Skip to content
StrikeCyberStrikeCyber
Research topic

Compliance

Essential Eight, ISO 27001, APRA CPS 234, SOCI and IRAP: how security testing maps to Australian compliance.

IRAP ISM Security Testing for Government and Suppliers in Australia

Government systems and their suppliers are held to the ISM and PSPF. Here is how IRAP, the ISM and offensive security testing fit together, and where IRAP-aligned testing adds value ahead of a formal assessment.

Cyber Security for Mining and Energy in Australia: Securing OT and Critical Infrastructure

Mining, energy and utilities run the systems that keep Australia moving. This briefing explains the IT and OT convergence risk, ICS and SCADA exposure, and how safety-first offensive testing supports SOCI and IEC 62443 without disrupting operations.

SOCI Act Critical Infrastructure Security: How Offensive Testing Supports Compliance

The Security of Critical Infrastructure Act sets real obligations for responsible entities across eleven sectors. Here is how the framework works and how offensive security testing strengthens both compliance and resilience.

PCI DSS Penetration Testing Requirements Under Version 4.0

PCI DSS v4.0 requires internal and external penetration testing, plus segmentation testing, at least annually and after significant change. Here is what Requirement 11.4 asks for, who needs it and how to scope the cardholder data environment.

APRA CPS 234 Penetration Testing: A Practical Compliance Guide for 2026

APRA CPS 234 requires regulated entities to systematically test the effectiveness of their information security controls. Here is what that means in practice and how offensive security testing builds the evidence APRA expects.

Cyber Security for Government in Australia

Government agencies and their suppliers protect citizen data and critical services under some of the most demanding security frameworks in the country. This briefing covers the ISM, PSPF, Essential Eight and how offensive testing builds real assurance.

ISO 27001 Penetration Testing: Scope, Frequency and Evidence

ISO 27001 does not name penetration testing as a mandatory control, but auditors expect it as evidence that technical risks are managed. Here is where it fits in the 2022 standard, what to scope, how often to test and what evidence to keep.

Essential Eight Penetration Testing: Validating Your Controls

A maturity assessment confirms your Essential Eight controls are configured. Penetration testing proves they actually work. Here is how adversary testing validates the Essential Eight and produces evidence auditors and boards trust.

Cyber Security for Financial Services in Australia

Australian financial services firms hold the data and money attackers want most. This briefing looks at the threats facing banks, insurers, super funds and fintechs, the APRA obligations that shape their programs, and why offensive testing is now core assurance.

ASD Essential Eight Explained: The Eight Strategies and Maturity Levels

The ASD Essential Eight is Australia's baseline set of eight mitigation strategies for defending against cyber attacks. Here is what each strategy does, how the maturity levels work, who must comply and how to uplift.

Supply Chain and Third-Party Risk for Australian Organisations in 2026

Australian organisations increasingly depend on software vendors, managed service providers and cloud platforms. This guide explains supply chain risk and how to assess and test your third-party exposure.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation