Gold Coast has a genuinely broad mix of businesses now being asked for a pentest report: healthcare providers, hospitality and retail operators running card payments, real estate agencies, professional services firms, and education providers, often because a client, insurer, or compliance framework is asking for one. The problem is that “penetration test” isn’t a protected term. Anyone can run an automated vulnerability scan, call it a pentest, and hand you a PDF. A quote that’s noticeably cheap and arrives with no scoping conversation attached is usually the first sign of this, not a bargain. Before you sign anything, these are the questions worth asking, and the kind of answers that tell you whether you’re talking to a real tester or a reseller.
1. What Exactly Is in Scope, and How Was It Decided?
A proper scoping conversation should happen before a quote, not after. Ask what’s actually being tested, your public website, internal network, cloud environment, wireless, or some combination, and whether it’s black box (no prior knowledge, like an outsider), grey box (some access, like a regular user), or white box (full access, like an insider). If a provider quotes you a price before asking a single question about your environment, that’s worth noticing.
2. What Methodology Do You Actually Follow?
A real tester should be able to name a standard and explain how they apply it. For web applications, that’s usually the OWASP Testing Guide. For broader engagements, providers often reference PTES, the Penetration Testing Execution Standard, or NIST SP 800-115. “We use industry best practice” isn’t an answer on its own. Ask them to walk you through their process, from reconnaissance through exploitation to reporting, in their own words.
3. Are Your Testers Certified, and by Whom?
Look for individual certifications like OSCP, alongside company-level accreditation. In Australia, CREST matters here, but there are two separate CREST bodies, CREST ANZ and CREST International, and they run their own independent accreditation programs. A provider might genuinely hold one, both, or neither. Rather than taking “we’re CREST accredited” at face value, ask which body specifically, and check the relevant public directory yourself.
4. What Does the Final Report Actually Contain?
Ask to see a sample, redacted if needed. A proper report has a plain-language executive summary a non-technical manager can actually read, technical findings with severity scoring, evidence of how each vulnerability was exploited, and prioritised, specific remediation guidance. If what you get back is a raw scanner export with a logo added, you haven’t had a penetration test.
5. Is a Retest Included?
Once you’ve fixed what the report flagged, someone needs to confirm the fixes actually worked. Ask whether that retest is included in the engagement or billed separately, and get it in writing either way. A provider who tests once and disappears hasn’t closed the loop.
6. What Happens if Something Goes Wrong During Testing?
Active exploitation on systems close to production carries real risk. Ask about the rules of engagement, defined testing windows, an emergency contact who can pause testing immediately, and whether the provider carries professional indemnity and public liability insurance. It’s also worth asking how they handle anything gathered during testing, credentials, screenshots, data touched during exploitation, and whether it’s securely destroyed once the engagement closes. A provider who hasn’t thought about any of this hasn’t done enough of these before.
7. Do They Understand Why You Actually Need This?
A pentest for a PCI DSS requirement looks different to one for an insurance renewal or a customer security questionnaire. PCI DSS has specific segmentation testing requirements, for instance, while an engagement driven by the Essential Eight needs to map back to a specific maturity level. Tell the provider exactly what’s driving the engagement and see whether they adjust scope and reporting accordingly, or just run the same generic test regardless of what you actually asked for.
8. What’s the Pricing Structure, and What Falls Outside It?
Ask whether the quote is fixed price or day rate, and what happens if testing turns up something that needs more time than originally scoped, extra cost, extra time at the same price, or a hard stop noted in the report. Get this in writing before the engagement starts, not worked out halfway through when a genuinely serious finding needs more digging.
9. Does It Matter That They’re Local to Gold Coast?
Honestly, for a lot of digital testing, not hugely. A competent remote tester can assess your web app or cloud environment from anywhere. Where local presence genuinely helps is the scoping conversation itself. A provider who already understands the mix of hospitality, retail, healthcare, and professional services businesses on the Gold Coast tends to ask better questions upfront, and being in the same timezone matters if something needs an urgent decision mid test.
Where to Go From Here
None of these questions should feel like an interrogation to a genuine provider. A tester who’s done real work will answer all of them without hesitation, because scoping conversations, methodology, and reporting standards are just how they operate. Hesitation, vagueness, or a quote with no scoping call attached are the actual red flags. Ask before you sign, not after the report lands.
If you’re weighing this up for a Gold Coast business, that’s exactly the conversation Cyber Ethos has with clients every day. We scope every engagement properly before quoting, work across networks, cloud, web applications, and OT and SCADA environments, and write reports in plain business language rather than a raw scanner export. We already support healthcare, hospitality, retail, real estate, and professional services businesses across the Gold Coast and South East Queensland. Call 1800 CETHOS (1800-238-467) for a free consultation and we’ll walk you through exactly how we’d scope yours.
