AegentraNew Zealand

Harden / New Zealand

Penetration testing

Aegentra provides scoped penetration testing with written authorisation, agreed rules of engagement and evidence-led reporting. We help New Zealand organisations understand the impact of identified weaknesses and prioritise remediation.

On this page

Start with the boundary

Define the work that is needed.

For organisations requiring an authorised technical assessment of agreed applications, systems or infrastructure.

  • Written targets, exclusions and testing authority
  • Manual testing appropriate to the agreed environment
  • Evidence, impact and remediation reporting
  • Separately defined remediation verification or retesting

Keep the responsibilities distinct

Testing is time- and scope-bounded and cannot prove the absence of all vulnerabilities. No testing begins without authorisation. Social engineering, denial-of-service activity and additional targets require explicit agreement.

What the engagement can produce

Useful outputs, agreed in advance.

  • Agreed rules of engagement and communication arrangements
  • A report describing findings, evidence and limitations
  • Risk-based remediation recommendations
  • Retest results for fixes included in the agreed scope

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How we work

From evidence to a practical next step.

Agree

Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.

Examine

Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.

Act or report

Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.

Verify and hand over

Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

An illustrative starting point

What a useful first decision looks like.

Fictional example to explain the service, not a New Zealand client case study or a promised outcome.

A web application permits one authorised user to access another account’s record. The finding needs minimal reproducible evidence and a clear affected boundary, not unnecessary extraction of customer data.

Questions for the first discussion

  • Which targets do you own or have permission to test?
  • Is testing in production, staging or another environment?
  • What methods, times, data-handling rules and stop conditions are acceptable?

Before you begin

Your questions, answered.

Is a vulnerability scan the same as penetration testing?

No. Scanning identifies potential weaknesses through automated checks. A penetration test uses a defined methodology and authorised investigation to evaluate impact and report evidence. The exact depth, methods and exclusions must be agreed before work begins.

What can be included in penetration testing?

The agreed scope can include written targets, exclusions and testing authority; manual testing appropriate to the agreed environment; evidence, impact and remediation reporting; separately defined remediation verification or retesting. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.

How much does this service cost?

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How do you deliver the work in New Zealand?

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

What should we provide before a proposal?

Bring answers to these starting questions: Which targets do you own or have permission to test? Is testing in production, staging or another environment? What methods, times, data-handling rules and stop conditions are acceptable? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.

Reference points

Check the underlying guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss your requirement

Start with your business.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.