FAQs

Questions we get asked.

30 answers, including the ones where the honest answer is no.

Penetration testing

What kinds of testing do you offer?

Web application and API testing, external and internal infrastructure testing, and cloud and identity configuration review. Engagements can be one-off or run on a cycle with re-testing.

How do you scope a test?

A short scoping form and usually one call. We agree the in-scope systems, the roles to be tested, the testing window, the rules of engagement and emergency contacts before anything starts.

What does it cost?

We quote a fixed price for a defined scope, not a day rate. You know the number before you commit, and the cost does not move because the work took longer than we expected.

Will testing disrupt our business?

Tests are designed to be low impact and the timing is agreed with you. Higher-risk steps are throttled or scheduled out of hours, and testing pauses immediately if you ask.

Do you prove the findings?

Yes. Every finding carries evidence, the business impact, and the fix. Where exploitation is in scope and safe, we demonstrate it rather than assert it.

How long does it take?

Most web application tests run one to two weeks of testing, with the report about a week later and a walkthrough after that. Scoping tells us the real answer.

Is a retest included?

A retest of all high and critical findings is included once you have remediated them.

Who actually does the testing?

CREST-certified testers working to Summit engagement terms. You meet the lead tester at the walkthrough.

How do you handle our credentials and data?

Test accounts in a non-production environment wherever possible, credentials handled through a password manager rather than email, and all engagement data destroyed on a defined schedule after the retest.

Web application and API testing

What does a web application test cover?

The OWASP Top 10, authentication and session handling, authorisation and privilege escalation, business-logic flaws, and cross-tenant segregation across every role. Applications with AI features are also tested against the OWASP Top 10 for LLM applications.

Do you test APIs?

Yes — REST and GraphQL, including the endpoints the front end never calls. An OpenAPI or schema export makes this considerably more thorough.

Can you test pre-production?

We prefer it. A production-like non-production environment gives you a real test without the risk, and it is what we ask for during pre-engagement.

What do you need from us before testing starts?

A non-production environment, accounts for each role in at least two tenants where the application is multi-tenant, an API export, and WAF allow-listing for the testing source addresses.

Cloud and identity

What is the difference between a cloud review and a penetration test?

A review is carried out with read access and tells you how the tenancy is configured and who can reach what. A test is adversarial and demonstrates what someone could actually do. Most organisations get more from the review first.

What do you look at?

Microsoft 365 and Entra ID conditional access, privileged roles, application consent, guest access and mailbox rules; and in Azure and AWS, identity and entitlements, network exposure, storage and key handling, and whether logging would tell you an account had been taken over.

Do you benchmark against a standard?

Findings are mapped to the ACSC Essential Eight where it applies, and to the relevant cloud provider benchmark. We report the gap, not a score.

Vulnerability and exposure management

What does the service include?

Tenable deployment and tuning, scheduled scanning, prioritisation that accounts for exploitability rather than CVSS alone, exception handling, remediation routed to the teams who own the systems, and a monthly report.

Do you validate scanner results?

Yes. Unvalidated scanner output is how remediation programmes lose credibility with the people expected to act on them.

Can you integrate with our ITSM?

Yes. Findings should arrive as tickets in the system your teams already work in, not as a spreadsheet attached to an email.

What support hours apply?

Managed vulnerability management runs in business hours with after-hours escalation. It is not one of the services monitored around the clock.

Managed services

Which services are monitored 24/7?

Managed firewall, managed email security, managed endpoint, managed identity and managed SIEM are monitored and triaged 24 hours a day, every day of the year. Your Summit engineer is available in business hours with after-hours escalation. Everything else, including project work, is business hours with escalation.

Do you operate your own security operations centre?

No, and we would rather say so plainly. We are a small, senior team in Perth. Around-the-clock monitoring on the services above is delivered through platforms built for it, with Summit engineers owning your environment and your escalations.

What does onboarding involve?

A fixed-price onboarding that gets the service into a known state: connected, tuned, documented, and with alerting pointed somewhere a person actually reads. You see the scope and the cost before it starts.

Are we locked in?

Services are contracted for a term, usually twelve months, because the vendor licensing underneath them is. There is no auto-escalating multi-year commitment, and we will tell you before a renewal rather than after it.

Working with us

How is Summit different?

The people who sell it are the people who do it. Your engagement is led by the Managing Director, not handed to an account manager and then to a junior. We also publish our prices, which most of our competitors do not.

Do you offer one-off work, or only contracts?

Both. A penetration test, a cloud review or a SIEM build are one-off engagements. The managed services are contracted monthly. Plenty of clients start with the former.

What industries do you work with?

Western Australian organisations, mostly between 25 and 1,000 staff — resources and mining services, agriculture, education, professional services, and state and local government.

How can you help with compliance?

We map technical work to the ACSC Essential Eight, SMB1001, ISO 27001 and APRA CPS 234 where they apply. We are not an audit firm and will not pretend otherwise — we do the technical work that makes an audit survivable.

How quickly can you start?

Scoping usually within the week. Penetration testing depends on tester availability and is typically a few weeks out. Managed services depend on your change process more than ours.

How do we get started?

Tell us what you are trying to solve. A short conversation is normally enough to work out whether we can help and roughly what it would cost — and we will say so if the answer is that you do not need us.

Tell us what you are trying to solve.

A short conversation is usually enough to work out whether we can help, and what it would cost.