Security

Cyber security and penetration testing, Newcastle

Most breaches we clean up were preventable with patching, multi-factor authentication and a backup someone had actually tested. We fix those first, then test from the outside the way an attacker would.

The basics, done properly

Before anyone talks about advanced threat protection, the fundamentals need to be in place: systems patched on a schedule, MFA on every account that matters, administrator rights removed from day-to-day logins, and backups that are isolated from the network and restored regularly to prove they work. This is where we start, and it removes most of the risk for most businesses.

External penetration testing

We test your internet-facing systems — firewalls, VPNs, remote access, web applications, email — the way an attacker would. You get a written report with findings rated by severity, what each one means for your business, and exactly how to fix it, followed by a retest once the fixes are in. Insurers and larger clients increasingly ask for this report; it's written to be handed over.

Essential Eight

The Australian Cyber Security Centre's Essential Eight is the baseline mitigation strategy for Australian organisations. We assess your current maturity level against each of the eight controls, produce a prioritised uplift plan, and implement it — application control, patching, macro settings, application hardening, admin privilege restriction, MFA and backups. Read our plain-English guide to the Essential Eight.

Email security, backup and recovery

SPF, DKIM and DMARC configured so your domain can't be impersonated; phishing protection and staff awareness; backup and disaster-recovery plans with scheduled restore tests and a written recovery time you can plan around.

ISO 27001 readiness

For organisations that need certification — or need to show a client they're on the path — we help build the controls, policies and evidence, and we build compliance tooling for organisations managing ISO 27001 and similar frameworks.

Had a breach?

Call (02) 9053 0915. Containment first, then investigation and recovery, then the report your insurer will ask for.

FAQ

Questions people ask

How long does a penetration test take?

An external test for a typical small or mid-sized business runs about one to two weeks from scoping to report, depending on the number of systems. Retesting after fixes is quicker.

Will testing disrupt our systems?

External testing is scheduled and non-destructive. We agree the scope, the systems in play and the hours before we start, and stop immediately if anything unexpected happens.

Do we have to do the Essential Eight?

It's mandatory for Commonwealth entities and increasingly expected by insurers, larger customers and government tenders. For everyone else it's simply the most cost-effective baseline available, which is why we recommend it.

Can you help us after a breach?

Yes. Call the office. We contain the incident, work out what happened, get you back to work and produce the documentation your insurer and any regulator will ask for.

Want this sorted?

Tell us what you've got and what's hurting. You'll get an engineer's straight answer and a written figure.