[{"data":1,"prerenderedAt":338},["ShallowReactive",2],{"marketing-page-resources":3,"launch-market-content":107},{"id":4,"content":5,"extension":99,"key":100,"meta":101,"seo":102,"stem":105,"__hash__":106},"marketingPages\u002Fpages\u002Fresources.yml",{"hero":6,"faqs":10,"listTitle":59,"fallbackEvidenceDescription":60,"officialResourceType":61,"officialResourceLabel":62,"cards":63},{"eyebrow":7,"title":8,"description":9},"Resources","Make the next security conversation easier.","Practical material for {audience} planning a penetration test, explaining exposure and preparing evidence for customers, tenders, insurers and audits.",{"eyebrow":11,"title":12,"description":13,"moreLabel":14,"lessLabel":15,"items":16},"Frequently asked questions","Answers before you plan a test.","Practical answers about scope, testing safeguards, reporting and data handling.","See more","See fewer",[17,20,26,29,32,35,38,41,44,47,50,53,56],{"question":18,"answer":19},"What is the process?","The process starts with you providing a URL or domain name. We will confirm the target and environment, then schedule a testing window. Once testing begins, we will work through the agreed scope and provide a report with findings and recommendations. To get started, click Plan a test.",{"question":21,"answer":22,"link":23},"How much does a test cost?","You can see more about plans and pricing",{"label":24,"to":25},"here","\u002F#plans",{"question":27,"answer":28},"Can you test my application or API?","Yes. The launch flow starts with one public HTTPS target and can record website, API and authentication coverage decisions. Broader or more complex scope can be discussed through the same Plan a test process.",{"question":30,"answer":31},"Do you need passwords or credentials?","We can do a black-box test with no credentials, or a grey-box test with credentials that you provide. For a more comprehensive assessment, it is recommended to test with user credentials.",{"question":33,"answer":34},"Can the test run in production?","We strongly recommend testing on a non-production environment, however production can be considered where the target, authorisation, safeguards and testing window are appropriate. The target and environment are confirmed before testing begins.",{"question":36,"answer":37},"What does penetration testing help with?","Penetration testing helps identify exploitable weaknesses in the agreed target so your team can reduce exposure. It does not prevent every cyber incident, and it is one part of a broader security programme.",{"question":39,"answer":40},"Does a penetration test guarantee security?","No. It provides evidence about exploitable weaknesses in the agreed scope at a point in time. Pensure reports limitations clearly and provides practical remediation context.",{"question":42,"answer":43},"Can anything outside my agreed scope be touched?","No. We only test targets expressly listed in the written scope. Nothing else is scanned, probed or tested.",{"question":45,"answer":46},"When does testing run?","Testing runs only during the window agreed with you and is coordinated around your local business hours. We do not begin until the scope and your authority to have the targets tested are confirmed in writing.",{"question":48,"answer":49},"Could the test take my system down?","Any testing of live systems carries some risk. We minimise it through agreed testing windows, exclusions, rate limits and clear stop conditions. Your nominated contact can pause testing at any time.",{"question":51,"answer":52},"What happens if you find something serious mid-test?","We notify your nominated escalation contact immediately and provide the information needed to respond. We do not wait until the final report.",{"question":54,"answer":55},"What do you need from me to authorise the test?","We need written confirmation that you are authorised to have the targets tested and that you acknowledge the agreed scope. We do not collect credentials, tokens, API keys or session cookies during planning. If authenticated testing is required, we will agree on a secure way to provide them before testing begins.",{"question":57,"answer":58},"What happens to my data afterwards?","Engagement data and evidence are handled in accordance with the commitments on our Trust and Data pages. Any specific retention, deletion or residency requirements can be agreed during the scope review.","Pensure resources","Current government or national cyber security evidence for {audience}.","Official resource · {marketName}","Open {resourceLabel}",[64,70,76,82,88,94],{"type":65,"title":66,"description":67,"to":68,"label":69},"Technical guide","Testing past the WAF without dropping your guard","Use the platform runbooks for Vercel, Cloudflare, Akamai and AWS WAF to create a narrow, temporary path for authorised testing.","\u002Fnews\u002Ftesting-beyond-the-waf","Open the WAF runbooks",{"type":71,"title":72,"description":73,"to":74,"label":75},"Planning guide","Start with the target that matters","A short guide to choosing the right application, API or digital asset for a first penetration test.","\u002Fnews\u002Fscoping-your-first-pentest","Read the scoping guide",{"type":77,"title":78,"description":79,"to":80,"label":81},"Buyer guide","What to ask for in a penetration-test report","Use the report output, evidence and remediation context to compare what different testing offers actually provide.","\u002Fnews\u002Freading-a-pentest-report","Read the report guide",{"type":83,"title":84,"description":85,"to":86,"label":87},"Trust and data","Understand the testing boundary","Review how Pensure approaches data handling, authorised scope and the information needed before testing begins.","\u002Fdata-security","Read Trust & Data",{"type":89,"title":90,"description":91,"to":92,"label":93},"First-time buyer guide","“Go get a pen test.” Now what?","Turn an urgent request from a customer, insurer or procurement team into a clear and controlled plan.","\u002Fnews\u002Fyou-need-a-pentest-now-what","Read the buyer guide",{"type":77,"title":95,"description":96,"to":97,"label":98},"Vulnerability scan or penetration test?","Understand what each approach does well, where the difference matters and when you may need both.","\u002Fnews\u002Fvulnerability-scan-vs-penetration-test","Compare the approaches","yml","resources",{},{"title":103,"ogTitle":103,"description":104,"ogDescription":104},"Penetration-testing resources for {marketName} | Pensure","Practical resources for {audience} planning penetration testing, explaining exposure and preparing evidence for customer and assurance reviews.","pages\u002Fresources","eaYosTvc1VFWqlTzFSJjr24TNmz0yz6fg4vlYKLeH18",[108,158,198,235,272,305],{"id":109,"audience":110,"extension":99,"heroTitle":111,"marketId":114,"meta":115,"resourceLinks":116,"riskCards":125,"riskEyebrow":150,"riskIntro":151,"riskTitle":152,"stem":153,"trustEyebrow":154,"trustLead":155,"trustTitle":156,"__hash__":157},"marketContent\u002Fmarkets\u002Fau.yml","Australian small and growing businesses",{"lineOne":112,"lineTwo":113},"1 in 5 businesses","had a cyber incident last year.","AU",{},[117,121],{"label":118,"description":119,"href":120},"Small business cyber security hub","Practical ASD guidance, checklists and tools for protecting accounts, data, cloud services and business operations.","https:\u002F\u002Fwww.cyber.gov.au\u002Fbusiness-government\u002Fsmall-business-cyber-security\u002Fsmall-business-hub",{"label":122,"description":123,"href":124},"Annual Cyber Threat Report","ASD’s national overview of reported cybercrime, common threats and impacts across Australian organisations.","https:\u002F\u002Fwww.cyber.gov.au\u002Fabout-us\u002Fview-all-content\u002Freports-and-statistics\u002Fannual-cyber-threat-report-2024-2025",[126,137,143],{"value":127,"title":128,"subtitle":129,"detail":130,"copy":131,"source":132,"href":133,"secondarySource":134},"21%","Businesses hit","Australian businesses • 2024–25","had an incident","About 200,000 Australian businesses with employees had a cyber incident in 2024–25.","ABS cyber incident data","https:\u002F\u002Fwww.abs.gov.au\u002Fstatistics\u002Findustry\u002Ftechnology-and-innovation\u002Fcharacteristics-australian-business\u002Flatest-release",{"label":135,"href":136},"ABS business counts","https:\u002F\u002Fwww.abs.gov.au\u002Fstatistics\u002Feconomy\u002Fbusiness-indicators\u002Fcounts-australian-businesses-including-entries-and-exits\u002Fjul2021-jun2025",{"value":138,"title":139,"subtitle":129,"detail":140,"copy":141,"source":142,"href":133},"28%","No protection in place","no measures","More than 1 in 4 businesses had no measures in place to prevent cyber incidents. Don’t be one of them.","Australian Bureau of Statistics",{"value":144,"title":145,"subtitle":146,"detail":147,"copy":148,"source":149,"href":124},"A$56,600","Average incident cost","Small businesses • 2024–25","average per reported incident","Small businesses reported an average cost of A$56,600 per cybercrime incident. For large businesses, it was A$202,700.","ASD\u002FACSC Annual Cyber Threat Report","The cost is real","Pensure Core costs A$4,400 including GST, less than 10% of that figure. See how an attacker could get into your business and what to fix first.","A cybercrime incident cost a small business A$56,600 on average last year.","markets\u002Fau","Onshore by design","Pensure provides seamless launch services managed in Australia. Clear coordination and practical communication keep Australian teams aligned from scope through reporting.","An Australian team for Australian business context.","h9kSRgv5Q8YR2sVHDb5AL2Xdg4SywYmVjf9JzmGwLWU",{"id":159,"audience":160,"extension":99,"heroTitle":161,"marketId":164,"meta":165,"resourceLinks":166,"riskCards":167,"riskEyebrow":191,"riskIntro":192,"riskTitle":188,"stem":193,"trustEyebrow":194,"trustLead":195,"trustTitle":196,"__hash__":197},"marketContent\u002Fmarkets\u002Feu.yml","European small and growing businesses",{"lineOne":162,"lineTwo":163},"More than 1 in 5 businesses","had a cyber incident in 2023.","EU",{},null,[168,175,183],{"value":169,"title":170,"subtitle":171,"detail":130,"copy":172,"source":173,"href":174},"22%","Businesses affected","EU businesses with 10+ people • 2023","More than 1 in 5 EU businesses had a cyber incident that stopped services, damaged data or exposed confidential information.","Eurostat Digitalisation in Europe 2026","https:\u002F\u002Fec.europa.eu\u002Feurostat\u002Fweb\u002Finteractive-publications\u002Fdigitalisation-2026",{"value":176,"title":177,"subtitle":178,"detail":179,"copy":180,"source":181,"href":182},"21.3%","Attacks exploiting a weakness","EU cyber attacks • 2024–25","used a weakness","Attackers exploited a vulnerability in 21.3% of intrusion entry points, making it the second most common way in.","ENISA Threat Landscape 2025","https:\u002F\u002Fwww.enisa.europa.eu\u002Fnews\u002Fetl-2025-eu-consistently-targeted-by-diverse-yet-convergent-threat-groups",{"value":184,"title":185,"subtitle":186,"detail":187,"copy":188,"source":189,"href":190},"50%","SMEs not testing annually","European SMEs • 2025","had not tested","More than half of European SMEs went a full year without a cyber security assessment or test.","ENISA NIS Investments Report 2025","https:\u002F\u002Fwww.enisa.europa.eu\u002Fsites\u002Fdefault\u002Ffiles\u002F2025-12\u002FNIS%20Investments%202025%20-%20Main%20report.pdf","A business-wide problem","Cyber incidents stop systems, damage data and expose confidential information. Pensure shows you what an attacker could reach and what to fix first.","markets\u002Feu","Clear cross-border delivery","Pensure coordinates European engagements from an expert Australian team, with euro pricing, agreed testing windows and practical hand-offs for customer, supplier and assurance reviews.","A defined scope with evidence your team can use.","WhAbw5RgTzi9ZSVGEX_nhdJLHyyIADnlnrahO7l3SmI",{"id":199,"audience":200,"extension":99,"heroTitle":201,"marketId":204,"meta":205,"resourceLinks":166,"riskCards":206,"riskEyebrow":228,"riskIntro":229,"riskTitle":230,"stem":231,"trustEyebrow":194,"trustLead":232,"trustTitle":233,"__hash__":234},"marketContent\u002Fmarkets\u002Fgb.yml","UK small and growing businesses",{"lineOne":202,"lineTwo":203},"Nearly half of UK small businesses","had a cyber attack last year.","GB",{},[207,214,220],{"value":208,"title":128,"subtitle":209,"detail":210,"copy":211,"source":212,"href":213},"612,000","All UK businesses • 2025–26","UK businesses","Around 612,000 UK businesses had a cyber attack in the previous 12 months.","UK Cyber Security Breaches Survey 2025–26","https:\u002F\u002Fwww.gov.uk\u002Fgovernment\u002Fstatistics\u002Fcyber-security-breaches-survey-20252026\u002Fcyber-security-breaches-survey-20252026",{"value":215,"title":216,"subtitle":217,"detail":218,"copy":219,"source":212,"href":213},"46%","Small businesses hit","UK small businesses • 2025–26","had an attack","Nearly half of UK small businesses, or 46%, had a cyber attack in the previous 12 months.",{"value":221,"title":222,"subtitle":223,"detail":224,"copy":225,"source":226,"href":227},"£195,000","Average attack cost","All UK businesses • 2025","modelled average","The average significant cyber attack costs a UK business almost £195,000.","UK Government economic impact research","https:\u002F\u002Fwww.gov.uk\u002Fgovernment\u002Fpublications\u002Findependent-research-on-the-economic-impact-of-cyber-attacks-on-the-uk","A small-business problem","Hundreds of thousands of UK businesses were hit. Pensure shows you what an attacker could reach and what to fix first.","A significant cyber attack costs a UK business almost £195,000 on average.","markets\u002Fgb","Pensure coordinates UK engagements from an expert Australian team, with UK-local pricing, agreed testing windows and clear hand-offs for customer and assurance reviews.","Fixed scope, clear timing and practical communication.","URR20k2S5LMhriVjjdTVjBIVxnDZazLzheyRnlKN13U",{"id":236,"audience":237,"extension":99,"heroTitle":238,"marketId":241,"meta":242,"resourceLinks":166,"riskCards":243,"riskEyebrow":228,"riskIntro":265,"riskTitle":266,"stem":267,"trustEyebrow":268,"trustLead":269,"trustTitle":270,"__hash__":271},"marketContent\u002Fmarkets\u002Fnz.yml","New Zealand small and growing businesses",{"lineOne":239,"lineTwo":240},"More than half of NZ small businesses","faced a cyber threat in six months.","NZ",{},[244,252,260],{"value":245,"title":246,"subtitle":247,"detail":248,"copy":249,"source":250,"href":251},"53%","Small businesses targeted","New Zealand SMEs • Jan–Jun 2025","faced a threat","More than half of New Zealand SMEs faced a cyber threat between January and June 2025.","New Zealand NCSC Cyber Threat Report 2025","https:\u002F\u002Fwww.ncsc.govt.nz\u002Finsights-and-research\u002Fcyber-threat-reports\u002Fcyber-threat-report-2025\u002Fjudgement-2\u002F",{"value":253,"title":254,"subtitle":255,"detail":256,"copy":257,"source":258,"href":259},"5,995","Cyber incidents","New Zealand • 2024–25","reports received","The NCSC received 5,995 cyber incident reports in 2024–25.","New Zealand NCSC by the numbers","https:\u002F\u002Fwww.ncsc.govt.nz\u002Finsights-and-research\u002Fcyber-threat-reports\u002Fcyber-threat-report-2025\u002Fby-the-numbers-2024-25\u002F",{"value":261,"title":262,"subtitle":255,"detail":263,"copy":264,"source":258,"href":259},"NZ$26.9m","Direct losses","in direct losses","The NCSC recorded NZ$26.9 million in direct losses from cyber incidents in 2024–25.","Cyber threats reach small businesses as well as large organisations. Pensure shows you what an attacker could reach and what to fix first.","Cyber incidents caused NZ$26.9 million in direct losses in 2024–25.","markets\u002Fnz","Regional delivery","Pensure coordinates New Zealand engagements from an expert Australian team, with New Zealand-dollar pricing, agreed testing windows and clear hand-offs for customer and assurance reviews.","Practical coordination for New Zealand teams.","FZk5fmJvCagGK5l-nX9DXH229BqJO2LvIzZVBVhoIow",{"id":273,"audience":274,"extension":99,"heroTitle":275,"marketId":277,"meta":278,"resourceLinks":166,"riskCards":279,"riskEyebrow":228,"riskIntro":298,"riskTitle":299,"stem":300,"trustEyebrow":301,"trustLead":302,"trustTitle":303,"__hash__":304},"marketContent\u002Fmarkets\u002Fsg.yml","Singapore small and growing businesses",{"lineOne":276,"lineTwo":203},"More than 8 in 10 businesses","SG",{},[280,286,291],{"value":281,"title":128,"subtitle":282,"detail":218,"copy":283,"source":284,"href":285},"80%+","Singapore businesses • 2025","More than 8 in 10 Singapore businesses had at least one cyber attack last year.","Cyber Security Agency of Singapore","https:\u002F\u002Fwww.csa.gov.sg\u002Fnews-events\u002Fspeeches\u002Fopening-remarks-by-senior-minister-of-state-for-digital-development-and-information-mr-tan-kiat-how-for-sg-cyber-safe-for-enterprises\u002F",{"value":287,"title":288,"subtitle":282,"detail":289,"copy":290,"source":284,"href":285},"99%","Attacks causing harm","caused harm","Almost every business hit suffered disruption, data loss, reputational damage or another business impact.",{"value":292,"title":293,"subtitle":294,"detail":295,"copy":296,"source":284,"href":297},"165","Ransomware cases","Singapore • 2025","cases reported","CSA received 165 ransomware reports in 2025. Small and medium businesses were hit hardest.","https:\u002F\u002Fwww.csa.gov.sg\u002Fnews-events\u002Fpress-releases\u002Fcsa-s-initiatives-to-strengthen-singapore-s-cyber-defences-amid-an-ai-driven-threat-landscape\u002F","Cybercriminals increasingly target small businesses, which remain disproportionately affected by ransomware. Pensure shows you what an attacker could reach and what to fix first.","Almost every Singapore business hit suffered disruption, data loss or other harm.","markets\u002Fsg","Regional coordination","Pensure coordinates Singapore engagements from an expert Australian team, with Singapore-dollar pricing, agreed testing windows and clear evidence for customers and assurance reviews.","Clear scope and practical communication for Singapore teams.","dslA7YUm1DW2_RwCuHc2ijWLA8qzN-7KS4GYlrRv74o",{"id":306,"audience":307,"extension":99,"heroTitle":308,"marketId":310,"meta":311,"resourceLinks":166,"riskCards":312,"riskEyebrow":228,"riskIntro":332,"riskTitle":333,"stem":334,"trustEyebrow":194,"trustLead":335,"trustTitle":336,"__hash__":337},"marketContent\u002Fmarkets\u002Fus.yml","US small and mid-sized businesses",{"lineOne":309,"lineTwo":113},"4 in 5 US small businesses","US",{},[313,319,325],{"value":314,"title":216,"subtitle":315,"detail":130,"copy":316,"source":317,"href":318},"81%","US small businesses • 2025","4 in 5 US small businesses had a cyber incident in the previous 12 months.","ITRC Business Impact Report 2025","https:\u002F\u002Fwww.idtheftcenter.org\u002Fpost\u002F2025-business-impact-report-cybercrime-costs-passed-consumers\u002F",{"value":320,"title":321,"subtitle":322,"detail":323,"copy":324,"source":317,"href":318},"US$250k+","Cost of an incident","Affected US small businesses • 2025","","Nearly 2 in 3 affected small businesses lost more than US$250,000 through lost revenue, recovery costs and fines.",{"value":326,"title":177,"subtitle":327,"detail":328,"copy":329,"source":330,"href":331},"31%","Global breaches • DBIR 2026","started this way","Nearly 1 in 3 breaches began with attackers exploiting a software vulnerability.","Verizon 2026 DBIR","https:\u002F\u002Fwww.verizon.com\u002Fbusiness\u002Fresources\u002Freports\u002Fdbir\u002F","A cyber incident can cost hundreds of thousands of dollars, and attackers increasingly exploit technical weaknesses to get in. Pensure shows you what they could reach and what to fix first.","Nearly 2 in 3 affected US small businesses lost more than US$250,000.","markets\u002Fus","Pensure coordinates US engagements from an expert Australian team, with US-dollar pricing, agreed testing windows and practical evidence for customers, insurers and compliance reviews.","A defined test with no procurement fog.","4utbMKyoMost5p3aC5SXh-VNMClV-4Vx4kyvOFMe1Iw",1788789303485]