Penetration Testing for Canberra Organisations
Canberra is the only Australian city where the dominant industry is the Commonwealth itself. Departments and agencies headquartered across Parkes, Barton, Civic, Woden, Belconnen and the airport precinct run the systems that deliver welfare, tax, health, border, defence and national security functions for the entire country. Around them sits an ecosystem of systems integrators, software vendors, managed service providers, consultancies and defence industry companies whose business depends on meeting the Commonwealth's security requirements, and whose networks are attractive to adversaries precisely because they connect to government.
The Australian Signals Directorate has been explicit that government and its supply chain are under sustained targeting by state-aligned actors seeking access to policy, defence and intelligence information, and by criminal groups seeking data and leverage. The response has been a maturing policy framework: the Protective Security Policy Framework setting governance expectations, the Information Security Manual setting technical controls, the Essential Eight defining a minimum maturity baseline, and the Infosec Registered Assessors Program providing independent assessment of systems before they are authorised to operate. Penetration testing sits underneath all of this as the practical test of whether controls work when someone capable tries to defeat them.
Canberra also has an ACT Government serving a territory of nearly half a million people, the Australian National University and the University of Canberra with significant national security and policy research, Canberra Hospital and the new Canberra Hospital expansion, a professional services sector built around government advisory, and a dense cluster of peak bodies, associations and not-for-profits with sensitive membership data. Each needs testing scoped to its own obligations and threat profile.
What We Test
External attack surface
Agencies and suppliers accumulate internet-facing assets through programs, pilots and legacy systems. Our autonomous reconnaissance and continuous attack-surface validation map domains, subdomains, remote access gateways, cloud assets, exposed management interfaces and leaked credentials across the estate. A certified operator validates what is genuinely reachable and exploitable, reporting against the relevant ISM controls for gateway and perimeter security.
Internal network and Active Directory
An on-site operator at your Canberra premises, or a shipped device, simulates a compromised staff or contractor workstation and maps privilege escalation, lateral movement and the path to domain administrator and sensitive systems. We test whether administrative privilege restrictions, multi-factor authentication, application control and network segmentation hold up in practice, and report against the corresponding Essential Eight strategies and ISM controls.
Web applications and APIs
Citizen-facing digital services, grants and case management systems, staff portals, data exchange APIs between agencies, and SaaS platforms delivered to government. Testing follows the OWASP Web Security Testing Guide and API Security Top 10, with attention to authentication integration with government identity services, authorisation across roles and organisations, input handling and business logic.
Cloud and identity
Azure, AWS, Google Cloud and Microsoft 365 configuration and exploitation-led testing, including Entra ID conditional access, privileged roles, service principals, hybrid identity and the hardening expectations in ASD's cloud and Microsoft 365 guidance. We test whether the configuration an IRAP assessor will review actually resists an adversary.
Mobile applications
Government service and workforce apps on iOS and Android, including local data handling, authentication, certificate pinning and backend API authorisation.
Wireless, physical and social engineering
Corporate, guest and visitor wireless at Canberra offices; physical intrusion testing of premises and secure areas where authorised; and phishing, vishing and pretext campaigns, including lures built around ministerial correspondence, procurement and security clearance processes, which are the themes real adversaries use against Canberra targets.
Canberra Compliance and Regulatory Drivers
The Protective Security Policy Framework requires Commonwealth entities to manage security risk across governance, information, personnel and physical domains and to report annually to their portfolio minister. Within it, the Information Security Manual provides the detailed technical controls for systems, and the Essential Eight maturity model sets the minimum baseline that non-corporate Commonwealth entities are required to implement to Maturity Level Two. Penetration testing is explicitly recognised as a form of security assessment that supports system authorisation, and a test that reports against ISM control identifiers saves your security advisers weeks of mapping work.
Systems that process government information are typically assessed under the Infosec Registered Assessors Program before an authorising officer grants authorisation to operate. StrikeCyber does not conduct IRAP assessments; what we provide is IRAP-aligned penetration testing whose scope and reporting are designed to serve as technical evidence within that assessment, supporting the work of your IRAP assessor and authorising officer. Suppliers to government inherit these requirements through contract clauses and the Hosting Certification Framework, and defence industry companies face the Defence Industry Security Program in addition.
ACT Government agencies operate under the ACT Government's protective security and cyber policies, which align with the PSPF and the Essential Eight. Universities face the Commonwealth foreign interference guidelines, which specifically recommend penetration testing of sensitive research environments. Across all sectors in Canberra, the Privacy Act and the Notifiable Data Breaches scheme apply, and the Essential Eight is the benchmark that auditors, insurers and agency customers ask about first.
How an Engagement Runs
Scoping. A conversation with your security adviser, CISO or delivery lead to understand the system, its classification and authorisation status, the ISM controls in play and what evidence your assessor or customer needs. You receive a fixed-scope, fixed-price proposal and rules of engagement tailored to government handling requirements.
Kick-off. We confirm targets, test accounts and roles, emergency contacts, testing windows, and agree how findings and evidence will be stored and transmitted in line with your handling rules.
Testing. Remote components run from our Brisbane headquarters while on-site components are delivered in Canberra by cleared operators where required. Methodology draws on PTES, NIST SP 800-115, OSSTMM and OWASP, mapped to MITRE ATT&CK and cross-referenced to ISM controls and Essential Eight strategies. AI-augmented reconnaissance and continuous attack-surface validation broaden coverage; certified human operators exploit, chain findings and judge impact.
Real-time critical findings. Confirmed critical issues are raised the same day through the agreed channel, with enough detail to support containment and any mandatory reporting.
Draft report. Executive summary for the authorising officer and executive, a risk-rated findings register with evidence and reproduction steps, ISM and Essential Eight mapping, and prioritised remediation guidance.
Final report and debrief. After your review we issue the final report and present it in Canberra or by video to security, technical and executive audiences.
Optional retest. Remediated findings are retested, typically within one business day per component, and the report reissued with closure status for your assessor and authorising officer.
Why Canberra Organisations Choose StrikeCyber
Canberra buyers are fluent in the ISM and sceptical of vendors who are not. Our operators hold recognised offensive security certifications and write reports in the language your security advisers and IRAP assessors use, leading engagements personally.
We combine AI-augmented reconnaissance and continuous attack-surface validation with human exploitation and judgement, giving agencies and suppliers broad discovery across complex estates without the false positives that waste security team time. Pricing is fixed-scope and agreed before work begins, with Canberra travel included, which suits procurement under the Commonwealth Procurement Rules. As a Brisbane-headquartered firm delivering nationally, we support organisations with presence in Canberra, Sydney, Adelaide and beyond under a single consistent methodology.
Reporting That Supports Authorisation
In Canberra, a penetration test is rarely an end in itself. It is evidence in a larger process that ends with an authorising officer deciding whether a system can operate. That process runs on the language of the Information Security Manual, and a report that speaks a different dialect creates weeks of translation work for your security advisers. We write findings against ISM control identifiers and Essential Eight mitigation strategies, indicate where an observed weakness undermines a claimed maturity level, and structure the report so it drops directly into your system security documentation and supports your IRAP assessor's work rather than duplicating or contradicting it.
We are careful about the boundary of our role. StrikeCyber does not perform IRAP assessments and does not present itself as an assessor. What we provide is independent technical testing, scoped and reported to serve as evidence within your assessment and authorisation activity, complementing the assessor you engage and the security adviser who guides you to authorisation to operate. That clarity matters to Canberra buyers, who have seen vendors blur the line and create problems at authorisation time. For agencies uplifting toward Essential Eight Maturity Level Two, our testing also gives an honest answer to whether the controls you have deployed actually resist an adversary, which is the difference between genuine maturity and a compliant-looking spreadsheet.
Related Services
Agencies and primes with established security operations often progress to a red team engagement that tests whether a realistic adversary is detected and contained. Suppliers with changing external footprints add continuous vulnerability assessments between annual penetration tests. Organisations preparing for IRAP assessment, Essential Eight uplift or ISO 27001 frequently begin with a cyber maturity level assessment against the Essential Eight and ISO 27001. Call 1300 654 898 to discuss your Canberra system and its authorisation pathway.
