What Is the Average Cost of a Penetration Test in 2026?

Penetration testing for a Christchurch business and what it costs in New Zealand

In New Zealand, a penetration test for a small business typically runs from around $4,000 to $30,000, depending on scope. A focused single web app or external network test sits at the lower end, while a full network, web app, wireless and phishing test built for ISO 27001 or cyber insurance sits at the top. Here is what actually drives the price.

What a penetration test costs in NZ (2026)

  • Focused single web app or external network test: around $4,000 to $8,000
  • Standard external and internal network test: around $8,000 to $15,000
  • Comprehensive test (network, web app, wireless and phishing, or ISO 27001 / insurance-grade): around $15,000 to $30,000+

Every environment is different, so treat these as planning ranges, not a quote. We scope before we price.

Penetration Test Cost Factors Explained

Ask ten Christchurch business owners what a penetration test is. You’ll hear ten different ideas. No two tests are the same. Scope shifts everything. Testing one web app is a completely different job. It’s bigger than checking your whole network, wireless systems, and staff’s phishing readiness all at once. We sort out the scope for every job before we quote. Not knowing the target means businesses often pay for a test that misses the real problems.

What affects the cost of a penetration test? It always comes down to a few key things we check for every job.

  • Scope and assets. Five servers take more time than one. A customer-facing app with logins and payment processing? That’s a bigger job.
  • Type of test. External network tests, internal network tests, web app tests, and wireless tests each use different tools. They also need different time on the ground.
  • System complexity. A basic Microsoft 365 setup with a few cloud apps is quicker to test. Custom-built software or a mix of on-premise and cloud systems take longer.
  • Compliance needs. If you need ISO 27001 or evidence for cyber insurance, the test must cover specific controls. The report has to meet that standard.
  • Retesting. Problems get found. Fix them. Most businesses want a second check to confirm the fix worked.

Your team’s size also plays a part, but maybe not how you’d expect. And it isn’t just about headcount. It’s about how many systems, logins, and third-party tools your people use daily. Last year, we tested a 40-person Christchurch firm. It had a bigger attack surface than a 120-person client. That happened because they built many custom integrations over the years. More moving parts means more time to test them right.

We see this often. Businesses think a penetration test is a one-off tick-box job. It isn’t. The testing depth shifts based on what you need to prove. And to whom. An internal risk review test looks different from one done for an ISO 27001 audit or a cyber insurance readiness assessment. So, which one do you need? That question alone changes the whole job, even before we talk money.

The timeframe also matters. A rushed test done in a few days covers less ground. A proper window lets us dig into edge cases. We’ve found that businesses planning tests around a slower period, say, January or February, when ticket volume is quieter, get better results, it’s certainly more useful than cramming it in before a deadline.

One more thing to mention: the report. A good penetration test doesn’t just list issues. It ranks them by risk. It explains what could happen. It gives your team a clear path to fix each one. This reporting takes time. It often makes the biggest difference to your next steps.

Not sure how these points apply to your business? That’s what a scoping conversation is for. Our team can walk through your setup. We give you a clear picture of what a proper test involves. No commitment needed first- Talk to the team. You can call us on 0800242206 or book a free IT and security review.

What’s Really Driving Your Need for Testing

Most business owners don’t start the day thinking about penetration tests. Something usually pushes them to it. It’s often one of three things: a client asking tough questions, an insurer tightening rules, or a scare too close for comfort. We see this pattern all the time with Christchurch businesses, from CBD firms to manufacturers near Hornby and Rolleston.

Cyber insurance is a big driver right now. Insurers have sharpened up. They ask for proof of testing before writing a policy. Some won’t renew without it. If your cover is due soon, sort this before the broker rings. Not after.

Compliance is another big one. Chasing ISO 27001? Or do you need SMB1001 certification to win government or corporate jobs? Testing isn’t an option then. It’s part of the evidence auditors expect. We’ve helped Christchurch businesses get SMB1001 Gold sorted in 90 days. Penetration testing always fits into that picture.

Common triggers we see

  • A big client or government contract needs security test proof before signing.
  • Your cyber insurance renewal now asks for a recent test report.
  • You’ve had a phishing incident or near miss. You want to know what else is exposed.
  • You’re adding new software, a server, or moving to the cloud. You want it checked before launch.
  • It’s been over a year since your last test. You know it’s due.

Spot the pattern? None of this is about fear alone. These are practical triggers. A client wants proof. An insurer wants proof. You want to sleep better, knowing someone else has checked your systems.

There’s a quieter reason too, one we don’t discuss enough: growth. Christchurch businesses add staff, open new sites. They move core systems to Microsoft 365 and cloud platforms. The attack surface expands with them. A 20-person business and a 120-person business have different risk profiles. This is true even if their software looks similar. More staff means more logins, more devices. More chances for something to slip through.

And here’s what many miss until it’s too late. A test isn’t just about finding holes. It’s about seeing what happens if someone gets in. Can they move across your network? Can they hit your finance system from a random staff laptop? A good test answers that. It’s not just “is the front door locked?”

Last year, a client thought their firewall covered everything. It didn’t. The test found an old remote access tool. It was still on from a project that finished two years ago. Nobody remembered it. That’s what testing catches: quiet, forgotten risks just sitting there.

What’s truly driving your need? Ask yourself three things. Has a client or insurer asked for proof? Have your systems changed in the last twelve months? Has it been over a year since an independent check of your security? If you said yes to any of those, you already have your answer.

This is the exact talk we have with Christchurch businesses every week. We figure out the real need. Then we match it to the right testing scope. Get a no-obligation assessment. Call us on 0800242206 or book a free IT and security review.

Vulnerability Assessment vs Penetration Test: Why the Difference Affects Cost

This is where most Christchurch business owners get mixed up. A vulnerability assessment and a penetration test sound alike. They aren’t. Mixing them up is the quickest way to get the wrong quote.

A vulnerability assessment scans your systems. It lists weak spots. It’s automated, quick. You get a report of known issues: missing patches, weak setups, old software. Think of it like a health check. It tells you what could be wrong. But nobody tries to break in.

A penetration test goes deeper. A real person, using an attacker’s tools and mindset, tries to exploit those weak spots. They test if that door you thought was locked opens. This extra layer of manual, skilled work makes a penetration test cost more. Every single time.

We see this error constantly. A client asks for “a pen test.” They just need a vulnerability assessment to tick a compliance box. Or the other way around: someone books a basic scan. Their insurer or client contract needs proof of manual exploitation testing. Getting this wrong means wasted money.

Vulnerability Assessment vs Penetration Test

  • Vulnerability assessment: Automated scan. Wide coverage. Costs less. Run monthly or quarterly.
  • Penetration test: Manual testing. Deeper, narrower scope. Costs more. Run yearly or after major system changes.
  • Vulnerability assessment: Shows what could be wrong.
  • Penetration test: Proves if it can be exploited.
  • Vulnerability assessment: Good for everyday security checks.
  • Penetration test: Good for compliance, insurance, and client scrutiny.

Which one drives your budget? The penetration test does. It needs a skilled tester’s time, not just a scanner. And the testing scope matters as much as its format. A test for one web application costs less. A full network, cloud environment, and staff phishing resistance test costs more.

Here’s a situation we see often. A Christchurch retailer has a customer-facing website. They assume they need a full network penetration test. But when we scope it, they need an application-focused test. Plus, a standard vulnerability assessment across their internal systems. That combo costs less than a blanket, full-scope test. And it covers their actual risk.

This is exactly why scoping talks matter. Before you get a number. Two businesses of the same size can get totally different quotes. One needs deep manual testing, the other a lighter scan with a clear report.

Not sure which your business needs? That’s a normal starting point. Talk to the team about a security assessment first. We’ll tell you straight. Do you need a vulnerability assessment, a full penetration test, or both? Book a free IT and security review. Call us on 0800242206 or get a no-obligation assessment.

Related reading

Frequently asked questions

How much does a penetration test cost in New Zealand?

Most NZ small businesses pay between $4,000 and $30,000, and scope is what moves the number. A focused single web application or external network test is around $4,000 to $8,000. A standard external and internal network test is around $8,000 to $15,000. A comprehensive test covering network, web application, wireless and phishing, or one built as evidence for ISO 27001 or cyber insurance, is around $15,000 to $30,000. Treat these as planning ranges rather than a quote. We scope your environment before we price it, because two businesses of the same size can need very different tests.

What's the difference between a penetration test and a vulnerability scan?

A vulnerability scan lists possible weak spots. A penetration test goes further and tries to break in like a real attacker would. Scans are quick and automated. Tests take skill and time, because a person attempts to exploit what's found. Many Christchurch businesses run scans often but only need a full test once a year or before a big compliance deadline. Both have a place, but they answer different questions about your risk.

How do I know if my Christchurch business needs a penetration test?

You likely need one if a client, insurer, or auditor has asked for proof of security testing. Other signs include a recent phishing scare, new software rollouts, or moving systems to the cloud. If it's been over a year since your last check, that's also a clear sign. Businesses across Christchurch, from the CBD to Hornby and Rolleston, often start here after a scare or a contract requirement pushes them to act.

How often should a business get a penetration test done?

Most businesses should test once a year, or sooner after major system changes. If you add new servers, switch to Microsoft 365, or open a new site, your attack surface changes too. Insurers and auditors often expect yearly proof as well. Waiting longer than a year leaves gaps unchecked, especially if staff numbers or third-party tools have grown since your last test.

Does the number of staff at my business affect how long a test takes?

Staff count matters less than what your team uses day to day. A smaller Christchurch firm with many custom integrations can have a bigger attack surface than a larger business with simpler systems. We saw this last year with a 40-person firm that took longer to test than a 120-person client. More logins, tools, and custom builds mean more ground to cover, no matter your headcount.

What happens if a penetration test finds problems in my systems?

You get a clear report ranking each issue by risk, with steps to fix it. A good test doesn't just list problems. It explains what could happen if someone exploited them and what to do next. Most businesses then fix the top issues and book a retest to confirm the fix worked. This process protects your systems and gives proof to clients, insurers, or auditors who ask for it.

Do Christchurch businesses need penetration testing for cyber insurance?

Many insurers now ask for a recent test report before they'll issue or renew a policy. This shift has become common across Christchurch as insurers tighten their rules. If your renewal is coming up, it's worth checking this early rather than scrambling before your broker calls. To understand what a proper test involves for your setup, take a look at our penetration testing services in Christchurch before your next renewal date arrives.

What is the single most important cyber security control a small business should implement first?

Multi-factor authentication (MFA) on every account is the single highest-value control for most small businesses, because it stops the majority of credential-based attacks even if a password is stolen. After MFA, tidy user permissions and reliable backups deliver the next biggest gains. A penetration test then confirms these basics are actually working.

How often should a small business run a cyber security assessment?

Most NZ small businesses should run a cyber security assessment at least once a year, and again after any major change such as a new system, an office move, or a merger. If you hold sensitive client data or carry cyber insurance, an annual penetration test plus lighter quarterly vulnerability checks is a sensible rhythm.