Skip to content
StrikeCyberStrikeCyber
Research

Threat briefings from the front line

Exploits, engagements and field notes from our operators. Practical intelligence, no fluff.

Latest
·6 min readPenetration Testing

Continuous Penetration Testing vs Point-in-Time Testing

Annual point-in-time testing gives you a snapshot; continuous penetration testing keeps assurance current as your environment changes. Here is how the two compare on coverage, cost and compliance, and how to move to continuous.

Read briefing
Filter by topic
All research34 articles
·6 min

Continuous Penetration Testing vs Point-in-Time Testing

Annual point-in-time testing gives you a snapshot; continuous penetration testing keeps assurance current as your environment changes. Here is how the two compare on coverage, cost and compliance, and how to move to continuous.

Read
·6 min

Field Notes: The Air Gap That Was Not There

An anonymised field note on an IT to OT attack path: how flat segmentation, a dual-homed host and shared credentials let a corporate network reach an OT environment everyone believed was air-gapped, and how to safely prevent it.

Read
·6 min

AI in Penetration Testing: What Is Real in 2026

AI is accelerating reconnaissance, exploit chaining and continuous validation in 2026, but human judgement still decides what matters. Here is what is real, what is hype, and how to choose an AI-augmented offensive security provider.

Read
·6 min

Penetration Testing vs Vulnerability Scanning: Which Do You Need?

Vulnerability scanning finds potential weaknesses automatically. Penetration testing proves what an attacker could actually do. Here is how they differ, when to use each and why most Australian organisations need both.

Read
·5 min

Field Notes: Phishing That Bypassed MFA

An anonymised red team field note on phishing that bypasses MFA: how an adversary-in-the-middle proxy captured a live session token, what it reached, and the controls that would have stopped it.

Read
·5 min

Field Notes: SSRF to Cloud Takeover

An anonymised web and cloud engagement against a mid-market fintech where a single server-side request forgery flaw reached the cloud metadata endpoint, harvested temporary credentials and opened a path toward full account takeover. Here is how the SSRF cloud metadata attack unfolded, and the layered controls that would have contained it.

Read
·5 min

Field Notes: Domain Admin in a Day

An anonymised internal engagement against a national logistics firm where our operators moved from a single low-privileged foothold to full Domain Admin control inside a working day. Here is how attackers reach domain admin, what went wrong, and the practical controls that would have broken the chain.

Read
·6 min

Penetration Testing Cost in Australia: What Drives the Price in 2026

Penetration testing cost in Australia depends on scope, complexity and the depth of manual work involved, not a flat sticker price. Here is what really drives pricing and how to scope for genuine value.

Read
·6 min

Offensive Security for MSPs in Australia: Protecting Yourself and Your Clients

Managed service providers hold the keys to dozens of client networks, which makes them a prime supply-chain target. This briefing covers MSP-specific risk, securing RMM and tooling, and how MSPs can offer penetration testing to clients through a specialist partner.

Read
·7 min

What Is Red Teaming? A Definitive Guide for Australian Organisations

Red teaming is an objectives-based, threat-led exercise that tests whether your people, processes and technology can detect and stop a determined adversary. Here is what it involves and when your organisation is ready for it.

Read
·6 min

What Is Penetration Testing? A Complete 2026 Guide for Australian Business

Penetration testing is an authorised, simulated cyber attack that finds and safely exploits weaknesses before real attackers do. Here is what it covers, how it works and why Australian organisations rely on it.

Read
·6 min

Cyber Security for Law Firms in Australia: Protecting Privilege, Trust Accounts and Client Data

Law firms hold the most sensitive data their clients have, and they move money through trust accounts. This briefing explains the threats that matter most, from business email compromise to ransomware, and how small legal teams can test their defences.

Read
·6 min

IRAP ISM Security Testing for Government and Suppliers in Australia

Government systems and their suppliers are held to the ISM and PSPF. Here is how IRAP, the ISM and offensive security testing fit together, and where IRAP-aligned testing adds value ahead of a formal assessment.

Read
·6 min

Cyber Security for Mining and Energy in Australia: Securing OT and Critical Infrastructure

Mining, energy and utilities run the systems that keep Australia moving. This briefing explains the IT and OT convergence risk, ICS and SCADA exposure, and how safety-first offensive testing supports SOCI and IEC 62443 without disrupting operations.

Read
·6 min

SOCI Act Critical Infrastructure Security: How Offensive Testing Supports Compliance

The Security of Critical Infrastructure Act sets real obligations for responsible entities across eleven sectors. Here is how the framework works and how offensive security testing strengthens both compliance and resilience.

Read
·5 min

Cyber Security for Schools and Universities in Australia

Schools and universities hold rich student and research data, run open networks, and face constant phishing. This briefing covers the threats to the education sector, the pressures on funding and reputation, and how offensive testing keeps learning secure.

Read
·6 min

PCI DSS Penetration Testing Requirements Under Version 4.0

PCI DSS v4.0 requires internal and external penetration testing, plus segmentation testing, at least annually and after significant change. Here is what Requirement 11.4 asks for, who needs it and how to scope the cardholder data environment.

Read
·6 min

APRA CPS 234 Penetration Testing: A Practical Compliance Guide for 2026

APRA CPS 234 requires regulated entities to systematically test the effectiveness of their information security controls. Here is what that means in practice and how offensive security testing builds the evidence APRA expects.

Read
·5 min

Cyber Security for Government in Australia

Government agencies and their suppliers protect citizen data and critical services under some of the most demanding security frameworks in the country. This briefing covers the ISM, PSPF, Essential Eight and how offensive testing builds real assurance.

Read
·6 min

ISO 27001 Penetration Testing: Scope, Frequency and Evidence

ISO 27001 does not name penetration testing as a mandatory control, but auditors expect it as evidence that technical risks are managed. Here is where it fits in the 2022 standard, what to scope, how often to test and what evidence to keep.

Read
·5 min

Cyber Security for Healthcare in Australia

Healthcare holds some of the most sensitive data in the country and cannot afford downtime when lives are on the line. This briefing covers the threats to hospitals, clinics and health tech, the compliance drivers, and how offensive testing keeps care safe.

Read
·5 min

Essential Eight Penetration Testing: Validating Your Controls

A maturity assessment confirms your Essential Eight controls are configured. Penetration testing proves they actually work. Here is how adversary testing validates the Essential Eight and produces evidence auditors and boards trust.

Read
·6 min

Cyber Security for Financial Services in Australia

Australian financial services firms hold the data and money attackers want most. This briefing looks at the threats facing banks, insurers, super funds and fintechs, the APRA obligations that shape their programs, and why offensive testing is now core assurance.

Read
·6 min

ASD Essential Eight Explained: The Eight Strategies and Maturity Levels

The ASD Essential Eight is Australia's baseline set of eight mitigation strategies for defending against cyber attacks. Here is what each strategy does, how the maturity levels work, who must comply and how to uplift.

Read
·6 min

Supply Chain and Third-Party Risk for Australian Organisations in 2026

Australian organisations increasingly depend on software vendors, managed service providers and cloud platforms. This guide explains supply chain risk and how to assess and test your third-party exposure.

Read
·6 min

The OWASP Top 10 in Practice for Web and API Security

The OWASP Top 10 is the industry reference for web application risk, but the list only matters when you see how the flaws behave in real applications. Here is the OWASP Top 10 in practice for web and API, and how testing catches each one.

Read
·6 min

Identity Attacks in 2026: Why MFA Alone Is No Longer Enough

Multi-factor authentication is essential, but attackers now routinely bypass weak implementations. This guide explains modern identity attacks and how to test and harden identity in Australian organisations.

Read
·6 min

Cloud Misconfigurations That Lead to Breach Across AWS, Azure and GCP

Most cloud breaches are not clever exploits. They are misconfigurations: a public bucket, an over-permissive role, a secret left in code. Here are the cloud misconfigurations that lead to breach across AWS, Azure and GCP, and how testing finds them first.

Read
·7 min

The Australian Cyber Threat Landscape 2026: What Every Organisation Needs to Know

Ransomware-as-a-service, AI-enabled attackers and identity abuse are reshaping how Australian organisations are targeted. This annual briefing maps the 2026 threat landscape and what it means for your defences.

Read
·6 min

Active Directory Attack Paths: The Routes to Domain Admin We See Most

Active Directory is still the beating heart of most Australian corporate networks, and it is where attackers spend most of their time. Here are the attack paths we see most often, why they work, and how to find and close them before someone else does.

Read
·3 min

Why Are Hackers Targeting Australian High Schools?

Australian high schools are increasingly in the crosshairs of cybercriminals. Here is why the education sector is under siege, and what schools can do about it.

Read
·5 min

Assumed Breach - The Evolution of Offensive Security

Assumed breach testing starts from a compromised foothold to measure how fast your team detects, responds and contains a live intruder. Here is why prevention-only security fails, and how to run an assume breach exercise.

Read
·5 min

How to Run a Successful Red Team Engagement - Lessons from the Front Lines

A practical guide to running a red team engagement that actually improves your defences: clear objectives, tight rules of engagement, threat-led scenarios, purple teaming and outcomes you can measure.

Read
·6 min

Ransomware Preparedness - A Proactive Approach to Preventing and Recovering from Attacks

Ransomware is now a business-continuity threat, not just an IT problem. Here is how Australian organisations build real ransomware preparedness across prevention, detection, immutable backups, incident response and board-level reporting.

Read
FAQ

Research FAQs

What does the StrikeCyber research library cover?

Offensive cyber security research, field notes from real engagements, compliance guidance across the Essential Eight, ISO 27001, PCI DSS, SOCI and APRA, and Australian threat-landscape analysis, written by our operators.

How often is new research published?

We publish regularly as our operators surface new findings and as the threat and compliance landscape shifts. You can follow along through our RSS feed at /feed.xml.

Can I cite or share StrikeCyber research?

Yes. You are welcome to reference and cite our research with attribution. For media or speaking enquiries, get in touch.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation