Straight answers to what clients ask us most.
What is penetration testing, and why do we need it?
A penetration test is a controlled simulation of a real-world attack against your systems, applications and infrastructure. Rather than listing theoretical weaknesses, we attempt to exploit them — proving which issues genuinely put your business at risk. The result validates that your existing controls work, and gives you prioritised, actionable guidance to close the gaps that matter before a real attacker finds them.
How is AI continuous testing different from a traditional pentest?
A traditional pentest is a deep, point-in-time assessment: it tells you your security posture during the week it was performed. Continuous testing runs against your environment permanently, re-testing as code ships and infrastructure changes, so new exposure is caught in days rather than at your next annual engagement. They are complementary — continuous testing maintains baseline assurance and catches drift; a manual engagement provides the depth that finds complex logic and privilege-boundary flaws. Most mature clients run both.
What's the difference between a penetration test and a red team engagement?
A penetration test aims for breadth of coverage within a defined scope, answering “what is vulnerable and how badly?”. A red team engagement is objective-based and covert: we pick a goal a real adversary would pursue — domain compromise, access to a specific dataset, fraudulent transaction — and pursue it using realistic tradecraft while your team attempts to detect us. Pentesting tests your prevention; red teaming tests your detection and response. If you do not yet have a functioning SOC or monitoring capability, a pentest almost always delivers better value first.
Will testing disrupt our production systems?
No. Engagements are safe, controlled and coordinated closely with your team. Rules of engagement, testing windows, out-of-scope systems and escalation contacts are agreed in writing before we begin. Any potentially disruptive technique — denial-of-service testing, destructive exploitation, aggressive fuzzing — is excluded by default and only performed with explicit written authorisation, typically against non-production environments.
Does a GRC assessment replace technical testing?
No — they answer different questions. GRC assesses your governance, policies, processes and control frameworks: whether you have the right structures in place and can demonstrate them to an auditor. Technical testing proves whether those controls actually hold up against an attacker. Governance complements technical assurance but never replaces it; plenty of ISO 27001-certified organisations have exploitable perimeters.
How often should we test?
At minimum annually, and additionally after any significant infrastructure change, major application release, merger or security incident. High-risk environments, regulated entities and organisations shipping frequently should test more often — which is precisely the gap continuous testing is designed to fill.
What do we receive at the end of an engagement?
A comprehensive report covering every finding with clear severity ratings, full steps to reproduce, supporting evidence and specific remediation guidance — written to be useful to your engineers and intelligible to your executive. That is accompanied by an executive summary suitable for board reporting, a one-on-one debrief session, and complimentary retesting to verify your remediation succeeded.
Is our data kept in Australia?
Yes. Covenant Cyber is Australian owned and operated, and engagement data is processed and stored onshore in isolated environments with controlled egress and full action logging. Client data is never used to train third-party AI models — not anonymised, not aggregated.