Australian SMBs comparing automated vs manual penetration testing are usually choosing depth, not a brand. An analyst-reviewed Automated Security Assessment ($80–$2,000) finds common, high-impact exposure fast. A human-led penetration test (from $5,000) adds creative exploitation, chaining, and proof-of-concept evidence auditors and tenders often expect. Neither is “fake” — they answer different questions. This guide maps scan vs assessment vs pentest, published AUD bands, and a simple decision tree so you buy evidence that matches the ask.
What is the difference between a vulnerability scan, an automated assessment, and a penetration test?
A vulnerability scan is a tool export: known signatures, lots of noise, little context. An Automated Security Assessment runs a structured toolchain against your targets, then a certified analyst reviews and validates findings before you see the PDF. A penetration test is human-led: testers attempt to exploit and chain issues the way an attacker would, with proof-of-concept on criticals.
Those three labels get mashed together in sales calls. Vendors rebrand scanner PDFs as “pentests.” Buyers pay for theatre. Insurers and clients get artefacts that don’t mean what the questionnaire assumed.
In plain terms:
- ▸Raw vulnerability scan: Unattended tooling (Qualys, Nessus-style dumps, open scanners) - Long CVE lists, high false-positive rates, little business context
- ▸Automated Security Assessment (analyst-reviewed): Purpose-built pipeline + human triage before delivery - Severity-ranked findings, evidence, plain-English remediation - not a raw export
- ▸Human-led penetration test: Manual creative testing on top of tooling - PoC on criticals, chaining, business-logic abuse, retest path
At Aussie Pentest, the automated product is named exactly what it is: an Automated Security Assessment - not a penetration test. The human-led penetration testing line is the engagement that reproduces critical findings with working evidence before they ship. As we put it internally: if we can't prove it, it doesn't ship.
OWASP's Top 10 and similar catalogues are useful for framing common web risks; they are not a substitute for either product. They tell you categories of weakness. An assessment or pentest tells you whether your systems actually expose them.
Automated vs manual at a glance: cost, depth, and turnaround
Side by side, the trade-off is speed and price versus depth and exploit proof - not "cheap fake" versus "real security."
Published price (AUD)
- ▸Automated Security Assessment: Basic $80 | Standard $200 | Professional $500 | Premium $2,000
- ▸Human-led penetration test: Basic from $5,000 | Standard from $12,000 | Advanced from $20,000 (+ GST; international GST-free per pricing page)
Who is on the keyboard
- ▸Automated Security Assessment: Automated pipeline (Nuclei, Burp Suite, SQLmap, Nmap, Nikto) + certified analyst review/validation
- ▸Human-led penetration test: Human tester(s) driving tools and creative attack paths
Best at
- ▸Automated Security Assessment: Common web/misconfig exposure; fast baseline; prioritised report for small scopes
- ▸Human-led penetration test: Exploitation, chaining, business logic, internal/AD/cloud depth, social engineering (Advanced)
Proof-of-concept
- ▸Automated Security Assessment: Validated findings with evidence in the PDF
- ▸Human-led penetration test: Every critical reproduced with PoC before it enters the report
Turnaround (published SLAs)
- ▸Automated Security Assessment: 24hr / 24hr / 48hr / 72hr by tier
- ▸Human-led penetration test: Basic delivered 3-5 days; Standard/Advanced typically 2-3 weeks (site also cites ~5-10 days average delivery on the pentest page - use the tier SLA when scoping)
How you buy
- ▸Automated Security Assessment: Book online, Stripe, report by email - no sales calls
- ▸Human-led penetration test: Written scope agreed before testing; fixed fee
Typical buyer trigger
- ▸Automated Security Assessment: First baseline, MVP launch, insurer questionnaire, we've never been tested
- ▸Human-led penetration test: Tender/client DD, board pack, complex estate, need to prove exploitability
We do not pretend a $5,000 engagement and an $80 assessment produce identical outcomes. They don't. The useful question is which outcome you need this quarter.
When is an Automated Security Assessment enough?
Choose an Automated Security Assessment when you need a credible, analyst-reviewed baseline on internet-facing assets quickly - and the ask does not yet require human exploit theatre or deep internal coverage.
Good fits we see with Australian SMBs:
- ▸You've never been tested. A readable first report beats another year of guessing.
- ▸Insurance or client questionnaires ask for recent vulnerability assessment evidence, and you need something structured - severity ratings, remediation language, not a raw scanner dump.
- ▸MVP / single domain / small web estate. One site or a handful of targets; you want common login, input, and exposure issues caught before launch or before a sales push.
- ▸Budget and timeline are tight. You can start from $80 with a 24-hour SLA on Basic/Standard, or scale to Professional ($500, up to 5 targets, 48hr) or Premium ($2,000, 10+ targets, 72hr) when you need broader coverage or multi-finding scenario thinking.
- ▸You're deciding whether a full pentest is warranted. Assessment findings often clarify whether the next spend should be remediation, a deeper manual test, or both.
What the assessment is not: a substitute for internal network, Active Directory, social engineering, or heavily customised business-logic abuse testing. Standard tiers cover internet-facing assets; private/internal systems need a different scope conversation - usually a human-led engagement.
Soft next step: If this sounds like your situation, start an Automated Security Assessment online - scope targets, pay, receive an analyst-reviewed PDF within the SLA. Sample report available on the service page if you want to see the artefact first.
When do you need a manual (human-led) penetration test?
You need a human-led penetration test when someone is relying on proof that an attacker path works - not only that signatures matched - or when the attack surface sits beyond a public web scan.
Buy (or insist your vendor provide) manual depth when:
- ▸A tender, enterprise customer, or auditor asks for a penetration test by name, with methodology, scope letter, and often retest.
- ▸You hold sensitive data or run complex apps (multi-role SaaS, payments, health, defence-adjacent supply chain) where business logic and access-control flaws matter more than CVE lists.
- ▸You need internal, cloud, AD, or phishing coverage. Human-led work at Aussie Pentest covers external and internal network, web/APIs, cloud (AWS/Azure/GCP), Active Directory, and social engineering on Advanced scopes.
- ▸Critical findings must ship with PoC. If we can't prove it, it doesn't ship is the bar for the manual line.
- ▸You're past the first baseline. You've already fixed the obvious, or an assessment showed enough risk that leadership wants exploit-backed evidence for the board.
Published manual tiers (from the pricing page):
- ▸Basic - from $5,000 AUD - external network, up to 25 IPs; suited to smaller web-facing estates; delivered in 3-5 days.
- ▸Standard - from $12,000 AUD (most popular) - external + internal, up to 50 IPs and 2-3 web apps; executive summary and debrief; 2-3 weeks.
- ▸Advanced - from $20,000 AUD - full-scale including social engineering; 2-3 weeks.
All manual tiers include written scope, fixed fee, severity-ranked/CVSS-scored reporting, PoC on criticals, remediation guidance, retest/validation confirmation, and compliance mapping language (ISO 27001, Essential Eight, SOC 2) as evidence support - not a guarantee that an insurer, auditor, or scheme will accept the report. Acceptance is always theirs.
How much does each option cost in Australia?
Published Aussie Pentest bands (AUD) - cite these, not invented market averages:
Automated Security Assessment - /security-assessment
- ▸Basic - Price: $80 | Scope: 1 target; single-domain web; common misconfigs | SLA: 24hr
- ▸Standard - Price: $200 | Scope: 1 domain; common web vulns (OWASP-style); 0-10 severity; plain-English remediation | SLA: 24hr
- ▸Professional - Price: $500 | Scope: Up to 5 targets (web/APIs); deeper login/data/access review; exec summary | SLA: 48hr
- ▸Premium - Price: $2,000 | Scope: 10+ targets incl. APIs/internal-facing; chaining/combined scenarios; exec + technical; compliance-ready framing | SLA: 72hr
Monthly (-25%) and quarterly recurring options exist on the assessment page if you want a cadence without jumping straight to a retainer.
Human-led penetration testing - from $5,000 / $12,000 / $20,000 as above (+ GST where applicable).
Nearby rungs on the same ladder (only if they match your journey - don't force them):
- ▸Essential Eight maturity assessment - $4,950 + GST (<=50 seats): independent technical assessment against the ACSC Essential Eight model - useful when insurance, tender, or DISP-oriented evidence needs control maturity, not just vuln findings. That is a different product to both assessment and pentest.
- ▸vCISO retainer - from $2,500 / $4,250 / $6,500 per month: advisory and oversight (risk register, stakeholder reporting, light checks on higher tiers) - not implementation and not incident response. Useful after you're tired of annual scramble; it does not replace a scoped test.
For a deeper walk through what moves the number on manual work, see Penetration Testing Costs for SMBs in Australia.
How should an Australian SMB choose: decision tree
Start with the ask, then the surface, then the budget - in that order.
- What does the other party literally request?
- ▸Vulnerability assessment / recent scan / security report -> Automated Security Assessment is often enough.
- ▸Penetration test / CREST-style / exploit evidence / internal + external -> Human-led pentest.
- ▸Essential Eight / ML1-ML2 / DISP cyber evidence -> E8 assessment (separate from both).
- What can an attacker reach?
- ▸One public website or a small set of internet-facing apps -> assessment tiers scale from $80-$2,000.
- ▸Internal networks, AD, cloud IAM, phishing -> manual scope.
- Do you need exploit proof or a prioritised baseline?
- ▸Baseline + triage -> assessment.
- ▸PoC, chaining, board-grade exploit narrative -> pentest.
- Is this the first test or the next one?
- ▸First ever -> many SMBs start with assessment, remediate, then book manual where residual risk or a customer still demands it.
- ▸Already mature / high-stakes deal -> don't under-buy; go manual earlier.
- Independence check.
If your MSP both builds and tests the same environment, ask whether the recipient of the report (insurer, auditor, customer) will treat that as objective. Independent third-party assessment or pentest is often the cleaner artefact - without fire your MSP theatre. Validate what they built; don't replace them on the blog.
Practical default for many AU SMBs: start with Standard or Professional Automated Security Assessment if the pressure is a questionnaire, launch, or first look; escalate to Basic+ manual pentest when a named pentest, internal depth, or PoC is on the table.
What should you ask any provider before you buy?
Whether you buy from us or elsewhere, these questions separate analyst-reviewed work and real pentests from rebranded scans:
- Do you call this a penetration test - and what does that mean in your SOW? If the answer is fully automated pentest with no human exploitation, treat it as an assessment or scan and price it accordingly.
- Who reviews findings before delivery? Analyst validation vs raw tool export.
- Are criticals reproduced with proof-of-concept? Yes for credible manual work.
- Is scope written and fee fixed before testing starts? Surprise invoices are a process smell.
- What is in / out of scope? External only? Internal? Cloud accounts? Auth bypass / business logic?
- Retest included? Manual tiers at Aussie Pentest include retest/validation confirmation; confirm in writing.
- Onshore delivery and authorisation? Legitimate testing requires your written authorisation for every target. We do not test without it.
- Can I see a sample report? Artefacts beat adjectives.
For a fuller provider checklist, see How to Choose a Penetration Testing Provider in Australia.
FAQ
Is an automated security assessment the same as a penetration test?
No. An Automated Security Assessment is analyst-reviewed vulnerability assessment: structured tooling plus human validation of findings. A penetration test adds human-led exploitation, chaining, and PoC on criticals. Useful products; different depth and price.
Will my cyber insurer accept an automated assessment report?
Often, yes for questionnaire-style evidence - our assessment reports are structured for common insurance, Essential Eight, ISO 27001, and SOC 2 evidence support. Insurers set their own bars; some deals or higher limits still expect a named penetration test. Ask the broker what artefact they mean before you buy either.
Why does manual testing start from $5,000 when assessments start at $80?
Because calendar time of skilled humans, written scoping, broader surfaces, PoC work, and retest are different cost structures. Paying $80 for a first look is rational. Expecting $80 to equal a scoped manual engagement is not.
Can I do automated first and pentest later?
Yes - and that sequence is common. Fix what the assessment surfaces, then book human-led testing where residual risk, customer contracts, or internal/cloud scope demand it. You are not failing by starting on the lower rung.
What if I need Essential Eight, not a vuln report?
Book an Essential Eight assessment ($4,950 + GST for <=50 seats): maturity scoring against the ACSC model with evidence and a remediation roadmap. It complements - it does not replace - technical testing of apps and networks.
Bottom line
Buy the rung that matches the question you must answer. Use an Automated Security Assessment when you need a fast, analyst-reviewed baseline on public assets without pretending it is a pentest. Use human-led penetration testing when you need exploit proof, deeper surfaces, or a named pentest for a tender, board, or customer. Keep Essential Eight and vCISO for maturity and ongoing oversight when those are the actual gaps.
Primary next step: If you want a first credible report without a sales process, get your Automated Security Assessment (from $80, report by email within the SLA). If you already know you need PoC-backed, scoped human testing, book a penetration test or compare fixed-fee pentest pricing.
