Practice · Security

Cyber security services

Penetration testing, red teaming, digital forensics and incident response, vCISO services and governance across Essential Eight, ISO 27001 and SOC 2. The practice is led by our Chief Information Security Officer and serves regulated and commercial organisations across Australia.

Start a conversation

The practice

Offensive, defensive and governance, together.

Most security firms do one of three things: test systems, respond to incidents, or write governance documents. Our practice does all three under one CISO-led team, which changes the quality of each. Testers who have worked incidents write findings that matter. Responders who know the compliance frameworks capture evidence that survives scrutiny. Governance written by practitioners describes controls that exist.

The practice serves clients directly and secures the systems our other practices build, from Dynamics 365 estates to cloud platforms and custom software.

What we deliver

Four lines of work.

OFFENSIVE

Penetration testing and red team

Web application, API, mobile, cloud and network penetration testing, scoped to what an attacker would actually target rather than what a template lists. Red team engagements test detection and response across people, process and technology.

Reports are written for two audiences: executives get risk in business terms, engineers get reproduction steps and remediation guidance they can action without a follow-up meeting. Retesting after remediation is included, not sold separately.

RESPONSE

Digital forensics and incident response

Incident response for active compromises: containment, investigation, eradication and recovery, with forensic evidence handled so it holds up for insurers, regulators and, where needed, courts. The practice also runs readiness work, response plans, tabletop exercises and rehearsals, because an incident response plan that has never been rehearsed is a document, not a capability.

LEADERSHIP

vCISO

Security leadership as a service for organisations that need CISO-level judgement without a full-time hire: risk assessment, security roadmap, vendor and board reporting, and a standing point of accountability for security decisions. vCISO arrangements run on a retained basis and typically follow an initial assessment that establishes the baseline.

GOVERNANCE

GRC and compliance

Assessment and uplift against Essential Eight, ISO 27001 and SOC 2, run by practitioners who treat the frameworks as a floor rather than a finish line. The work covers gap assessment, control implementation, policy that matches practice, and audit preparation, with the aim that certification reflects an operating reality rather than a documentation exercise.

Delivery

How engagements run.

Scoped against risk, not templates

Engagements start from what the organisation actually holds and who would want it. A pentest scope, an Essential Eight uplift or a response plan built from that starting point costs the same as a templated one and is worth considerably more.

Findings that get fixed

Every assessment ends with a prioritised remediation path, an offer to help deliver it, and retesting to confirm it worked. Where remediation needs engineering, our cloud and software practices do the work rather than leaving a report on the table.

Confidentiality as standard

Security work runs under strict confidentiality, with NDA, defined data handling and Australian-based storage of engagement material. Reports name what was found, not who found it easiest.

Common questions

Security, answered plainly.

How often should we run a penetration test?
At least annually, and after any significant change: a new customer-facing application, a major integration, a cloud migration, an acquisition. Regulated industries and enterprise customer contracts often set the floor. The cadence matters less than the coverage: an annual test of the same scope while the estate grows around it produces confidence without evidence.
What do the Essential Eight maturity levels mean for us?
The Essential Eight defines three maturity levels across eight mitigation strategies, from patching and application control to backups and MFA. Which level you need depends on your threat profile and, increasingly, on what your customers and insurers require. We assess current maturity honestly, including the controls that exist on paper but not in practice, and build the uplift plan from there.
How long does ISO 27001 certification take?
For a mid-sized organisation starting from reasonable practice, nine to twelve months to certification is realistic: gap assessment, control implementation, evidence collection over an operating period, then audit. Faster is achievable when leadership treats it as an operating change rather than a documentation project. SOC 2 runs on a similar arc, with the Type II report requiring a monitoring window.
We think we have an active incident. What happens first?
Containment and evidence preservation, in that order and quickly: isolating affected systems without destroying the forensic record, establishing what the attacker can still reach, and standing up a clean communication channel. Then investigation, eradication and recovery. If you are in this position now, call rather than email, and avoid switching machines off before forensic capture unless data is actively being destroyed.
Is a vCISO enough, or do we need a full-time hire?
Depends on scale and obligation. Most organisations under a thousand people need CISO-level judgement for a few days a month: setting direction, owning risk decisions, reporting to the board, handling customer security reviews. A vCISO covers that at a fraction of a full-time cost. The signal you have outgrown it is when security decisions queue up daily rather than weekly.
Do you test systems you also built?
No. Where Coder Trove has built a system, testing is arranged with independent separation: different personnel, independent reporting lines, and the option of a third-party tester with our cooperation. Marking your own homework is not assurance, and we say so before clients need to ask.

Start here

Tell us what you need tested, or what has happened.

A pentest before a launch, an Essential Eight uplift, a compliance deadline, or an incident in progress. A practitioner replies within one business day.