The Challenge
The enterprise is a high-profile ASX-listed group with operations across multiple countries, holding sensitive corporate information, investor data and the systems that move significant financial transactions. As a public company, a material breach is not only an operational problem but a disclosure event with direct consequences for share price, shareholder trust and board accountability.
Global scale brought a large and constantly shifting attack surface: many subsidiaries, inconsistent security maturity across acquired businesses, cloud environments provisioned by different teams, and a broad third-party ecosystem. Executives were also attractive spear-phishing targets given their access and public profile. The board wanted proactive, adversary-grade assurance that the group could resist a targeted attack and that its posture stood up against its continuous disclosure and governance obligations.
Our Approach
StrikeCyber scoped an objective-based red team supported by focused penetration testing, designed to answer the board's real question: could a capable attacker reach the crown-jewel financial and investor systems?
- Reconnaissance and external attack surface mapping across the group's global footprint using StrikeCyber's autonomous reconnaissance, part of our AI-augmented offensive security platform, to find forgotten assets, exposed services and OSINT that a targeted attacker would exploit.
- Red teaming against agreed objectives, emulating techniques from MITRE ATT&CK to test not just prevention but detection and response across corporate networks, cloud and financial platforms.
- Penetration testing of high-value applications and cloud environments, plus controlled executive spear-phishing to assess social-engineering exposure at the top of the organisation.
Every automated lead was validated and exploited by hand by expert operators, so the group received confirmed, business-relevant attack paths. Findings flowed into a live client portal with AI-accelerated reporting, giving both technical teams and executives a shared, real-time view.
What We Found
- A forgotten external asset as a foothold. Autonomous reconnaissance uncovered an unmonitored subsidiary system whose exposed service gave operators an initial foothold outside the well-defended core.
- Executive spear-phishing success. A targeted campaign against senior staff recovered credentials, and inconsistent MFA on cloud and email let those credentials be reused against sensitive systems.
- Cloud misconfiguration and secrets in code. Over-permissive IAM roles, a publicly readable storage bucket and secrets committed to a code repository combined to expose access to financial data.
- A lateral path toward financial systems. Weak internal segmentation between a subsidiary and the group core, plus Kerberoastable service accounts, gave a demonstrable route toward investor and transaction platforms.
The Outcome
The group received a board-ready remediation plan that translated technical attack paths into business and disclosure risk. The exposed subsidiary asset was decommissioned, MFA was enforced consistently across cloud and email, the cloud IAM and storage misconfigurations were corrected, and the leaked secrets were rotated with repository scanning added to prevent recurrence. Segmentation between subsidiaries and the group core was tightened to break the lateral path.
A follow-up retest confirmed the critical findings were remediated and verified, and that the demonstrated routes toward financial and investor systems were closed. Detection of the simulated activity also improved. The company gained documented, adversary-tested assurance to support its continuous disclosure position and governance reporting, reinforcing shareholder trust and alignment with Australian regulatory expectations.
Why It Matters
For a listed enterprise, cyber risk is governance risk, and the weakest link is often a subsidiary or forgotten asset far from the well-funded core. Objective-based red teaming across the whole group, validated by human operators, shows the board how an attacker would actually reach the systems that move money and move markets, so investment lands where it protects both operations and shareholder value. To pressure-test your group's posture, get in touch.