Skip to content
StrikeCyberStrikeCyber
Geelong, VIC

Penetration Testing Geelong

Offensive security testing for Geelong's manufacturers, health services, Commonwealth and state agencies, Deakin University and port operators.

AdelaideBrisbaneCanberraDarwinGold CoastHobartMelbournePerthSydneyBallaratBendigoCairnsGeelongLauncestonMackayNewcastleRockhamptonSunshine CoastToowoombaTownsvilleWollongong

Penetration Testing for Geelong Organisations

Geelong has reinvented itself. The closure of large-scale car manufacturing gave way to advanced manufacturing in carbon fibre, composites, defence vehicles and materials, much of it clustered around Deakin University's Waurn Ponds research precinct. The city is also an unusual concentration of government and insurance agencies: the National Disability Insurance Agency, the Transport Accident Commission and WorkSafe Victoria are all headquartered here, bringing a deep pool of suppliers, contractors and professional firms with them. Barwon Health runs University Hospital Geelong and a network of services across the region. The Port of Geelong handles bulk grain, fertiliser, petroleum and woodchips, and the Geelong waterfront and Surf Coast support a busy tourism and hospitality sector.

The data these organisations hold is among the most sensitive in the country. Disability, injury and compensation records, clinical data, defence manufacturing information and research intellectual property are all targeted by capable adversaries. Suppliers to the agencies inherit high expectations, and manufacturers in defence supply chains face explicit obligations. StrikeCyber gives Geelong organisations an honest, adversarial view of their exposure and a prioritised path to fixing it.

What We Test

External penetration testing. Internet-facing infrastructure, remote access, web properties and cloud services, mapped with autonomous reconnaissance and validated by expert operators who concentrate on exploitable weaknesses.

Internal network and Active Directory. Assumed-breach testing from a compromised user or device, tracing paths to domain administrator, sensitive data and plant or clinical systems. Manufacturers and professional firms often find that legacy trust relationships expose far more than intended.

Web applications and APIs. Client, participant and provider portals, claims and case management systems, research platforms, e-commerce and the APIs between them. We emphasise authentication, authorisation and business logic, which is where automated scanners fall short.

Cloud and identity. Microsoft 365, Azure and AWS, including conditional access, privileged identity management, storage exposure and logging.

Wireless and physical. Campus, hospital, factory and office wireless, and physical access testing of premises where in scope.

Operational technology boundary. Passive, engineering-approved assessment of how corporate IT connects to manufacturing and port control systems.

Social engineering. Phishing and voice pretexting tailored to realistic scenarios, such as invoice changes from a supplier or urgent requests from an agency contact.

Geelong Compliance and Regulatory Drivers

Suppliers to the Commonwealth agencies headquartered in Geelong work within the Protective Security Policy Framework and are increasingly required to evidence Essential Eight maturity. Victorian public sector bodies, including Barwon Health and the City of Greater Geelong, operate under the Victorian Protective Data Security Standards administered by the Office of the Victorian Information Commissioner. Health and professional services providers handle personal and health information under the Privacy Act, the Notifiable Data Breaches scheme and Victorian health records legislation. The port and some utilities are captured by the Security of Critical Infrastructure Act. Manufacturers in defence supply chains face Defence Industry Security Program requirements and prime contractor security clauses, and ISO 27001 remains the most commonly requested certification in commercial supply chains. Our reports map findings directly to these frameworks.

How an Engagement Runs

  1. Scoping. A short call to agree targets, windows, rules of engagement and contacts, followed by a fixed-scope quote.
  2. Testing. AI-augmented offensive tooling and continuous attack-surface validation deliver breadth; certified human operators deliver depth, chaining findings into realistic attack paths.
  3. Real-time critical findings. Urgent issues are reported the same day with containment guidance.
  4. Reporting. An executive summary for boards and agency sponsors and a technical section with reproduction steps, evidence and prioritised remediation.
  5. Debrief and retest. We walk your team through the results and retest fixes so you can demonstrate closure.

Why Geelong Organisations Choose StrikeCyber

StrikeCyber is an Australian offensive security firm headquartered in Brisbane. Seasoned offensive security operators lead every engagement. Our AI-augmented methodology is always validated by humans, so the findings you receive are confirmed and actionable. Pricing is fixed-scope with the retest included. We deliver remotely Australia-wide and travel on-site for internal, wireless and physical components wherever they are, including Geelong and the Surf Coast. Call 1300 654 898 to discuss your engagement.

  • Red teaming for agencies, suppliers and manufacturers that want to test detection and response against a realistic adversary.
  • Vulnerability assessments for regular coverage of large corporate, campus and hospital estates.
  • Maturity level assessments to benchmark against the Essential Eight and the Victorian Protective Data Security Standards.
FAQ

Penetration testing in Geelong: your questions

How much does a penetration test cost in Geelong?

We quote a fixed price after scoping. A single application or a small external footprint is the entry point. Internal assessments at a manufacturer, hospital or multi-site professional firm take more operator days, and on-site travel is itemised up front. The report, a debrief and a retest of remediated findings are included in every engagement.

We supply a Commonwealth agency headquartered in Geelong. What will they expect?

Commonwealth entities and their suppliers work within the Protective Security Policy Framework and the Essential Eight, and procurement increasingly asks for independent testing evidence. We scope to the systems that handle agency data, report in language that maps to those frameworks, and include a retest so you can show closure. That evidence tends to shorten security questionnaires considerably.

Do you travel to Geelong for on-site testing?

Yes. Internal network, wireless and physical assessments are done in person. We fly from Brisbane to Melbourne and drive down, scheduling on-site days together so they are efficient. Everything that can be tested remotely is tested remotely first, which keeps the overall cost down.

Can you test manufacturing and plant networks safely?

Yes. We test the IT to OT boundary using passive discovery and methods agreed with your engineering team, and we never run aggressive scans against production control systems. The objective is to show how an attacker could move from a phishing email or a vendor connection to the edge of your plant network, and what controls would stop them.

Nearby

Also serving Victoria

Get a fixed-scope quote for Geelong

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation