Security
Cyber security and penetration testing, Newcastle
Most breaches we clean up were preventable with patching, multi-factor authentication and a backup someone had actually tested. We fix those first, then test from the outside the way an attacker would.
The basics, done properly
Before anyone talks about advanced threat protection, the fundamentals need to be in place: systems patched on a schedule, MFA on every account that matters, administrator rights removed from day-to-day logins, and backups that are isolated from the network and restored regularly to prove they work. This is where we start, and it removes most of the risk for most businesses.
External penetration testing
We test your internet-facing systems — firewalls, VPNs, remote access, web applications, email — the way an attacker would. You get a written report with findings rated by severity, what each one means for your business, and exactly how to fix it, followed by a retest once the fixes are in. Insurers and larger clients increasingly ask for this report; it's written to be handed over.
Essential Eight
The Australian Cyber Security Centre's Essential Eight is the baseline mitigation strategy for Australian organisations. We assess your current maturity level against each of the eight controls, produce a prioritised uplift plan, and implement it — application control, patching, macro settings, application hardening, admin privilege restriction, MFA and backups. Read our plain-English guide to the Essential Eight.
Email security, backup and recovery
SPF, DKIM and DMARC configured so your domain can't be impersonated; phishing protection and staff awareness; backup and disaster-recovery plans with scheduled restore tests and a written recovery time you can plan around.
ISO 27001 readiness
For organisations that need certification — or need to show a client they're on the path — we help build the controls, policies and evidence, and we build compliance tooling for organisations managing ISO 27001 and similar frameworks.
Had a breach?
Call (02) 9053 0915. Containment first, then investigation and recovery, then the report your insurer will ask for.
FAQ
Questions people ask
How long does a penetration test take?
An external test for a typical small or mid-sized business runs about one to two weeks from scoping to report, depending on the number of systems. Retesting after fixes is quicker.
Will testing disrupt our systems?
External testing is scheduled and non-destructive. We agree the scope, the systems in play and the hours before we start, and stop immediately if anything unexpected happens.
Do we have to do the Essential Eight?
It's mandatory for Commonwealth entities and increasingly expected by insurers, larger customers and government tenders. For everyone else it's simply the most cost-effective baseline available, which is why we recommend it.
Can you help us after a breach?
Yes. Call the office. We contain the incident, work out what happened, get you back to work and produce the documentation your insurer and any regulator will ask for.
Related services
Usually paired with
Managed IT support
Phone, email or remote session — a senior engineer picks it up. Servers, desktops, users, backups.
Read more →NetworksNetworks, cabling & business NBN
Firewalls, switching, Wi-Fi and cabling from Cisco-certified engineers. Business NBN and WAN with end-to-end visibility.
Read more →Microsoft 365Microsoft 365
Migrations off old Exchange and file servers, licensing at the right tier, Intune, Teams and SharePoint.
Read more →Want this sorted?
Tell us what you've got and what's hurting. You'll get an engineer's straight answer and a written figure.