Skip to content
StrikeCyberStrikeCyber
State Government

Securing Critical Infrastructure for a State Government Department

A state government department needed to improve cyber resilience against nation-state actors and ransomware groups targeting critical public services.

State Government sector
State Government
Industry
State Government
Services
Red Teaming, Penetration Testing, Adversary Simulation
Engagement
Red team and adversary simulation
Region
Queensland

The Challenge

The department delivers essential public services and holds large volumes of citizen data, which makes it a standing target for nation-state actors and financially motivated ransomware crews. Leadership needed hard evidence, not assurances, that its defences could withstand a determined adversary who was willing to spend weeks inside the environment.

The estate was typical of long-standing government: a sprawling Active Directory forest, legacy applications that could not simply be retired, an expanding public-facing footprint, and a broad supply chain of vendors with varying levels of maturity. The department also carried obligations under the Essential Eight and its state information security policy (IS18), and wanted an engagement that spoke to those frameworks in operational terms rather than as a paperwork exercise.

Our Approach

StrikeCyber scoped a full-spectrum, objective-based red teaming engagement rather than a checklist scan. Working with the department's security leadership, we agreed on realistic threat scenarios modelled on the tactics and techniques catalogued in MITRE ATT&CK, then ran the work in phases.

  • Reconnaissance and external attack surface mapping using StrikeCyber's autonomous reconnaissance capability, part of our AI-augmented offensive security platform, to inventory internet-facing services, exposed credentials and OSINT-derived intelligence at a scale manual testing cannot match.
  • Adversary simulation and red teaming against agreed objectives, including gaining a foothold, escalating privilege and reaching sensitive citizen data stores.
  • Internal and external penetration testing across networks, VPN and remote access, plus a review of third-party and supply-chain exposure.

Every machine-generated lead was triaged and exploited by hand by expert operators, so the department received validated attack paths rather than a queue of unconfirmed alerts. Findings streamed into a live client portal as they were confirmed, and AI-accelerated reporting meant remediation guidance reached asset owners while the engagement was still live.

What We Found

  • External foothold via an exposed service. An unpatched, internet-facing application gave initial access that OSINT-harvested credentials then extended, confirming a viable entry point for an external attacker.
  • A path to domain admin. Chaining Kerberoasting of a weak service account with SMB and NTLM relay opportunities and misconfigured access rights, operators moved laterally and demonstrated a realistic route to full Active Directory compromise.
  • Phishing and MFA gaps. A controlled phishing scenario showed that targeted staff would engage, and that inconsistent multi-factor coverage on remote access left several accounts recoverable for an attacker.
  • Supply-chain and cloud exposure. Over-permissioned vendor access and misconfigured government cloud storage widened the blast radius well beyond the core network.

The Outcome

The department received a prioritised remediation plan mapped to the Essential Eight and IS18, aligned so that each fix could be reported to executives and auditors in language they already used. Critical findings were remediated and independently verified in a follow-up retest, which confirmed the attack paths to domain admin were closed, MFA coverage was consistent across remote access, and the most exposed external services were removed or hardened.

The measurable result was a materially reduced external attack surface, stronger detection of lateral movement, and board-level assurance that citizen-facing services could withstand the scenarios that were simulated. The department left the engagement with a repeatable testing baseline rather than a one-off snapshot.

Why It Matters

Public-sector bodies cannot choose their adversaries, and the same data that makes them essential makes them worth attacking. Objective-based red teaming, validated by human operators, shows leaders exactly how a breach would unfold and where a single control would have broken the chain. For any organisation holding citizen data at scale, that clarity is what turns a compliance obligation into genuine resilience. If your teams carry that same duty of care, get in touch to scope an engagement.

FAQ

About this case study

What does this case study show?

This state government case study is drawn from a genuine engagement, anonymised where needed to protect the client. It shows the challenge, our approach and the outcome.

Can StrikeCyber deliver similar results for our organisation?

Yes. The expert-led, prioritised approach behind this outcome applies across state government and other sectors and organisation sizes. Scope a free consultation to discuss your environment.

How is client confidentiality protected?

Findings and client data are isolated to your organisation and handled in access-limited environments we control in Australia. Nothing is published without the client's consent.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation