Penetration Testing for Newcastle Organisations
Newcastle is the commercial and industrial heart of the Hunter, and it is in the middle of a significant change. The Port of Newcastle, long defined by coal, is diversifying into container trade, hydrogen and clean energy. The closure timeline for the Hunter coal-fired generators is driving investment in renewables, transmission, batteries and the supporting manufacturing and engineering firms that cluster around Tomago, Kooragang and Beresfield. John Hunter Hospital and the Hunter New England Local Health District run some of the largest clinical operations outside Sydney. The University of Newcastle anchors research, and a deep bench of mining services, fabrication and advanced manufacturing companies supports the region and the wider Hunter Valley.
All of that is an attractive surface for an attacker. Energy and port operators fall squarely within the critical infrastructure regime. Health providers hold sensitive clinical and identity data. Manufacturers and contractors sit in the supply chains of much larger organisations, and those larger organisations increasingly expect evidence of security testing before they sign. StrikeCyber provides that evidence. We are an Australian offensive security firm headquartered in Brisbane, and we test Newcastle and Hunter organisations the way a genuine adversary would approach them, then give you a clear, prioritised path to fixing what we find.
What We Test
External penetration testing. Your internet-facing footprint: web servers, VPN concentrators, remote access portals, mail, DNS, cloud-hosted services and anything else an attacker can reach from outside. For Newcastle operators this often includes vendor remote access into plant and logistics systems that nobody has reviewed in years.
Internal network and Active Directory. We start from the position of an attacker who already has a foothold, such as a phished user or a compromised contractor laptop, and work towards domain dominance. Flat networks between corporate IT and site systems are a recurring finding in Hunter industrial environments.
Web applications and APIs. Customer portals, booking and freight systems, patient-facing services, student and staff platforms, and the APIs that connect them. We test authentication, authorisation, business logic and data exposure, not just the OWASP Top 10 checklist.
Cloud configuration. Microsoft 365, Azure, AWS and Google Cloud estates, with a focus on identity, conditional access, privileged roles, storage exposure and logging.
Wireless and physical. Corporate and guest wireless at campuses, hospitals, depots and terminals, and physical access testing where badge systems, reception processes and perimeter controls are in scope.
Operational technology boundary. For energy, port and manufacturing clients, we assess the IT to OT boundary and the paths that lead to it, using passive techniques agreed with your engineers.
Social engineering. Phishing, voice pretexting and on-site pretexting campaigns that measure how people and process respond, with results used for improvement rather than blame.
Newcastle Compliance and Regulatory Drivers
The Security of Critical Infrastructure Act captures port, energy, water and some health and transport assets across the Hunter, bringing risk management program obligations and, for some entities, enhanced cyber security obligations. The Australian Energy Sector Cyber Security Framework gives generators, networks and new renewable operators a maturity model that benefits directly from independent testing. NSW public sector entities and their suppliers are guided by the NSW Cyber Security Policy, which leans heavily on the Essential Eight. Health providers handle personal and health information under the Privacy Act and the Notifiable Data Breaches scheme, alongside NSW health records legislation. Manufacturers working with defence primes or major miners are increasingly asked for ISO 27001 alignment or Essential Eight maturity evidence. Our reports are written so that findings can be mapped directly to these frameworks.
How an Engagement Runs
- Scoping. A short call to understand what you run, what worries you and what your stakeholders need to see. We agree targets, rules of engagement, testing windows and contacts, and issue a fixed-scope quote.
- Reconnaissance and testing. Autonomous reconnaissance and AI-augmented tooling map your attack surface quickly and continuously during the engagement. Every lead is then validated and exploited, where safe, by an expert human operator. Automation finds the breadth; people find the depth.
- Real-time critical findings. If we find something an attacker could use tonight, you hear about it the same day with enough detail to act.
- Reporting. An executive summary for leadership and the board, and a technical section for your engineers with reproduction steps, evidence and remediation guidance ranked by real risk.
- Debrief and retest. We walk your team through the results, answer questions, and retest remediated findings so you can close the loop with auditors, insurers and customers.
Why Newcastle Organisations Choose StrikeCyber
StrikeCyber is an Australian offensive security firm. Every engagement is led by expert operators rather than handed to a scanner. We combine AI-augmented offensive tooling and continuous attack-surface validation with human judgement, so you get coverage and insight rather than a long list of unverified alerts. Pricing is fixed-scope with no surprises. We are Brisbane-based and deliver remotely Australia-wide, travelling on-site for internal, wireless and physical components wherever they are needed, from Newcastle's CBD to industrial sites in the Upper Hunter. Call 1300 654 898 to talk through your requirements.
Related Services
- Red teaming for Hunter organisations that want to test detection and response against a realistic, objective-driven adversary.
- Vulnerability assessments for broad, regular coverage of large estates between full penetration tests.
- Maturity level assessments to benchmark against the Essential Eight and AESCSF and plan the next twelve months.