Skip to content

Defend · Service 04

Penetration testing & red teaming

Find out what an attacker would find first. We test your networks, applications, cloud and people the way a real adversary would, then show you exactly what we reached and how to close each path.

The position

A control is only proven once somebody tries to get past it

Configuration reviews tell you what is switched on. A penetration test tells you what an attacker can actually do with what is switched on: which credentials lead where, which low-rated findings chain together into full domain compromise, and which of your controls stopped the attempt.

Real intrusions rarely hinge on one critical vulnerability. They combine a password sprayed against a forgotten remote access portal, an over-permissioned service account and a file share nobody remembered existed. A scanner reports each of those separately, if it sees them at all. A tester connects them.

We test the way attacks actually happen, report the path as well as the findings, and stay with you through remediation until a retest confirms each one is closed.

What we test

Seven kinds of test, scoped to what you actually run

Most organisations need two or three of these rather than all seven. We scope to your exposure, your obligations and your budget, and recommend the tests that will tell you the most.

External network & perimeter

Everything reachable from the internet: firewalls, VPN and remote access gateways, exposed services, email infrastructure, and the forgotten hosts that attack surface discovery turns up. The first place an opportunistic attacker looks.

Internal network & Active Directory

An assumed-breach start inside your network, testing how far a compromised workstation or stolen credential can reach: privilege escalation, lateral movement, Active Directory and Entra ID attack paths, and access to the data that matters most.

Web applications

Authenticated and unauthenticated testing of customer portals, line-of-business systems and public websites, aligned to the OWASP Web Security Testing Guide and covering the OWASP Top 10, business logic, and access control between users, roles and tenants.

APIs & mobile applications

REST and GraphQL APIs tested for authentication, authorisation and data exposure flaws, and iOS and Android applications tested for insecure storage, weak transport security and the API calls behind them.

Cloud & Microsoft 365

Configuration and attack-path testing across Microsoft 365, Entra ID, Azure and AWS: conditional access gaps, over-permissioned app registrations and OAuth consent, exposed storage, and the identity paths from an ordinary user to tenant or subscription administrator.

Wireless

Corporate and guest wireless networks, the segmentation between them, rogue access point exposure, and the strength of the authentication protecting each one.

Social engineering

Phishing, pretext phone calls and, where agreed, physical access attempts, run against an agreed scope to measure how your people and processes hold up. Results are reported in aggregate, on a blame-free basis.

Red teaming

A red team tests whether you would notice

A penetration test finds as many weaknesses as it can in the time available. A red team pursues one objective, quietly, the way a determined adversary would, and measures whether your people, tools and processes detect and respond.

Red team engagements are objective-based and threat-led. We agree the goal with a small control group on your side, such as reaching the finance system, reading an executive mailbox or obtaining domain administrator, and plan the campaign around the MITRE ATT&CK techniques used by the groups that target your sector.

How an engagement runs

  1. Objectives and threat profile. The systems and data that matter most, the adversaries most likely to go after them, and the questions your leadership wants answered.

  2. Rules of engagement. Scope, exclusions, timing, an emergency stop procedure and a named control group who know the test is running, all agreed in writing before anything starts.

  3. Initial access. A full chain from phishing, external exposure or a physical foothold, or an assumed-breach start where the budget is better spent further in.

  4. Pursue the objective. Persistence, privilege escalation, lateral movement and collection, with every action logged and timestamped.

  5. Measure the response. For each step, whether it was prevented, detected, investigated and contained, compared against what your monitoring actually recorded.

  6. Debrief and replay. A walkthrough with your security team, then a replay of any techniques that went unseen so detections can be built and proven.

Red teaming delivers the most for organisations with monitoring in place that want to know it works. Where detection is still being built, a penetration test alongside an Essential Eight assessment usually delivers more for the budget, and we will recommend the right starting point when we scope the work.

Purple teaming

Attack and defence in the same room

Purple teaming turns a test into an improvement. Our testers run techniques one at a time while your defenders watch, so every gap in detection is found, fixed and re-tested together.

How it works

We select the ATT&CK techniques that matter for your threat profile, such as credential dumping, Kerberoasting, malicious PowerShell, inbox rule creation and OAuth consent abuse, and execute each one in a controlled way. Your defenders, or our detection and response team if we run your monitoring, check what was logged, what alerted and what was missed.

  • Detection coverage mapped. Every technique recorded as prevented, detected, logged only or missed, so you can see exactly where the gaps are.

  • Detections built on the spot. Missing rules written and tuned in Microsoft Defender, Sentinel or your SIEM, then proven by running the technique again.

  • Repeatable. The test cases are kept, so the same techniques can be re-run after major changes to confirm nothing has regressed.

  • Works with your monitoring provider. If your monitoring is with us, findings flow straight into our detection engineering. If it is with someone else, we work alongside them.

The report

Written for the person who paid for it and the person who fixes it

Every finding has an owner, a risk rating that reflects your environment, and a fix specific enough to act on. Anything critical is raised with you as soon as we confirm it, well before the report is written.

  • An executive summary in plain language: what we reached, what it would mean for the business, and the first things to fix.

  • The attack narrative. The path from first foothold to objective, step by step, showing which controls would have broken the chain.

  • Technical findings rated with CVSS and adjusted for your context, each with evidence, affected assets and remediation steps written for your environment.

  • Control mapping to the Essential Eight, the ISM and ISO/IEC 27001 Annex A, so findings slot straight into the frameworks you already report against.

  • Two debriefs. A technical walkthrough with the people fixing it, and a separate briefing for leadership.

  • A retest once the fixes are in, and a letter confirming what was retested and closed, ready for your insurer, auditor or customer.

Our guide on how to read a penetration test report explains how to turn any report into a decision.

How it runs

From first call to closed findings

A fixed sequence, so you know what happens when, who is involved and what you will hold at the end.

1. Scope

A short workshop to agree targets, test types, timing and constraints, followed by a fixed-fee proposal with the scope written in plain language.

2. Authorise

Rules of engagement and written authorisation signed before testing starts, covering contacts, testing windows, exclusions and the stop procedure.

3. Test

Testing inside the agreed windows using production-safe techniques, with a named contact on our side throughout and critical findings raised immediately.

4. Report and debrief

The report, the technical walkthrough and the leadership briefing, with findings sequenced into a remediation plan you can schedule.

5. Retest

Fixes verified, and the report updated to show each finding closed.

Questions

What people ask

How often should we have a penetration test?

At least annually, and after any significant change: a new application, a cloud migration, a merger or a major network redesign. Contracts, insurers and frameworks often set their own requirement too, and we will time the work so one engagement satisfies as many of them as possible.

What is the difference between a vulnerability scan, a penetration test and a red team?

A scan runs automated tooling and lists what it recognises. A penetration test adds skilled testers who chain findings into working attack paths and find the logic flaws no scanner can. A red team pursues a single objective covertly to test whether your detection and response would catch a real adversary. Each answers a different question, and we will recommend the one that answers yours.

Will testing disrupt our systems?

Testing is planned to avoid it. We agree testing windows, handle fragile systems with extra care or exclude them, leave out denial-of-service techniques unless you specifically ask for them, and keep named contacts on both sides throughout with an agreed stop procedure.

Can you test Microsoft 365, Azure and AWS?

Yes. Cloud testing covers identity, conditional access, app registrations and consent, storage exposure, and the paths from an ordinary user to tenant or subscription administrator, conducted within the testing rules Microsoft and AWS publish for their customers.

Can you test if another provider runs our IT?

Yes. We coordinate testing windows and contacts with your provider, share findings with whoever owns each fix, and can help with remediation directly if you would like us to.

How do you handle our data?

Test evidence is stored onshore in Australia, encrypted and limited to the engagement team. Sensitive data we reach is recorded only as far as needed to prove the finding, and evidence is securely destroyed at the end of the retention period agreed in the engagement.

Pairs with

Cyber security

The hardening and blue team work that closes what the test finds.

Explore →

Detection & response

Red team findings become detections, watched around the clock.

Explore →

Essential Eight

Test results mapped to the maturity model you already report against.

Explore →

Find out what an attacker would find first

Tell us what you run and what you need to prove. We will recommend the right test, scope it in writing and send a fixed-fee proposal.