The Challenge
The department delivers essential public services and holds large volumes of citizen data, which makes it a standing target for nation-state actors and financially motivated ransomware crews. Leadership needed hard evidence, not assurances, that its defences could withstand a determined adversary who was willing to spend weeks inside the environment.
The estate was typical of long-standing government: a sprawling Active Directory forest, legacy applications that could not simply be retired, an expanding public-facing footprint, and a broad supply chain of vendors with varying levels of maturity. The department also carried obligations under the Essential Eight and its state information security policy (IS18), and wanted an engagement that spoke to those frameworks in operational terms rather than as a paperwork exercise.
Our Approach
StrikeCyber scoped a full-spectrum, objective-based red teaming engagement rather than a checklist scan. Working with the department's security leadership, we agreed on realistic threat scenarios modelled on the tactics and techniques catalogued in MITRE ATT&CK, then ran the work in phases.
- Reconnaissance and external attack surface mapping using StrikeCyber's autonomous reconnaissance capability, part of our AI-augmented offensive security platform, to inventory internet-facing services, exposed credentials and OSINT-derived intelligence at a scale manual testing cannot match.
- Adversary simulation and red teaming against agreed objectives, including gaining a foothold, escalating privilege and reaching sensitive citizen data stores.
- Internal and external penetration testing across networks, VPN and remote access, plus a review of third-party and supply-chain exposure.
Every machine-generated lead was triaged and exploited by hand by expert operators, so the department received validated attack paths rather than a queue of unconfirmed alerts. Findings streamed into a live client portal as they were confirmed, and AI-accelerated reporting meant remediation guidance reached asset owners while the engagement was still live.
What We Found
- External foothold via an exposed service. An unpatched, internet-facing application gave initial access that OSINT-harvested credentials then extended, confirming a viable entry point for an external attacker.
- A path to domain admin. Chaining Kerberoasting of a weak service account with SMB and NTLM relay opportunities and misconfigured access rights, operators moved laterally and demonstrated a realistic route to full Active Directory compromise.
- Phishing and MFA gaps. A controlled phishing scenario showed that targeted staff would engage, and that inconsistent multi-factor coverage on remote access left several accounts recoverable for an attacker.
- Supply-chain and cloud exposure. Over-permissioned vendor access and misconfigured government cloud storage widened the blast radius well beyond the core network.
The Outcome
The department received a prioritised remediation plan mapped to the Essential Eight and IS18, aligned so that each fix could be reported to executives and auditors in language they already used. Critical findings were remediated and independently verified in a follow-up retest, which confirmed the attack paths to domain admin were closed, MFA coverage was consistent across remote access, and the most exposed external services were removed or hardened.
The measurable result was a materially reduced external attack surface, stronger detection of lateral movement, and board-level assurance that citizen-facing services could withstand the scenarios that were simulated. The department left the engagement with a repeatable testing baseline rather than a one-off snapshot.
Why It Matters
Public-sector bodies cannot choose their adversaries, and the same data that makes them essential makes them worth attacking. Objective-based red teaming, validated by human operators, shows leaders exactly how a breach would unfold and where a single control would have broken the chain. For any organisation holding citizen data at scale, that clarity is what turns a compliance obligation into genuine resilience. If your teams carry that same duty of care, get in touch to scope an engagement.
