Skip to content
Penetration testing
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
All services on one page
Industries How we work About Blog
1300 AURIAN Contact
Menu
Penetration testing
  • Penetration testing services
  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation
Security assurance
  • Security assurance and compliance services
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
Managed security
  • Managed security services
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring
  • All services
  • Industries
  • How we work
  • About
  • Blog
Call 1300 AURIAN Contact
  1. Industries

Penetration testing for every sector

Aurian works across every sector. These are the ones we work in most, with the engagements each usually needs and the obligations behind them.

  • Federal government
  • State government
  • Local government
  • Independent and faith-based schools
  • Universities and tertiary education
  • Not-for-profits and associations
  • Financial services and lenders
  • Legal services
  • Professional services
  • Healthcare
  • Utilities and critical infrastructure
  • Manufacturing, construction and industrial
  • Technology and SaaS
  • Automotive, logistics and transport
  • Enterprise

Federal government

Non-corporate Commonwealth entities must reach Essential Eight Maturity Level Two under the Protective Security Policy Framework and report against it, with the Information Security Manual behind every control. Statutory bodies and corporate entities are held to the same bar by their boards and auditors. The rating has to be earned on evidence, and testing is where the evidence comes from.

Engagements usually start with an Essential Eight assessment that tests each strategy against Maturity Level Two with evidence from the systems themselves, or with an external network penetration test of the public-facing services and remote access. Web application testing of the portals follows, internal network tests examine the paths from a compromised workstation to the records, cloud security assessments cover the Microsoft 365 tenancy and the Azure or AWS workloads, and configuration reviews close the gaps the tests found. Aurian does not hold IRAP-endorsed assessors; where an IRAP assessment is required, our testing supplies the evidence it draws on.

Obligations and drivers

  • Protective Security Policy Framework: Essential Eight Maturity Level Two for non-corporate Commonwealth entities, and annual reporting
  • Information Security Manual controls behind each strategy
  • Privacy Act 1988 and the Notifiable Data Breaches scheme
  • Australian National Audit Office cyber security audits

Typical engagements

  • Essential Eight assessment

    Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Web application penetration testing

    Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

  • Internal network penetration testing

    Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Configuration review and benchmarking

    Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

State government

State agencies hold the records of everyone they serve and run the services people cannot go elsewhere for, under cyber security policies that name the controls and demand an annual attestation backed by evidence. Audit offices test that attestation in public. The evidence has to come from testing, not from a questionnaire.

Engagements usually start with an Essential Eight assessment that produces the evidence the annual attestation needs, strategy by strategy, or with an external network penetration test of the citizen-facing services and the remote access behind them. Web application testing of the portals and case systems follows, internal network tests examine the paths from a compromised workstation to the records, cloud security assessments cover the Microsoft 365 tenancy and any Azure or AWS workloads, and configuration reviews of the standard operating environment and the firewalls close the loop where the tests found the gaps.

NSW agencies can engage Aurian through the ICT Services Scheme (SCM0020), which the NSW Procurement Board mandates for ICT services, so a purchase order can be raised without an open tender.

Obligations and drivers

  • NSW Cyber Security Policy: the Essential Eight at Maturity Level 1 or above and an annual attestation to Cyber Security NSW by 31 October, with evidence kept
  • Audit office cyber security performance audits, including compliance with the state policy
  • Victorian Protective Data Security Standards, mandatory for Victorian public sector bodies under the Privacy and Data Protection Act 2014
  • Queensland's Information and cyber security policy (IS18) for departments
  • State privacy legislation

Typical engagements

  • Essential Eight assessment

    Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Web application penetration testing

    Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

  • Internal network penetration testing

    Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Configuration review and benchmarking

    Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

Local government

Councils run public-facing services and payment portals on one side and a long tail of legacy systems on the other, often with suppliers holding remote access to parts of the estate. State audit offices publish what they expect, and the Essential Eight is the yardstick.

A typical programme pairs an external network penetration test of the public services with an internal test that includes supplier access paths and the legacy systems nobody wants to touch. Essential Eight assessments give the audit committee a maturity rating per strategy and a roadmap. Cloud security assessments cover the Microsoft 365 tenancy and any Azure or AWS workloads, and configuration reviews of firewalls and the standard operating environment follow where the internal test found the gaps.

Councils in New South Wales can engage Aurian through Local Government Procurement’s IT&C Products, Services and Consulting panel (LGP115-2), councils in Queensland, the Northern Territory and Tasmania through Local Buy’s ICT arrangement (LB308), and NSW Government agencies through the ICT Services Scheme (SCM0020), so an engagement can be raised against a panel rather than an open tender.

Obligations and drivers

  • Essential Eight, as adopted in state cyber security policies for councils
  • State privacy legislation and information-security requirements
  • Audit office cyber security performance audits

Typical engagements

  • Essential Eight assessment

    Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Internal network penetration testing

    Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Configuration review and benchmarking

    Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

Independent and faith-based schools

Schools hold sensitive information about children and families, run student, staff and BYOD devices across the same infrastructure, and answer to boards, auditors and insurers who now ask for evidence of testing. A small IT team carries all of it alongside the day job.

Engagements usually begin with an Essential Eight assessment, because it is what the board and the insurer ask about, or with an internal network penetration test that looks hard at the separation between student, staff and BYOD networks. From there the common additions are a Microsoft 365 and identity review, testing of the learning management system and parent portals, and a phishing simulation for staff that produces a baseline the school can act on without naming anyone.

Obligations and drivers

  • Privacy Act 1988 and the Notifiable Data Breaches scheme
  • Cyber insurance renewal questionnaires that ask for evidence of testing
  • Diocesan and system cyber security policies, for schools that belong to one

Typical engagements

  • Essential Eight assessment

    Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

  • Internal network penetration testing

    Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Web application penetration testing

    Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

  • Social engineering and phishing simulation

    Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

Universities and tertiary education

Universities run some of the most open networks in the country: tens of thousands of students and staff, research that crosses borders, federated identity, and decades of systems side by side. Registered universities are critical infrastructure under the Security of Critical Infrastructure Act, TEQSA expects information systems to be kept secure, and the foreign interference guidelines put cyber security on the council's agenda. TAFEs and other public providers answer to state cyber security policies as well.

Engagements usually start at the edge: an external network penetration test of the perimeter and the remote access that thousands of people use every day, and web application and API testing of the student-facing platforms, the learning management system and the research portals. Internal network tests follow the federated identity through to the research, HR and finance systems, cloud security assessments cover the Microsoft 365 or Google tenancy and the research workloads in AWS or Azure, and a phishing simulation gives the security team a baseline across a population that turns over every year.

Obligations and drivers

  • Security of Critical Infrastructure Act 2018: registered universities are critical education assets, with mandatory cyber incident reporting
  • Higher Education Standards Framework 2021, standard 7.3.3, on keeping information systems and records secure
  • Guidelines to Counter Foreign Interference in the Australian University Sector
  • Privacy Act 1988 and the Notifiable Data Breaches scheme
  • State cyber security policies for TAFEs and other public providers

Typical engagements

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Web application penetration testing

    Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

  • API penetration testing

    API penetration testing for REST, GraphQL and SOAP against the OWASP API Security Top 10: authorisation, rate limiting and undocumented endpoints.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Internal network penetration testing

    Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

  • Social engineering and phishing simulation

    Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

Not-for-profits and associations

Charities and associations hold donor, member and beneficiary records, take payments, and run on Microsoft 365 with a small team or a volunteer looking after it. The ACNC has made cyber security a compliance focus and places the responsibility with the board, and funders and insurers increasingly ask for evidence of controls. The question is how to get real assurance on a modest budget.

Engagements are scoped to the budget: an Essential Eight assessment gives the board a rating and a roadmap it can fund over time, an external network penetration test covers the perimeter and remote access, and a Microsoft 365 and identity review covers the tenancy where most of the risk sits. Web application testing follows for the donation, membership or booking platform, and a phishing simulation gives staff and volunteers a baseline without naming anyone.

Obligations and drivers

  • ACNC Governance Standards 3 and 5: lawful operation and the responsible persons' duty of care and diligence, with cyber security an ACNC compliance focus
  • Privacy Act 1988 and the Notifiable Data Breaches scheme, for organisations over the turnover threshold, health providers and those that opt in
  • Funding agreements and cyber insurers that ask for evidence of security controls
  • Card payment obligations where donations and fees are taken online

Typical engagements

  • Essential Eight assessment

    Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Web application penetration testing

    Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

  • Social engineering and phishing simulation

    Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

Financial services and lenders

Lenders and financial firms hold identity and credit data, run customer portals and APIs that partners and brokers depend on, and face questions from regulators, auditors, banks and insurers about how that data is protected. The evidence has to stand up to someone reading it closely.

Most engagements start with the customer-facing surface: an external network penetration test and a web application or API test of the portal, the broker channel and the integrations behind it. Cloud security assessments cover the platform those applications run on. Configuration reviews and formal retesting produce the evidence that auditors and partners ask for, with an updated report that shows each finding was closed.

Obligations and drivers

  • APRA CPS 234 Information Security, for APRA-regulated entities
  • Privacy Act 1988, the Australian Privacy Principles and the Notifiable Data Breaches scheme
  • Due-diligence questionnaires from funders, banks and partners

Typical engagements

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Web application penetration testing

    Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

  • API penetration testing

    API penetration testing for REST, GraphQL and SOAP against the OWASP API Security Top 10: authorisation, rate limiting and undocumented endpoints.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Configuration review and benchmarking

    Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

  • Remediation support and retesting

    Penetration test remediation support and retesting: hands-on help closing findings, sessions with your engineers or MSP, and a formal retest and report.

Legal services

A firm holds material that is privileged, confidential and, for the other side, valuable. It moves money through trust accounts, settles property through PEXA, and lives in email, which is where payment-redirection fraud and document lures arrive. The Microsoft 365 tenancy is usually the whole estate, and one compromised mailbox is a breach of every matter in it.

An external network penetration test and a Microsoft 365 and identity review cover the perimeter that matters: remote access, mail, Conditional Access and the administrator accounts. A phishing simulation shows how staff respond to the invoice, settlement and document-share lures that target firms, an Essential Eight assessment gives the partners a rating to report to clients and the insurer, and web application testing covers the client portal where the practice runs one. Endpoint monitoring suits firms that want the tenancy watched between tests.

Obligations and drivers

  • Confidentiality duties under the Legal Profession Uniform Law and the professional bodies' cyber security guidance
  • PEXA's Subscriber Security Policy for firms that settle electronically
  • Privacy Act 1988 and the Notifiable Data Breaches scheme
  • Cyber insurance and client panel requirements for multi-factor authentication and testing

Typical engagements

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Social engineering and phishing simulation

    Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

  • Essential Eight assessment

    Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

  • EDR monitoring

    Managed EDR monitoring on your endpoint platform: alert triage, investigation, containment guidance, threat hunting and tuning by the consultants who test.

  • Web application penetration testing

    Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

Professional services

Accounting, engineering, actuarial and advisory firms hold client material that would be damaging in the wrong hands, and email is both the way work arrives and the way attacks arrive. The Microsoft 365 tenancy is usually the whole estate.

An external network penetration test and a Microsoft 365 and identity review cover the perimeter that matters: remote access, mail, Conditional Access and the administrator accounts. Phishing simulations show how staff respond to the invoice and document-share lures that target firms like yours, and an Essential Eight assessment gives partners a rating to report to clients and the insurer.

Obligations and drivers

  • Client contractual and professional-body confidentiality obligations
  • Privacy Act 1988 and the Notifiable Data Breaches scheme
  • Cyber insurance requirements for multi-factor authentication and testing

Typical engagements

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Social engineering and phishing simulation

    Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

  • Essential Eight assessment

    Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

  • EDR monitoring

    Managed EDR monitoring on your endpoint platform: alert triage, investigation, containment guidance, threat hunting and tuning by the consultants who test.

Healthcare

Health records are among the most sensitive data any organisation holds, and clinical networks mix medical devices, building systems and administrative computing that cannot all be patched on the same schedule. Availability matters as much as confidentiality when the systems are in use around the clock.

The internal network penetration test is where most healthcare engagements begin, with segmentation between clinical devices, administrative systems and guest networks tested rather than assumed. Patient and practitioner portals get a web application test. Phishing simulations are run with care for shift patterns and clinical workloads, and Essential Eight assessments give the executive a rating they can report against.

Obligations and drivers

  • Privacy Act 1988, the Australian Privacy Principles and the Notifiable Data Breaches scheme
  • My Health Record obligations for connected providers
  • State health department security requirements

Typical engagements

  • Internal network penetration testing

    Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

  • Web application penetration testing

    Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

  • Social engineering and phishing simulation

    Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

  • Essential Eight assessment

    Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

  • Configuration review and benchmarking

    Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

Utilities and critical infrastructure

Operators of critical infrastructure carry obligations under the Security of Critical Infrastructure Act and answer to regulators as well as customers. The boundary between corporate IT and operational technology is where an attacker would look first, and it is where testing has to be planned most carefully.

Engagements are scoped around the boundary. External network penetration tests cover the corporate perimeter and remote access, cloud security assessments cover landing zones and the identity that spans them, and segmentation reviews examine the controls between corporate and operational networks without touching the operational side unless that is explicitly agreed. Configuration reviews of the firewalls that enforce those boundaries follow, and SIEM monitoring keeps eyes on the crossing points.

Obligations and drivers

  • Security of Critical Infrastructure Act 2018 and the Critical Infrastructure Risk Management Program
  • AESCSF for energy operators
  • ASD Essential Eight

Typical engagements

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Configuration review and benchmarking

    Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

  • Internal network penetration testing

    Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

  • SIEM monitoring

    Managed SIEM monitoring: correlation and triage of events from network, endpoint, cloud and identity sources, with rule tuning and monthly reporting.

Manufacturing, construction and industrial

Manufacturers and industrial businesses run corporate IT next to the plant, the site and the fleet, and an attacker who lands on the office network looks straight for the systems that make, move and build things. Larger customers now write security requirements into contracts, ask for ISO 27001 evidence, and expect suppliers to a critical sector to carry its obligations.

Engagements usually begin with an external network penetration test of the perimeter and remote access, then an internal test that examines the separation between the corporate network and the operational technology without touching the operational side unless that is explicitly agreed. Configuration reviews of the firewalls that enforce those boundaries follow, an Essential Eight assessment gives the board and the customers a rating, vulnerability management keeps the estate watched between tests, and a phishing simulation covers the finance and purchasing staff that invoice fraud targets.

Obligations and drivers

  • Customer contract security requirements and ISO 27001 evidence requests through the supply chain
  • Security of Critical Infrastructure Act obligations for suppliers to critical sectors, and the Defence Industry Security Program for defence suppliers
  • Privacy Act 1988 and the Notifiable Data Breaches scheme
  • Cyber insurance requirements for multi-factor authentication, backups and testing

Typical engagements

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Internal network penetration testing

    Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

  • Configuration review and benchmarking

    Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

  • Essential Eight assessment

    Essential Eight assessment against the ASD maturity model: every strategy tested with evidence, rated ML0 to ML3, with a prioritised uplift roadmap.

  • Vulnerability management

    Managed vulnerability management: continuous scanning of external and internal assets, results validated and ranked by a consultant, reported monthly.

  • Social engineering and phishing simulation

    Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

Technology and SaaS

For a SaaS or advertising technology company the web application and its API are the business, and every enterprise customer's procurement process asks for evidence that they have been tested. Releases ship weekly or daily, so a test from twelve months ago says less than it used to.

The core engagement is an authenticated web application and API penetration test, repeated annually and after major releases, with a cloud security assessment of the AWS, Azure or Google Cloud environment the platform runs on. Continuous application scanning sits between manual tests and flags drift between releases. Retesting produces the updated report and attestation letter that customers’ security teams ask for, the letter on request at no charge.

Obligations and drivers

  • Customer due-diligence questionnaires and evidence requests
  • Privacy Act 1988 and the Notifiable Data Breaches scheme
  • Contractual security clauses in enterprise agreements

Typical engagements

  • Web application penetration testing

    Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

  • API penetration testing

    API penetration testing for REST, GraphQL and SOAP against the OWASP API Security Top 10: authorisation, rate limiting and undocumented endpoints.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Continuous application scanning

    Continuous web application scanning between manual tests: authenticated scans with human review, drift detection between releases and monthly summaries.

  • Remediation support and retesting

    Penetration test remediation support and retesting: hands-on help closing findings, sessions with your engineers or MSP, and a formal retest and report.

Automotive, logistics and transport

Depots, warehouses, dealerships and vehicles spread the estate across many sites with wireless everywhere, telematics and warehouse systems on the operational side, and manufacturers and major customers setting security requirements by contract.

External and internal network penetration tests establish what an attacker reaches from the internet and from a depot floor. Wireless penetration testing covers the corporate and scanner networks in warehouses and yards, where signal leaks well beyond the fence. Reviews of the boundary between office IT and operational systems, and phishing simulations for dispatch and administration staff, round out the usual programme.

Obligations and drivers

  • Contractual security requirements from manufacturers and major customers
  • Privacy Act 1988 and the Notifiable Data Breaches scheme
  • Security of Critical Infrastructure Act 2018 obligations for transport operators captured as critical infrastructure: aviation, ports, freight infrastructure and services, and public transport

Typical engagements

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Internal network penetration testing

    Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

  • Wireless penetration testing

    Wireless penetration testing of corporate and guest Wi-Fi: WPA2 and WPA3-Enterprise, rogue access points, guest isolation and signal leakage.

  • Configuration review and benchmarking

    Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

  • Social engineering and phishing simulation

    Phishing simulation and social engineering assessment: measured, consented email and voice campaigns that show your awareness baseline and process gaps.

Enterprise

Larger organisations have internal security teams and still need an independent view: a fresh set of senior eyes on the estate, a programme that covers the whole attack surface over a year, and reporting that holds up in front of the board and the auditors.

Enterprise programmes combine several services over a year: external and internal network tests, application and API tests as systems change, cloud security assessments of each platform, configuration reviews of the controls that matter most, and vulnerability management in between. One consultant coordinates the programme so the findings from each engagement inform the next, and the annual report to the board shows the trend rather than a list.

Obligations and drivers

  • Board and audit committee reporting on cyber risk
  • ISO 27001 internal audit and surveillance evidence
  • Sector regulation as applicable

Typical engagements

  • External network penetration testing

    External penetration testing of your internet-facing perimeter: exposed services, VPN, mail and DNS, tested by hand by a senior consultant.

  • Internal network penetration testing

    Internal penetration testing from a foothold on your network: Active Directory attack paths, credential hygiene and segmentation, tested to domain admin.

  • Web application penetration testing

    Web application penetration testing against the OWASP Testing Guide: authentication, access control, injection and business logic, tested by hand.

  • Cloud security assessment

    Cloud security assessment for AWS, Azure, Microsoft 365 and Google Cloud: CIS Benchmark review and attack-path testing of identity, exposure and logging.

  • Configuration review and benchmarking

    Security configuration review of firewalls, servers, endpoints, network devices and Microsoft 365 against CIS Benchmarks, with the exact settings to change.

  • Vulnerability management

    Managed vulnerability management: continuous scanning of external and internal assets, results validated and ranked by a consultant, reported monthly.

The method is the same in every sector

If yours is not listed, tell us what you run and who is asking for the test, and we will scope it the same way.

Scope a test Call 1300 AURIAN

Aurian Security is an Australian penetration testing and security assurance firm. Senior consultants perform every engagement, for clients across the country.

Penetration testing

  • External network penetration testing
  • Internal network penetration testing
  • Web application penetration testing
  • API penetration testing
  • Mobile application penetration testing
  • Wireless penetration testing
  • Cloud security assessment
  • Social engineering and phishing simulation

Assurance and managed

  • Security assurance
  • Essential Eight assessment
  • Configuration review and benchmarking
  • Remediation support and retesting
  • Managed security
  • Vulnerability management
  • Continuous application scanning
  • SIEM monitoring
  • EDR monitoring

Company

  • About Aurian
  • How we work
  • Industries
  • Blog
  • Contact
  • Privacy policy
526/368 Sussex St, Sydney NSW 2000 1300 AURIAN (1300 287 426) sales@aurian.com.au

© 2026 Aurian Security Pty Ltd. ACN 639 930 528.

This site is static, loads no third-party trackers, and publishes a security.txt.