Penetration Testing for Mackay Organisations
Mackay is the service hub for the Bowen Basin. The Paget industrial precinct hosts one of the largest concentrations of mining equipment, technology and services firms in the country: engineering, fabrication, maintenance, hydraulics, automation, drilling services, labour hire and the technology providers that support remote and autonomous operations. South of the city, Hay Point and Dalrymple Bay together form one of the world's largest coal export terminals, and the Port of Mackay handles fuel, grain and general cargo. The region is also the heart of Queensland's sugar industry, with mills, cane rail networks and a large grower community. Mackay Base Hospital serves a wide catchment, Mackay Regional Council delivers services across a large area, and the Whitsundays to the north support a major tourism industry.
The METS sector faces a specific and growing pressure. Major mining companies now treat supplier cyber risk as their own risk, because a compromised contractor's remote access or a malicious invoice can reach straight into a mine's operations and finances. Questionnaires, contract clauses and audit requests are arriving at Mackay businesses that have never needed them before. StrikeCyber helps those businesses, along with the region's ports, mills, health services and council, understand how they would be attacked and what to fix, with certified operators and fixed-scope pricing.
What We Test
External penetration testing. Internet-facing infrastructure, remote access, customer and supplier portals, email and cloud services. Autonomous reconnaissance maps the footprint continuously; seasoned operators validate and exploit what is genuinely dangerous.
Internal network and Active Directory. Assumed-breach testing from a compromised staff account, a workshop PC or a contractor laptop, tracing the paths to administrative control, financial systems, design data and the connections that lead towards client mine sites.
Web applications and APIs. Supplier and customer portals, asset management and maintenance systems, grower and cane payment platforms, patient portals, council self-service systems and the APIs that connect them, with a focus on authentication, authorisation and business logic.
Cloud and Microsoft 365. Identity, conditional access, privileged roles, sharing settings and mailbox rules, which account for most real-world compromises of regional businesses, including invoice fraud.
Wireless and physical. Workshop, depot, office, hospital and terminal wireless, plus physical access testing of premises where in scope.
Operational technology boundary. For METS firms, mills, ports and utilities, a passive, engineering-approved assessment of how corporate IT and remote support tooling connect to control systems.
Social engineering. Phishing and voice pretexting built around realistic scenarios for the region, such as changed bank details on a large equipment invoice.
Mackay Compliance and Regulatory Drivers
The coal terminals, the port, rail and some water and energy assets in the region are captured by the Security of Critical Infrastructure Act, and operators pass obligations down to their suppliers. Major mining companies impose their own supplier security requirements, typically built around the Essential Eight and ISO 27001, and increasingly ask for independent testing evidence. Queensland Government agencies, the hospital and health service and Mackay Regional Council operate under the Queensland Government Information Security Policy (IS18). Health providers handle personal and health information under the Privacy Act, the Notifiable Data Breaches scheme and Queensland health information law. Sugar millers and agricultural exporters face supply chain security expectations from buyers. Our reports map findings to these frameworks so your evidence is ready when a miner, regulator or insurer asks for it.
How an Engagement Runs
- Scoping. A short call to agree targets, constraints, testing windows and contacts, followed by a fixed-scope quote.
- Testing. AI-augmented offensive tooling and continuous attack-surface validation deliver breadth and speed; certified operators deliver depth, chaining findings into realistic attack paths.
- Real-time critical findings. Urgent issues are reported the same day with containment guidance.
- Reporting. An executive summary for owners and client security teams, plus a technical section with evidence and prioritised remediation.
- Debrief and retest. We present the results and retest fixes so you can demonstrate closure to your mining clients and insurers.
Why Mackay Organisations Choose StrikeCyber
StrikeCyber is an Australian offensive security firm headquartered in Brisbane. Our engagements are led by expert offensive security operators. Our AI-augmented methodology is always validated by humans, so the report contains confirmed, exploitable findings rather than scanner noise. Pricing is fixed-scope with the retest included. We deliver remotely Australia-wide and travel on-site for internal, wireless and physical components, with regular trips to Mackay and the Bowen Basin. Call 1300 654 898 to discuss your requirements.
Related Services
- Red teaming for terminal operators, larger METS firms and health services that want to test detection and response end to end.
- Vulnerability assessments for regular coverage of multi-site workshop, depot and corporate estates.
- Maturity level assessments to benchmark Essential Eight maturity for mining company supplier requirements.