Skip to content
StrikeCyberStrikeCyber
Adelaide, SA

Penetration Testing Adelaide

Defence-grade offensive security for the city building Australia's submarines, frigates, satellites and space capability.

AdelaideBrisbaneCanberraDarwinGold CoastHobartMelbournePerthSydneyBallaratBendigoCairnsGeelongLauncestonMackayNewcastleRockhamptonSunshine CoastToowoombaTownsvilleWollongong
Adelaide, SA — where StrikeCyber delivers penetration testing on site
Adelaide, SA

Certified operators on site across Adelaide.

Penetration Testing for Adelaide Organisations

Adelaide has become the centre of gravity for Australian defence industry. The Osborne Naval Shipyard on the Port River is where the Hunter class frigates are being built and where the nuclear-powered submarine program under AUKUS will be constructed. RAAF Base Edinburgh and the Defence Science and Technology Group at Edinburgh Parks anchor a cluster of primes, systems integrators and research organisations in the northern suburbs. Around them sits a supply chain of several hundred small and medium businesses machining components, writing software, integrating systems and providing services, each one holding information an adversary would value and each one contractually required to protect it.

That supply chain is precisely where well-resourced threat actors focus, because a small engineering firm with a flat network and a shared password is a far easier entry point than a prime contractor's hardened enclave. Defence has responded with the Defence Industry Security Program and tightening contractual security requirements that flow down through every tier. For Adelaide businesses, independent penetration testing is no longer optional; it is how you prove to your customer that you deserve the contract.

The city's technology story extends beyond defence. Lot Fourteen on North Terrace, the former Royal Adelaide Hospital site, hosts the Australian Space Agency, the Australian Institute for Machine Learning, cyber security and space companies, and a startup community that sells into government and defence from day one. The new Royal Adelaide Hospital, the South Australian Health and Medical Research Institute, the Women's and Children's Hospital and SA Health's statewide networks carry clinical and research data. The University of Adelaide, Flinders University and the University of South Australia, now merging into Adelaide University, hold defence-relevant research. Tonsley and the northern manufacturing corridor host advanced manufacturers, and the state's globally known wine and agribusiness sectors increasingly run on connected operational and logistics systems.

What We Test

External attack surface

Defence subcontractors and technology companies often have more internet exposure than they realise: remote access for engineers, file transfer portals for drawings and specifications, development environments and cloud storage. Our autonomous reconnaissance and continuous attack-surface validation map every exposed asset, certificate, service and leaked credential, and a certified operator validates what is genuinely exploitable and what a prime contractor's security assessor would flag.

Internal network and Active Directory

An on-site operator in your Adelaide office, or a shipped device, simulates a compromised engineer's workstation or a malicious insider and maps the path to domain administrator and on to the file shares, PLM and CAD systems, and project environments where Defence information lives. For DISP members, we pay particular attention to whether the controls that separate Defence project data from the rest of the business actually hold.

Web applications and APIs

Ground segment and mission software, customer and supplier portals, SA Government citizen services, patient and booking portals, student and research systems and SaaS products. Testing follows the OWASP Web Security Testing Guide and API Security Top 10, with emphasis on authentication, authorisation across roles and tenants, integration points and business logic.

Cloud and identity

Azure, AWS, Google Cloud and Microsoft 365 configuration and exploitation-led testing, including Entra ID conditional access, privileged roles and hybrid identity. Many defence suppliers run Microsoft 365 tenancies that have grown organically, and the gap between the tenancy settings a DISP assessor expects and what is actually configured is a common finding.

Product and embedded systems

For manufacturers and space companies, security assessment of firmware, embedded interfaces and the software that configures and controls delivered systems, scoped to your product and your customer's requirements.

Wireless, physical and social engineering

Corporate and guest wireless at Adelaide offices, workshops and labs; physical intrusion testing where authorised, including tailgating into engineering areas; and phishing, vishing and pretext campaigns, including scenarios that mimic prime contractor procurement and Defence correspondence, which are realistic lures for this sector.

Adelaide Compliance and Regulatory Drivers

The Defence Industry Security Program sets the security baseline for businesses that work with Defence. Membership requires governance, personnel, physical and ICT security controls appropriate to the level of membership, with ICT controls drawn from the Australian Government Information Security Manual and the Essential Eight. Prime contractors flow these requirements down through their supply chains and increasingly ask for independent testing evidence as a condition of subcontract. AUKUS and the submarine program are bringing additional scrutiny of supply chain security, and Adelaide businesses positioning for that work need to be ready.

South Australian Government agencies operate under the South Australian Cyber Security Framework, which requires proportionate controls and annual attestation, and suppliers delivering digital services to government are expected to demonstrate equivalent assurance. Operators of critical infrastructure in South Australia, including the port, energy generators and networks, water, defence industry facilities and major hospitals, carry obligations under the Security of Critical Infrastructure Act and its risk management program rules.

Health services operate under the Privacy Act, the Notifiable Data Breaches scheme and SA Health policy. Universities face the Commonwealth foreign interference guidelines, which are directly relevant to defence-funded research in Adelaide. Space sector companies selling into government face the Essential Eight and, for some contracts, ISM-aligned expectations. Across all sectors, ISO 27001 is the certification customers and insurers ask about, and penetration testing is core evidence for its control effectiveness requirements.

How an Engagement Runs

Scoping. A conversation with your security officer, IT lead or founder to understand your systems, your customers' requirements and the evidence the report needs to provide. For DISP members we align scope to the systems handling Defence information. You receive a fixed-scope, fixed-price proposal and rules of engagement.

Kick-off. We confirm targets, test accounts, emergency contacts, testing windows and any handling requirements for sensitive project data. Testing is conducted with appropriate care for classified and controlled environments, and our operators work within your handling rules.

Testing. Remote components begin from our Brisbane headquarters while on-site components are delivered in Adelaide. Methodology draws on PTES, NIST SP 800-115, OSSTMM and OWASP, mapped to MITRE ATT&CK. AI-augmented reconnaissance and continuous attack-surface validation broaden coverage; certified human operators exploit, chain findings and judge impact.

Real-time critical findings. Confirmed critical issues are raised the same day so containment can begin immediately.

Draft report. Executive summary for directors and prime contractor stakeholders, a risk-rated findings register with evidence and reproduction steps, and remediation guidance mapped to ISM and Essential Eight controls where relevant.

Final report and debrief. After your review we issue the final report and present it in Adelaide or by video.

Optional retest. Remediated findings are retested, typically within one business day per component, and the report reissued with closure status.

Why Adelaide Organisations Choose StrikeCyber

Adelaide's defence and technology businesses need a tester who understands what their customers are actually checking and can write a report that satisfies a prime contractor's security assessor while still being understandable to a business owner. Our operators hold recognised offensive security certifications and lead engagements directly.

We combine AI-augmented reconnaissance and continuous attack-surface validation with human exploitation and judgement, giving small supply chain firms enterprise-quality coverage at a price that fits their size, and giving primes, government and universities the depth their estates demand. Pricing is fixed-scope and agreed before work begins, with Adelaide travel included. As a Brisbane-headquartered firm delivering nationally, we support companies with sites in Adelaide, Canberra, Perth and Darwin under one consistent methodology.

Testing That Satisfies the Prime and the Owner

The Adelaide defence supply chain has a particular problem: the security requirements are written for large organisations, but most of the companies that must meet them are small engineering, software and services firms without a security team. A prime contractor's assessor expects controls aligned to the Information Security Manual and evidence that they work, while the business owner needs to keep machining parts and winning contracts. A report full of unexplained jargon helps neither. We write for both audiences at once: findings mapped to the ISM controls and Essential Eight maturity levels your customer will check, alongside plain-language explanations and prioritised, affordable remediation an owner can action without a consultant to translate it.

We also scope realistically. A twenty-person firm handling Defence drawings does not need the same test as a prime, but it does need the specific things that matter: how Defence information is separated from the rest of the business, whether remote access and file transfer are locked down, and whether the Microsoft 365 tenancy is hardened to the level an assessor expects. We focus the engagement there, prove or disprove those controls, and give you evidence you can hand straight to your prime or use in DISP reporting. For companies positioning for submarine and frigate work, getting this right now is what keeps you eligible as scrutiny of the supply chain intensifies.

Defence primes and larger Adelaide organisations often progress to a red team engagement that tests whether a realistic intrusion is detected and contained before it reaches project data. Supply chain businesses with changing external footprints add continuous vulnerability assessments between annual penetration tests. Companies preparing for DISP membership, SACSF attestation or ISO 27001 certification frequently start with a cyber maturity level assessment against the Essential Eight and ISO 27001. Call 1300 654 898 to talk through your Adelaide requirements.

FAQ

Penetration testing in Adelaide: your questions

How much does a penetration test cost in Adelaide?

Scope drives cost. A focused web application or external perimeter test is typically a low to mid four-figure engagement. A defence supply chain program covering internal network, Active Directory, cloud and several applications, written to support DISP membership evidence, is a larger scoped engagement over several weeks. All quotes are fixed-scope and fixed-price with Adelaide travel included.

Can you help with Defence Industry Security Program requirements?

Yes. DISP membership at the various levels requires members to implement and maintain ICT security controls aligned to the Information Security Manual and the Essential Eight, and to evidence their effectiveness. Penetration testing provides that evidence. We scope tests to the systems that handle Defence information, report against ISM control language and Essential Eight maturity levels, and produce findings your security officer can use directly in DISP reporting.

Do you test for small defence subcontractors as well as primes?

The majority of Adelaide's defence industry is small and medium businesses in the supply chain of the primes at Osborne and Edinburgh. These firms face the same contractual security requirements with far smaller teams. We scope pragmatic, fixed-price tests that satisfy prime contractor and DISP expectations without enterprise overhead, and we explain findings in plain terms for owners who do not have a security department.

Do you work with Lot Fourteen and space sector companies?

We do. Startups and scale-ups at Lot Fourteen, companies connected to the Australian Space Agency and the wider SmartSat and Australian space ecosystem typically need testing for ground segment software, mission control interfaces, customer platforms and cloud environments, often to satisfy a government or defence customer. We tailor scope to what your customer's security questionnaire actually requires.

Do you come to Adelaide for on-site work?

Yes. Internal network, Active Directory, wireless and physical testing are delivered on site at your Adelaide premises by a travelling operator, with travel priced into the fixed scope. External, cloud and application testing is performed remotely from our Brisbane headquarters, usually in parallel to keep the engagement short.

Can you support South Australian Government agencies under the SACSF?

Yes. The South Australian Cyber Security Framework requires agencies to implement controls proportionate to their risk profile and to attest annually. Penetration testing is direct evidence for the technical control requirements. We report in language that maps to the SACSF and the Essential Eight so your attestation pack is straightforward to assemble.

Is a retest available?

Retesting is an optional add-on, typically completed within one business day per component after you confirm remediation. The report is reissued with closure status for each finding, which is the record DISP security officers, prime contractors and auditors want to see.

Nearby

Also serving South Australia

Get a fixed-scope quote for Adelaide

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation