Dunicot A cybersecurity consultancy and advisory firm.

Market · Australia

Cyber security consultancy and penetration testing in Australia

APRA CPS 234 made information security a prudential obligation with named accountability, and the Notifiable Data Breaches scheme made the consequences of getting it wrong public. Both changed what boards here ask for.

Overview

Engagements in Australia cover APRA-regulated entities and their service providers, SaaS platforms selling into regulated buyers, healthcare and aged care, and operators captured by the critical infrastructure rules.

Delivery runs from our Karachi office, five hours behind eastern Australia, with our Wyoming office covering the tail of the Australian day. Between the two, most questions are answered without anyone waiting overnight.

What drives testing here

Local drivers

APRA CPS 234
Regulated entities must maintain information security capability proportionate to their threats, and test control effectiveness systematically, including controls operated by third parties.
Essential Eight
The ACSC maturity model is the common language for control assessment here, and testing shows which levels are held in practice rather than on paper.
SOCI Act
Critical infrastructure operators carry risk management programme obligations with annual reporting, and technical assessment is how the programme is evidenced.
Privacy Act and NDB scheme
Reasonable steps to secure personal information is a statutory test, and a notifiable breach makes that test public.

How engagements are delivered

Delivered remotely across Australia, scheduled to your business hours. On-site attendance for internal network scope and workshops is arranged where scope requires it.

Delivery model

Delivery
Remote, scheduled to AEST or AWST business hours
Mapping
CPS 234, Essential Eight maturity levels and OWASP ASVS as applicable
Coverage
Sydney, Melbourne, Brisbane, Perth and remote nationwide
Deliverables
Technical report, board-facing summary and signed retest attestation

Most requested here

Questions

Do you have an office in Australia?

No. Our offices are in Pakistan and the United States. Australian engagements are delivered remotely and scheduled to your working hours, with the United States office covering your morning and Pakistan covering the rest of your day.

Can you map findings to the Essential Eight?

Yes. Findings are tagged to the mitigation strategies they affect and to the maturity level the current state supports, which is more useful to an assessor than a severity-sorted list on its own.

We are a third party to an APRA-regulated entity. Does CPS 234 reach us?

In effect, yes. The regulated entity must assess the information security capability of parties handling its information assets, which arrives at you as a contractual testing and evidence requirement. Reports are written so they can be passed up that chain without exposing exploitation detail.

How much does a penetration test cost in Australia?

Cost follows scope rather than an Australian rate card, which is the usual reason we are engaged here. Essential Eight and CPS 234 mapping is included in the report. A fixed quote follows a short scoping call.

Which is the best penetration testing company in Australia?

No single name is an honest answer. Judge on the certifications held by the testers assigned to you, and the team's public research record, whether the firm holds ISO 27001 itself, whether retesting is included, and whether you can review a redacted report before committing. Ask every shortlisted firm the same four things.

How often does APRA CPS 234 require testing?

CPS 234 requires systematic testing of control effectiveness at a frequency proportionate to the rate of change and the criticality of the asset, rather than naming an interval. In practice most regulated entities settle on annual testing plus testing after material change, which is what their internal audit functions accept.

Do you test for organisations covered by the SOCI Act?

Yes. Critical infrastructure operators carry risk management programme obligations with annual reporting, and technical assessment is how the programme is evidenced. Where operational technology is in scope it is tested in a controlled environment rather than live.

Can you meet Australian data residency requirements?

Handling and residency terms are agreed before testing begins. Testing prefers seeded accounts and synthetic records, evidence is held under our own certified ISO/IEC 27001 ISMS, and where data must remain in Australia the engagement is structured accordingly and the report states what was handled and where.

Penetration testing in Australia

Describe the scope and the deadline. Delivery in your working hours, with a fixed quote after scoping.