Penetration Testing for Perth Organisations
Perth runs a disproportionate share of Australia's export economy from a few square kilometres around St Georges Terrace. The head offices of iron ore, gold, lithium, nickel and alumina producers, LNG operators and the engineering and services contractors that support them are concentrated in the CBD and West Perth. From there, remote operations centres near the airport and in the city control autonomous haul trucks, driverless trains, processing plants and port loaders thousands of kilometres away in the Pilbara, the Goldfields and the North West Shelf. That architecture, where a Perth office network ultimately connects to physical processes worth billions of dollars a year, is exactly what sophisticated adversaries study.
The threat is not theoretical. Resources and energy companies globally have faced ransomware that halted production, intrusions into engineering networks, and state-aligned espionage targeting commodity strategy and joint venture negotiations. In Western Australia, the attack surface extends from corporate email and finance systems, through the remote access and jump host layers that connect the corporate network to site, into the operational technology that controls extraction, processing and export. A penetration test in Perth has to understand that chain and test the boundaries along it.
Beyond resources, Perth hosts WA Government departments and agencies serving a state the size of Western Europe, a health system centred on Fiona Stanley, Sir Charles Gairdner, Royal Perth and Perth Children's Hospitals, the University of Western Australia, Curtin, Murdoch and Edith Cowan universities, Fremantle Port, a growing defence presence around HMAS Stirling at Garden Island, and a diverse mid-market of engineering firms, professional services practices and technology businesses. Each brings its own exposure, and each increasingly needs independent testing evidence for regulators, insurers, customers and joint venture partners.
What We Test
External attack surface
Resources companies accumulate internet-facing assets through exploration projects, joint ventures, acquisitions and contractor portals. Our autonomous reconnaissance and continuous attack-surface validation map domains, subdomains, remote access gateways, exposed management interfaces, cloud assets and leaked credentials across the whole estate, including legacy assets from projects long since divested. Operators then validate what is genuinely exploitable.
Internal network and Active Directory
An on-site operator in your Perth office, or a shipped device, replicates a compromised corporate workstation and maps privilege escalation, lateral movement and the path to domain administrator. In resources environments we pay particular attention to how far a corporate compromise can travel toward the remote operations centre, engineering networks and site domains, and whether trust relationships and shared credentials bridge what should be separate zones.
Operational technology and ICS boundaries
We assess segmentation between corporate IT, the remote operations centre and site control networks against IEC 62443 zone and conduit principles, test remote access paths used by vendors and control engineers, review historian, SCADA server and engineering workstation exposure, and perform passive analysis of control network traffic. Active exploitation is confined to test rigs, spare equipment or agreed maintenance windows, and every step is planned with your control systems team.
Web applications and APIs
Supplier and contractor portals, safety and permit-to-work systems, fleet and asset management platforms, citizen services for WA Government, patient portals and student systems. Testing follows the OWASP Web Security Testing Guide and API Security Top 10 with attention to authorisation between contractors and business units, integration with ERP and identity systems, and business logic.
Cloud and identity
Azure, AWS, Google Cloud and Microsoft 365 configuration and exploitation-led testing, including Entra ID conditional access, privileged roles and the hybrid identity paths that connect cloud tenancies to on-premises and site domains. Many resources companies have moved corporate workloads to cloud while OT stays on premises, and the identity layer between them is a frequent weak point.
Wireless, physical and social engineering
Corporate and guest wireless at Perth offices and operations centres, physical intrusion testing where authorised, and phishing, vishing and pretext campaigns, including scenarios targeting contractor onboarding, site access and vendor support channels.
Perth Compliance and Regulatory Drivers
The Security of Critical Infrastructure Act 2018 captures a large share of Western Australia's economy: ports, energy generation and transmission, gas pipelines and processing, water, and increasingly the mining and resources operations and data centres that underpin them. Responsible entities must maintain a Critical Infrastructure Risk Management Program and report cyber incidents, and those designated as systems of national significance face enhanced obligations. Regular adversarial testing of both IT and OT boundaries is how a responsible entity demonstrates that its program is working rather than merely documented.
For industrial control environments, IEC 62443 provides the reference architecture for zones, conduits and security levels, and boards and insurers increasingly expect testing to be framed against it. WA Government agencies operate under the WA Government Cyber Security Policy, which aligns with the Essential Eight and requires annual reporting to the Office of Digital Government. Suppliers to WA Government are expected to show comparable assurance.
Resources companies listed on the ASX face continuous disclosure expectations around material cyber incidents, and joint venture partners and offtake customers routinely require evidence of security testing. Health services and universities operate under the Privacy Act, the Notifiable Data Breaches scheme and, for universities, the Commonwealth foreign interference guidelines. The Essential Eight is the baseline that auditors and cyber insurers ask about across all Perth sectors, and ISO 27001 certification is increasingly a contractual requirement for engineering and services firms bidding on major projects.
How an Engagement Runs
Scoping. A conversation with your security, IT and, where relevant, control systems leads to understand the environment, the driver behind the test and the constraints around production systems. You receive a fixed-scope, fixed-price proposal and rules of engagement, with Perth travel and any site logistics included.
Kick-off. We confirm targets, credentials, emergency contacts and testing windows, and agree explicitly which OT assets are in scope for passive review, which are off limits, and which can be tested actively in a rig or during a shutdown.
Testing. Remote components begin from our Brisbane headquarters, scheduled to Perth hours. On-site work is delivered at your Perth premises, remote operations centre or site. Methodology draws on PTES, NIST SP 800-115, OSSTMM, OWASP and IEC 62443, mapped to MITRE ATT&CK and ATT&CK for ICS. AI-augmented tooling handles reconnaissance and continuous validation; certified humans exploit, chain findings and judge consequence.
Real-time critical findings. Anything critical, particularly a demonstrated path from corporate IT toward OT, is raised the same day.
Draft report. Executive summary for the board, a risk-rated findings register with evidence and reproduction steps, and remediation guidance that distinguishes quick wins from architectural changes.
Final report and debrief. After your review we issue the final report and present it in Perth or by video to technical, OT and leadership audiences.
Optional retest. Remediated findings are retested, typically within one business day per component, and the report reissued with closure status.
Why Perth Organisations Choose StrikeCyber
Perth organisations want testers who understand that a finding in the corporate network matters most when it leads somewhere physical. Our operators hold recognised offensive security certifications and approach resources environments with the caution control engineers expect, leading engagements personally.
We pair AI-augmented reconnaissance and continuous attack-surface validation with human exploitation and judgement. For sprawling resources estates built through decades of projects and acquisitions, that means broader discovery than a manual test and far less noise than an automated one. Reports are written for boards, IT teams and control engineers alike.
Pricing is fixed-scope and agreed before work begins, with Perth travel and any site logistics built in. We are Brisbane-headquartered and deliver nationally, so companies with offices in Perth, operations in the Pilbara, Adelaide or Darwin, and corporate functions on the east coast get one partner and one consistent methodology.
The Corporate to OT Attack Path
The scenario that should keep a Perth resources executive awake is not a defaced website; it is an attacker who lands in the corporate network through a phished engineer or an exposed remote access gateway and then finds an unbroken path toward the systems that run extraction, processing and export. In too many organisations that path exists because the remote operations centre was connected to corporate IT for convenience, vendor remote access was provisioned once and never reviewed, and shared credentials bridge zones that the architecture diagram shows as separate. We test that path deliberately and safely, mapping how far a corporate compromise can travel toward operational networks before any control stops it.
This is where a resources-aware methodology matters. We do not point exploitation tooling at live process control and hope for the best. We validate the boundaries, the jump hosts, the historian and engineering workstation exposure and the identity trust between zones, then demonstrate the reachable path up to the point where crossing it would risk production, and document exactly what a determined adversary would do next. The result is a report that your control engineers respect because it does not endanger operations, and that your board understands because it answers the only question that matters: could someone reach the plant, and how do we make sure they cannot.
Related Services
Resources and energy companies with mature security operations often progress to a red team engagement that tests whether your security operations centre detects a realistic intrusion before it reaches operational networks. Organisations managing large, changing external estates add continuous vulnerability assessments between annual penetration tests. Boards preparing for SOCI obligations, ISO 27001 or joint venture audits frequently start with a cyber maturity level assessment against the Essential Eight and ISO 27001. Call 1300 654 898 to discuss your Perth and site environments.
