Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. How we work

The Aurian engagement lifecycle

How a penetration test with Aurian works

Four phases, the same every time: scope, test, report, retest. This page explains what happens in each, what the report contains, and what we need from you to start.

Scope, test, report, retest

The four phases

  1. 01 Scope

    We agree what is in and out, the test windows, the credentials and contacts, and the rules of engagement, in writing.

  2. 02 Test

    A senior consultant tests by hand, using automated tooling for coverage. You hear about serious findings the day we confirm them.

  3. 03 Report

    An executive summary for the board and the insurer, and technical findings with evidence and a fix your engineers can apply.

  4. 04 Retest

    Once you have remediated, we retest and update the report so the record shows what was found and what was closed.

Phase 1, scope

Scoping

Every engagement starts with a conversation and ends the scoping phase with a written agreement of exactly what will be tested, when, and how.

A scoping call with a senior consultant establishes what you need to know and why: which systems, which threat you have in mind, who is asking for the test, and what the report will be used for. From that we write a scope that lists the assets in and out, the testing windows, the accounts and access we need, the contacts on both sides, and the rules of engagement, including anything you consider fragile and any technique you do not want used.

You receive a proposal with a fixed price for the agreed scope and a letter of authorisation for someone with the authority to grant it to sign. Nothing is tested until that letter is signed. If any system is hosted by a third party, we help you obtain their permission before we start.

  • What is in and out

    A named list of hosts, applications, tenancies or people, and an explicit list of what we will not touch.

  • When we test

    Testing windows, blackout periods, and the change windows for anything that could affect production.

  • What we need

    Test accounts by role, network access for internal tests, and read access for assessments.

  • Who to call

    A technical contact and an escalation contact on your side, and a named consultant on ours.

Phase 2, test

Testing

A senior Aurian consultant performs the test by hand. Automated tooling is used for coverage, never as the test.

Scanners and enumeration tools sweep a large scope quickly and reliably, and we use them for exactly that. The findings that matter, the chained weaknesses, the logic flaws, the misplaced trust between systems, come from a consultant working through the environment with the methodology for that service: PTES and NIST SP 800-115 for networks, the OWASP testing guides for applications and APIs, the CIS Benchmarks for configuration, the ASD maturity model for the Essential Eight.

External, application, cloud and assessment work needs nothing from you but access, and internal tests run through a small testing device we ship to you or a VPN you provide. Throughout, you have a named contact. Critical findings are raised the day we confirm them rather than held for the report, so you can act on a serious exposure immediately. We avoid anything that risks availability, and we agree in advance how to handle the systems you tell us are fragile.

  • Senior consultants only

    A senior consultant runs every engagement, onshore in Australia. Nothing is outsourced, offshored or crowdsourced.

  • Serious findings, same day

    A serious exposure is reported when it is confirmed, with enough detail to act on before the report.

  • Safe against production

    No denial-of-service testing unless asked. Fragile systems handled as agreed, with a contact open throughout.

  • Australia-wide

    Consultants across the country, working with organisations in every sector, from schools and universities to councils and critical infrastructure.

Phase 3, report

Reporting

The report is the product. It is written for two readers at once: the executive who has to decide, and the engineer who has to fix.

What the report contains

  1. Executive summary. The overall position in plain language, the headline risks, and what to do first. Written for the board, the audit committee and the insurer.
  2. Scope and method. What was tested, when, from where, with what access, and against which standard, so the report can be read in context later.
  3. Findings, ranked by risk. Every finding in the same format: title, rating with the likelihood and impact behind it, affected asset, description, evidence, impact, remediation, references.
  4. The attack path. Where findings chained together, the path drawn step by step, and the single change that would have broken it.
  5. Remediation roadmap. The findings ordered by risk reduction and effort, so the plan starts with what matters.
  6. Appendices. Tooling output, the full asset inventory, and anything an engineer needs to reproduce a finding.

How a finding is rated

Every finding is placed on Aurian's risk matrix: how likely the threat is, from remote to almost certain, multiplied by what it would do to your organisation, from trivial to critical. The score puts the finding in one of six bands, and the band sets the urgency. A rating covers what was in scope; the real-world risk can be greater once a finding is combined with systems we did not test.

Risk matrix: threat likelihood by organisational impact, each cell the score and its rating
Organisational impact
Trivial 1 Low 2 Medium 3 High 4 Severe 5 Critical 6
Threat likelihood Almost certain 5 5 Low 10 Moderate 15 High 20 Extreme 25 Catastrophic 30 Catastrophic
Likely 4 4 Low 8 Moderate 12 Moderate 16 High 20 Extreme 24 Extreme
Possible 3 3 Informational 6 Low 9 Moderate 12 Moderate 15 High 18 High
Improbable 2 2 Informational 4 Low 6 Low 8 Moderate 10 Moderate 12 Moderate
Remote 1 1 Informational 2 Informational 3 Informational 4 Low 5 Low 6 Low

Likelihood 1 remote, 2 improbable, 3 possible, 4 likely, 5 almost certain Impact 1 trivial, 2 low, 3 medium, 4 high, 5 severe, 6 critical

  1. Informational 1 to 3

    Raised to bring the discovery to your attention. No immediate action is needed; monitor it so the risk does not grow.

  2. Low 4 to 7

    Investigate where applicable and plan remediation within a reasonable timeframe.

  3. Moderate 8 to 14

    Could cause a limited adverse impact on business operations. Review the effectiveness of current controls and plan the mitigation.

  4. High 15 to 19

    Could seriously reduce the effectiveness of business operations and damage organisational assets. Mitigate as soon as possible, given your other security priorities.

  5. Extreme 20 to 24

    Could significantly damage business information, finances, reputation, employees and customers. Plan the mitigation immediately.

  6. Catastrophic 25 to 30

    Multiple exceptional consequences: significant financial loss, notable reputational damage and considerable loss of data, with likely ramifications for organisations connected to yours. Act immediately to mitigate or eliminate the risk.

The bands are a guide to help you classify and prioritise. Your own risk framework decides the final score, and we recommend remediating every finding within a reasonable timeframe, whatever its band.

Every finding looks like this, whatever the engagement.

Extreme AUR-2026-014 Sample finding, fictional environment

Expired VPN appliance exposes a known authentication bypass

Affected asset
vpn.example.com.au (203.0.113.42)
Rating
Extreme Likely 4 × Critical 6 = 24

Description

The remote access appliance is running firmware three major versions behind current and is affected by a published authentication bypass. An attacker on the internet can reach the internal network without valid credentials by sending a crafted request to the session endpoint.

Evidence

$ curl -sk https://203.0.113.42/dana-na/../dana/html5acc/guacamole/ \
    -H "Host: vpn.example.com.au"
HTTP/1.1 200 OK
Server: MAG-VPN 9.1R2 (build 4711)   # 9.1R18 is current
X-Session: created uid=0 sslvpn-admin

The response confirms an authenticated session was created for an administrative user without any credentials being supplied.

Remediation

Update the appliance to the current firmware, which closes the bypass, then rotate all local and administrative credentials because the device may already have been reached. Restrict the management interface to named administrative addresses, and enable multi-factor authentication on all remote access.

Phase 4, retest

Retesting and support

A finding is not closed until it has been retested. Once you have remediated, we test again and update the report.

Retesting of findings rated high or above is quoted with the test or booked afterwards as a short follow-on engagement. Each remediated finding is tested again to confirm it is genuinely closed rather than reported as done, because fixes land in the wrong environment, get applied partially, or are reverted by a later change more often than anyone would like. The updated report records what was found and what has been closed, and an attestation letter, available on request at no charge, gives auditors, customers and insurers the short version.

Where your team needs more than a retest, our remediation support and retesting service carries findings through to closure: working sessions on the priorities, clarification for your engineers or managed service provider, hands-on help implementing fixes, and advice on the systemic changes that stop the same class of finding coming back.

  • Retest of findings rated high or above

    Quoted with the test or booked afterwards. Each remediated finding is tested again and the report updated.

  • Updated report and attestation

    The record shows what was found and what was closed, and an attestation letter is available on request.

  • Remediation support

    Hands-on help closing findings, as a separate service, for teams without in-house security staff.

  • The next test

    Findings and the retest set the baseline for the next annual engagement, so the trend is visible.

Before we start

What we need from you

A short list. We send it at scoping so nothing holds up the start date.

  • Written authorisation from someone with the authority to grant it, on the letter we provide
  • The scope: IP ranges, domains, applications, tenancies or the people in scope, and anything out of scope
  • Permission from any third party that hosts a system in scope
  • Test accounts in each role for authenticated testing, or read access for assessments
  • A technical contact and an escalation contact, and the hours they can be reached
  • Change windows and rollback contacts for any system you consider fragile
  • For internal tests: a network port for the testing device we ship, or a VPN account
  • Anything you already know is a problem, so we can confirm it quickly and spend the time elsewhere

Scope a test with a senior consultant

Tell us what you need to know about your environment. We reply within one business day.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.