Penetration Testing in Sydney: A Guide for Regulated Business
Blog

Penetration Testing in Sydney: A Guide for Regulated Business

Siege Cyber is a CREST-accredited company for penetration testing. The accreditation is assessed and held at company level and is verifiable on the CREST member register. In Sydney that matters more than in most Australian cities, because a large share of the organisations buying penetration testing here are doing it to satisfy a regulator or a regulated customer, and both will ask who tested you and what they are accredited to do.

More regulated financial services sit in Sydney than anywhere else in the country. That single fact changes the shape of almost every penetration testing conversation in the city. Elsewhere the trigger is usually a customer questionnaire or a board that got nervous. In Sydney it is just as often a standing obligation with a frequency attached to it.

APRA CPS 234 Makes Testing an Obligation, Not a Project

If your organisation is APRA regulated, testing the effectiveness of your information security controls is not something you choose to do. CPS 234 requires it to be systematic, and it sets the frequency by five factors rather than by a number:

  • the rate at which the vulnerabilities and threats change
  • the criticality and sensitivity of the information asset
  • the consequences of an information security incident
  • the risks associated with exposure to environments where you cannot enforce your own information security policies
  • the materiality and frequency of change to information assets

Two things follow from that, and they are the two things Sydney buyers most often get wrong.

An annual test is a decision, not a default. If your customer-facing platform ships fortnightly, “we test once a year” is very hard to defend against the fifth factor. The schedule needs a written rationale behind it, and the rationale needs to reference those factors specifically.

A vulnerability scan is not testing of control effectiveness. Scanning tells you which known issues exist. Testing tells you whether your controls hold when someone competent works against them. Reviewers know the difference, and the report makes it obvious which one you bought.

CPS 234 also reaches well past APRA regulated entities themselves. It requires controls over information assets managed by related parties and third parties, and internal audit review of those third party controls. If you supply a bank, an insurer or a superannuation fund, that obligation lands on you through the contract even though you are not the regulated entity.

Who Actually Buys Penetration Testing in Sydney

Banks, insurers, superannuation and their suppliers. Driven by CPS 234 and by third party assurance programmes that are increasingly rigorous. Expect the report to be read by someone whose job is to find fault with it.

Fintech and payments. Usually PCI DSS alongside whatever the bank partner requires. Testing scope tends to be tightly defined by the standard, which makes scoping easier and depth expectations higher.

SaaS selling into enterprise. The trigger is a vendor security questionnaire, and the test usually sits inside a broader SOC 2 or ISO 27001 programme rather than standing alone.

Professional services holding client data. Law firms, accountants and consultancies, where the sensitivity of what is held is out of proportion to the size of the IT environment.

Government and government suppliers. NSW agencies and the businesses that sell to them, where the procurement process asks about accreditation before it asks about approach.

The Independence Question

This comes up in Sydney more than anywhere else, and it is worth understanding before you shortlist. Where testing exists to satisfy an obligation, whoever reviews it will care that the tester was independent of the people who built and run the thing being tested.

That rules out a few arrangements that look convenient. Your managed service provider testing the environment they configured is not independent. An internal team testing their own build is not independent. A reseller testing a product they sold you is not independent, and the report will be discounted accordingly.

Company level accreditation helps here because it is assessed by someone with no commercial interest in the outcome, and because you can verify it yourself on the CREST member register rather than accepting a capability statement.

What to Ask a Sydney Penetration Testing Provider

  1. What are you accredited for, specifically? CREST accredits companies by discipline and certifies individuals separately. Penetration testing accreditation does not imply incident response or threat intelligence accreditation. Ask for the discipline and check the register.
  2. Will the report satisfy a CPS 234 reviewer, an ISO 27001 auditor or a client’s assurance team? Ask for a redacted sample and read it as that person would. Reproduction steps, evidence, business impact, specific remediation.
  3. How do you justify the testing frequency you are proposing? A provider who answers with those five CPS 234 factors understands your obligation. One who answers “most clients do annual” does not.
  4. Who is testing, and are they yours? Named individuals, their certifications, employees or subcontractors.
  5. How is our data handled? A penetration test report is a shopping list if it leaks. Ask where findings are stored, how they are transmitted, and how long they are retained.
  6. Is a retest included? You will need evidence that findings were closed, not just found.

What a Test Usually Finds in a Sydney Environment

The pattern here skews differently to other cities, mostly because the environments are older and more integrated. The recurring findings are rarely exotic.

Legacy integrations between core systems and newer platforms, where authentication was handled once at the boundary and then trusted everywhere inside. Service accounts with far more privilege than the function needs, created during a migration and never revisited. Test and staging environments holding production data, reachable from the internet, and outside the scope everyone assumed. Third party components in customer-facing applications that nobody owns the patching of.

None of those are found by a scanner. All of them are the kind of thing an assurance team asks about.

Working With a Brisbane-Based Provider From Sydney

We are based in Brisbane and work with Sydney clients remotely, attending on site where it genuinely helps rather than as a billable default. Same time zone for most of the year, the same regulatory environment, and the people who do your testing are the people who write your report and answer questions about it afterwards.

Testing is fixed price. The number in the proposal is the number on the invoice, and the scope is written down in enough detail that neither side can be surprised by it. If your obligation calls for a testing programme across the year rather than a single engagement, we will structure it that way and document the rationale for the frequency so you are not reconstructing it later under audit.

Getting Started

The fastest route to a number is a short scoping conversation. We will ask what is in scope, what obligation or customer is driving the test, and who is going to read the report, then quote against that.

Get in touch for a Sydney penetration testing quote, read more about our CREST accredited penetration testing, or see the rest of what we do for Sydney cyber security clients.

Siege Cyber is a CREST-accredited company for penetration testing, working with businesses across Australia on fixed-price testing and compliance. Talk to us. Get a Fixed-Price Quote.