Skip to content
StrikeCyberStrikeCyber
Canberra, ACT

Penetration Testing Canberra

IRAP-aligned offensive testing for Commonwealth agencies, defence industry and the suppliers who serve them.

AdelaideBrisbaneCanberraDarwinGold CoastHobartMelbournePerthSydneyBallaratBendigoCairnsGeelongLauncestonMackayNewcastleRockhamptonSunshine CoastToowoombaTownsvilleWollongong
Canberra, ACT — where StrikeCyber delivers penetration testing on site
Canberra, ACT

Certified operators on site across Canberra.

Penetration Testing for Canberra Organisations

Canberra is the only Australian city where the dominant industry is the Commonwealth itself. Departments and agencies headquartered across Parkes, Barton, Civic, Woden, Belconnen and the airport precinct run the systems that deliver welfare, tax, health, border, defence and national security functions for the entire country. Around them sits an ecosystem of systems integrators, software vendors, managed service providers, consultancies and defence industry companies whose business depends on meeting the Commonwealth's security requirements, and whose networks are attractive to adversaries precisely because they connect to government.

The Australian Signals Directorate has been explicit that government and its supply chain are under sustained targeting by state-aligned actors seeking access to policy, defence and intelligence information, and by criminal groups seeking data and leverage. The response has been a maturing policy framework: the Protective Security Policy Framework setting governance expectations, the Information Security Manual setting technical controls, the Essential Eight defining a minimum maturity baseline, and the Infosec Registered Assessors Program providing independent assessment of systems before they are authorised to operate. Penetration testing sits underneath all of this as the practical test of whether controls work when someone capable tries to defeat them.

Canberra also has an ACT Government serving a territory of nearly half a million people, the Australian National University and the University of Canberra with significant national security and policy research, Canberra Hospital and the new Canberra Hospital expansion, a professional services sector built around government advisory, and a dense cluster of peak bodies, associations and not-for-profits with sensitive membership data. Each needs testing scoped to its own obligations and threat profile.

What We Test

External attack surface

Agencies and suppliers accumulate internet-facing assets through programs, pilots and legacy systems. Our autonomous reconnaissance and continuous attack-surface validation map domains, subdomains, remote access gateways, cloud assets, exposed management interfaces and leaked credentials across the estate. A certified operator validates what is genuinely reachable and exploitable, reporting against the relevant ISM controls for gateway and perimeter security.

Internal network and Active Directory

An on-site operator at your Canberra premises, or a shipped device, simulates a compromised staff or contractor workstation and maps privilege escalation, lateral movement and the path to domain administrator and sensitive systems. We test whether administrative privilege restrictions, multi-factor authentication, application control and network segmentation hold up in practice, and report against the corresponding Essential Eight strategies and ISM controls.

Web applications and APIs

Citizen-facing digital services, grants and case management systems, staff portals, data exchange APIs between agencies, and SaaS platforms delivered to government. Testing follows the OWASP Web Security Testing Guide and API Security Top 10, with attention to authentication integration with government identity services, authorisation across roles and organisations, input handling and business logic.

Cloud and identity

Azure, AWS, Google Cloud and Microsoft 365 configuration and exploitation-led testing, including Entra ID conditional access, privileged roles, service principals, hybrid identity and the hardening expectations in ASD's cloud and Microsoft 365 guidance. We test whether the configuration an IRAP assessor will review actually resists an adversary.

Mobile applications

Government service and workforce apps on iOS and Android, including local data handling, authentication, certificate pinning and backend API authorisation.

Wireless, physical and social engineering

Corporate, guest and visitor wireless at Canberra offices; physical intrusion testing of premises and secure areas where authorised; and phishing, vishing and pretext campaigns, including lures built around ministerial correspondence, procurement and security clearance processes, which are the themes real adversaries use against Canberra targets.

Canberra Compliance and Regulatory Drivers

The Protective Security Policy Framework requires Commonwealth entities to manage security risk across governance, information, personnel and physical domains and to report annually to their portfolio minister. Within it, the Information Security Manual provides the detailed technical controls for systems, and the Essential Eight maturity model sets the minimum baseline that non-corporate Commonwealth entities are required to implement to Maturity Level Two. Penetration testing is explicitly recognised as a form of security assessment that supports system authorisation, and a test that reports against ISM control identifiers saves your security advisers weeks of mapping work.

Systems that process government information are typically assessed under the Infosec Registered Assessors Program before an authorising officer grants authorisation to operate. StrikeCyber does not conduct IRAP assessments; what we provide is IRAP-aligned penetration testing whose scope and reporting are designed to serve as technical evidence within that assessment, supporting the work of your IRAP assessor and authorising officer. Suppliers to government inherit these requirements through contract clauses and the Hosting Certification Framework, and defence industry companies face the Defence Industry Security Program in addition.

ACT Government agencies operate under the ACT Government's protective security and cyber policies, which align with the PSPF and the Essential Eight. Universities face the Commonwealth foreign interference guidelines, which specifically recommend penetration testing of sensitive research environments. Across all sectors in Canberra, the Privacy Act and the Notifiable Data Breaches scheme apply, and the Essential Eight is the benchmark that auditors, insurers and agency customers ask about first.

How an Engagement Runs

Scoping. A conversation with your security adviser, CISO or delivery lead to understand the system, its classification and authorisation status, the ISM controls in play and what evidence your assessor or customer needs. You receive a fixed-scope, fixed-price proposal and rules of engagement tailored to government handling requirements.

Kick-off. We confirm targets, test accounts and roles, emergency contacts, testing windows, and agree how findings and evidence will be stored and transmitted in line with your handling rules.

Testing. Remote components run from our Brisbane headquarters while on-site components are delivered in Canberra by cleared operators where required. Methodology draws on PTES, NIST SP 800-115, OSSTMM and OWASP, mapped to MITRE ATT&CK and cross-referenced to ISM controls and Essential Eight strategies. AI-augmented reconnaissance and continuous attack-surface validation broaden coverage; certified human operators exploit, chain findings and judge impact.

Real-time critical findings. Confirmed critical issues are raised the same day through the agreed channel, with enough detail to support containment and any mandatory reporting.

Draft report. Executive summary for the authorising officer and executive, a risk-rated findings register with evidence and reproduction steps, ISM and Essential Eight mapping, and prioritised remediation guidance.

Final report and debrief. After your review we issue the final report and present it in Canberra or by video to security, technical and executive audiences.

Optional retest. Remediated findings are retested, typically within one business day per component, and the report reissued with closure status for your assessor and authorising officer.

Why Canberra Organisations Choose StrikeCyber

Canberra buyers are fluent in the ISM and sceptical of vendors who are not. Our operators hold recognised offensive security certifications and write reports in the language your security advisers and IRAP assessors use, leading engagements personally.

We combine AI-augmented reconnaissance and continuous attack-surface validation with human exploitation and judgement, giving agencies and suppliers broad discovery across complex estates without the false positives that waste security team time. Pricing is fixed-scope and agreed before work begins, with Canberra travel included, which suits procurement under the Commonwealth Procurement Rules. As a Brisbane-headquartered firm delivering nationally, we support organisations with presence in Canberra, Sydney, Adelaide and beyond under a single consistent methodology.

Reporting That Supports Authorisation

In Canberra, a penetration test is rarely an end in itself. It is evidence in a larger process that ends with an authorising officer deciding whether a system can operate. That process runs on the language of the Information Security Manual, and a report that speaks a different dialect creates weeks of translation work for your security advisers. We write findings against ISM control identifiers and Essential Eight mitigation strategies, indicate where an observed weakness undermines a claimed maturity level, and structure the report so it drops directly into your system security documentation and supports your IRAP assessor's work rather than duplicating or contradicting it.

We are careful about the boundary of our role. StrikeCyber does not perform IRAP assessments and does not present itself as an assessor. What we provide is independent technical testing, scoped and reported to serve as evidence within your assessment and authorisation activity, complementing the assessor you engage and the security adviser who guides you to authorisation to operate. That clarity matters to Canberra buyers, who have seen vendors blur the line and create problems at authorisation time. For agencies uplifting toward Essential Eight Maturity Level Two, our testing also gives an honest answer to whether the controls you have deployed actually resist an adversary, which is the difference between genuine maturity and a compliant-looking spreadsheet.

Agencies and primes with established security operations often progress to a red team engagement that tests whether a realistic adversary is detected and contained. Suppliers with changing external footprints add continuous vulnerability assessments between annual penetration tests. Organisations preparing for IRAP assessment, Essential Eight uplift or ISO 27001 frequently begin with a cyber maturity level assessment against the Essential Eight and ISO 27001. Call 1300 654 898 to discuss your Canberra system and its authorisation pathway.

FAQ

Penetration testing in Canberra: your questions

How much does a penetration test cost in Canberra?

Cost depends on scope. A single application or external perimeter test for a government supplier is typically a low to mid four-figure engagement. A program covering an agency's internal network, Active Directory, cloud tenancy and several systems, reported against ISM controls to support an IRAP assessment, is scoped over several weeks. Every quote is fixed-scope and fixed-price with Canberra travel included.

Are you IRAP assessors?

No. StrikeCyber does not perform IRAP assessments. What we provide is IRAP-aligned penetration testing: independent technical testing scoped and reported against the ISM controls an IRAP assessor will examine. Agencies and suppliers use our reports as evidence within their IRAP assessment and authorisation process. We work alongside your chosen IRAP assessor rather than replacing them.

Can you test systems handling PROTECTED information?

We test systems and environments designed to handle information up to PROTECTED, working within your handling requirements and the conditions set by your security team. Scoping agrees what is in bounds, how findings and evidence are stored and transmitted, and which components are tested on site. For higher classifications, speak with us about what is feasible and appropriate for your environment.

How do you report against the Essential Eight?

Our reports map findings to the relevant Essential Eight mitigation strategies and indicate where observed weaknesses undermine a claimed maturity level. Penetration testing is the most reliable way to check whether application control, patching, macro settings, hardening, administrative privilege restrictions, multi-factor authentication and backups actually hold up against an adversary rather than looking compliant on paper.

Do you work with suppliers to government as well as agencies?

Yes, and suppliers make up a large share of our Canberra work. Systems integrators, SaaS providers, managed service providers and consultancies delivering to the Commonwealth are expected to meet ISM and PSPF requirements through their contracts, and agencies increasingly ask for independent testing evidence during procurement and at renewal. We scope to what your agency customer actually requires.

Do you come to Canberra for on-site testing?

We do. Internal network, Active Directory, wireless and physical components are delivered on site by a travelling operator who holds appropriate clearances where required, with travel built into the fixed scope. External, cloud and application testing runs remotely from our Brisbane headquarters, often in parallel.

Is retesting available?

Retesting is an optional add-on, typically completed within one business day per component once remediation is confirmed. The reissued report shows each finding as closed or still open, which is what IRAP assessors, agency security advisers and authorising officers want to see before authorisation to operate.

Nearby

Also serving Australian Capital Territory

Get a fixed-scope quote for Canberra

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation