Penetration Testing for Adelaide Organisations
Adelaide has become the centre of gravity for Australian defence industry. The Osborne Naval Shipyard on the Port River is where the Hunter class frigates are being built and where the nuclear-powered submarine program under AUKUS will be constructed. RAAF Base Edinburgh and the Defence Science and Technology Group at Edinburgh Parks anchor a cluster of primes, systems integrators and research organisations in the northern suburbs. Around them sits a supply chain of several hundred small and medium businesses machining components, writing software, integrating systems and providing services, each one holding information an adversary would value and each one contractually required to protect it.
That supply chain is precisely where well-resourced threat actors focus, because a small engineering firm with a flat network and a shared password is a far easier entry point than a prime contractor's hardened enclave. Defence has responded with the Defence Industry Security Program and tightening contractual security requirements that flow down through every tier. For Adelaide businesses, independent penetration testing is no longer optional; it is how you prove to your customer that you deserve the contract.
The city's technology story extends beyond defence. Lot Fourteen on North Terrace, the former Royal Adelaide Hospital site, hosts the Australian Space Agency, the Australian Institute for Machine Learning, cyber security and space companies, and a startup community that sells into government and defence from day one. The new Royal Adelaide Hospital, the South Australian Health and Medical Research Institute, the Women's and Children's Hospital and SA Health's statewide networks carry clinical and research data. The University of Adelaide, Flinders University and the University of South Australia, now merging into Adelaide University, hold defence-relevant research. Tonsley and the northern manufacturing corridor host advanced manufacturers, and the state's globally known wine and agribusiness sectors increasingly run on connected operational and logistics systems.
What We Test
External attack surface
Defence subcontractors and technology companies often have more internet exposure than they realise: remote access for engineers, file transfer portals for drawings and specifications, development environments and cloud storage. Our autonomous reconnaissance and continuous attack-surface validation map every exposed asset, certificate, service and leaked credential, and a certified operator validates what is genuinely exploitable and what a prime contractor's security assessor would flag.
Internal network and Active Directory
An on-site operator in your Adelaide office, or a shipped device, simulates a compromised engineer's workstation or a malicious insider and maps the path to domain administrator and on to the file shares, PLM and CAD systems, and project environments where Defence information lives. For DISP members, we pay particular attention to whether the controls that separate Defence project data from the rest of the business actually hold.
Web applications and APIs
Ground segment and mission software, customer and supplier portals, SA Government citizen services, patient and booking portals, student and research systems and SaaS products. Testing follows the OWASP Web Security Testing Guide and API Security Top 10, with emphasis on authentication, authorisation across roles and tenants, integration points and business logic.
Cloud and identity
Azure, AWS, Google Cloud and Microsoft 365 configuration and exploitation-led testing, including Entra ID conditional access, privileged roles and hybrid identity. Many defence suppliers run Microsoft 365 tenancies that have grown organically, and the gap between the tenancy settings a DISP assessor expects and what is actually configured is a common finding.
Product and embedded systems
For manufacturers and space companies, security assessment of firmware, embedded interfaces and the software that configures and controls delivered systems, scoped to your product and your customer's requirements.
Wireless, physical and social engineering
Corporate and guest wireless at Adelaide offices, workshops and labs; physical intrusion testing where authorised, including tailgating into engineering areas; and phishing, vishing and pretext campaigns, including scenarios that mimic prime contractor procurement and Defence correspondence, which are realistic lures for this sector.
Adelaide Compliance and Regulatory Drivers
The Defence Industry Security Program sets the security baseline for businesses that work with Defence. Membership requires governance, personnel, physical and ICT security controls appropriate to the level of membership, with ICT controls drawn from the Australian Government Information Security Manual and the Essential Eight. Prime contractors flow these requirements down through their supply chains and increasingly ask for independent testing evidence as a condition of subcontract. AUKUS and the submarine program are bringing additional scrutiny of supply chain security, and Adelaide businesses positioning for that work need to be ready.
South Australian Government agencies operate under the South Australian Cyber Security Framework, which requires proportionate controls and annual attestation, and suppliers delivering digital services to government are expected to demonstrate equivalent assurance. Operators of critical infrastructure in South Australia, including the port, energy generators and networks, water, defence industry facilities and major hospitals, carry obligations under the Security of Critical Infrastructure Act and its risk management program rules.
Health services operate under the Privacy Act, the Notifiable Data Breaches scheme and SA Health policy. Universities face the Commonwealth foreign interference guidelines, which are directly relevant to defence-funded research in Adelaide. Space sector companies selling into government face the Essential Eight and, for some contracts, ISM-aligned expectations. Across all sectors, ISO 27001 is the certification customers and insurers ask about, and penetration testing is core evidence for its control effectiveness requirements.
How an Engagement Runs
Scoping. A conversation with your security officer, IT lead or founder to understand your systems, your customers' requirements and the evidence the report needs to provide. For DISP members we align scope to the systems handling Defence information. You receive a fixed-scope, fixed-price proposal and rules of engagement.
Kick-off. We confirm targets, test accounts, emergency contacts, testing windows and any handling requirements for sensitive project data. Testing is conducted with appropriate care for classified and controlled environments, and our operators work within your handling rules.
Testing. Remote components begin from our Brisbane headquarters while on-site components are delivered in Adelaide. Methodology draws on PTES, NIST SP 800-115, OSSTMM and OWASP, mapped to MITRE ATT&CK. AI-augmented reconnaissance and continuous attack-surface validation broaden coverage; certified human operators exploit, chain findings and judge impact.
Real-time critical findings. Confirmed critical issues are raised the same day so containment can begin immediately.
Draft report. Executive summary for directors and prime contractor stakeholders, a risk-rated findings register with evidence and reproduction steps, and remediation guidance mapped to ISM and Essential Eight controls where relevant.
Final report and debrief. After your review we issue the final report and present it in Adelaide or by video.
Optional retest. Remediated findings are retested, typically within one business day per component, and the report reissued with closure status.
Why Adelaide Organisations Choose StrikeCyber
Adelaide's defence and technology businesses need a tester who understands what their customers are actually checking and can write a report that satisfies a prime contractor's security assessor while still being understandable to a business owner. Our operators hold recognised offensive security certifications and lead engagements directly.
We combine AI-augmented reconnaissance and continuous attack-surface validation with human exploitation and judgement, giving small supply chain firms enterprise-quality coverage at a price that fits their size, and giving primes, government and universities the depth their estates demand. Pricing is fixed-scope and agreed before work begins, with Adelaide travel included. As a Brisbane-headquartered firm delivering nationally, we support companies with sites in Adelaide, Canberra, Perth and Darwin under one consistent methodology.
Testing That Satisfies the Prime and the Owner
The Adelaide defence supply chain has a particular problem: the security requirements are written for large organisations, but most of the companies that must meet them are small engineering, software and services firms without a security team. A prime contractor's assessor expects controls aligned to the Information Security Manual and evidence that they work, while the business owner needs to keep machining parts and winning contracts. A report full of unexplained jargon helps neither. We write for both audiences at once: findings mapped to the ISM controls and Essential Eight maturity levels your customer will check, alongside plain-language explanations and prioritised, affordable remediation an owner can action without a consultant to translate it.
We also scope realistically. A twenty-person firm handling Defence drawings does not need the same test as a prime, but it does need the specific things that matter: how Defence information is separated from the rest of the business, whether remote access and file transfer are locked down, and whether the Microsoft 365 tenancy is hardened to the level an assessor expects. We focus the engagement there, prove or disprove those controls, and give you evidence you can hand straight to your prime or use in DISP reporting. For companies positioning for submarine and frigate work, getting this right now is what keeps you eligible as scrutiny of the supply chain intensifies.
Related Services
Defence primes and larger Adelaide organisations often progress to a red team engagement that tests whether a realistic intrusion is detected and contained before it reaches project data. Supply chain businesses with changing external footprints add continuous vulnerability assessments between annual penetration tests. Companies preparing for DISP membership, SACSF attestation or ISO 27001 certification frequently start with a cyber maturity level assessment against the Essential Eight and ISO 27001. Call 1300 654 898 to talk through your Adelaide requirements.
