Generated by All in One SEO Pro v5.0.0.1, this is an llms.txt file, used by LLMs to index the site. # dotSec - Cyber security specialists Australian cyber security consultancy specialising in testing and assessment, managed cyber, and GRC ## Sitemaps - [XML Sitemap](https://www.dotsec.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Hugging Face: Over the router, through the firewall, off to Grandma's house we go](https://www.dotsec.com/hugging-face-over-the-router-through-the-firewall/) - OpenAI says its own models escaped a test environment and breached Hugging Face. What both companies stated, and what it means for agentic AI security. - [Five multi-billion-dollar companies in two months... the past and the future](https://www.dotsec.com/webrtc-skimmer-past-and-future/) - A WebRTC skimmer hit five major companies in two months. The lesson is not which channel to block, but why assume-breach is the only reliable posture. - [Anthropic Mythos: The model, the myth and the mundane](https://www.dotsec.com/anthropic-mythos-the-model-the-myth-and-the-mundane/) - Anthropic's Mythos Preview is real but the actual fix is the same boring stuff it has always been. Risk frameworks, patching, access controls and verification. - [Surprise PCI compliance request? An Australian SAQ guide](https://www.dotsec.com/pci-dss-saq-guide-australian-merchants/) - Surprise PCI compliance request from your payment provider? Australian SAQ guide: SAQ A vs A-EP vs others, when a QSA is required, and managing costs - [Managed SIEM services case study: tailored Splunk Enterprise Security for an Australian financial services platform](https://www.dotsec.com/managed-siem-services-splunk-enterprise-security-case-study/) - How dotSec built tailored managed SIEM services on Splunk Enterprise Security for a large Australian financial services platform. 205 detections, 13 sources. - [Your service providers, the devil's in the compliance detail](https://www.dotsec.com/pci-saq-a-eligibility-msps-australia/) - What PCI DSS requires of merchants and service providers, which SAQ applies, and why Australian regulators are paying attention. - [Your website provider handles payments. Are you accepting the risk?](https://www.dotsec.com/pci-compliance-website-provider-handles-payments/) - Your website provider may handle payments, but that doesn't make them PCI DSS compliant. Here's what Australian merchants need to know. - [DLL sideloading - Part 1](https://www.dotsec.com/dll-sideloading-part-1/) - This blog post is a result of our investigation into the process that attackers use when sideloading malicious DLLs into .NET executables. - [Proxied Execution via Custom Trace Listeners](https://www.dotsec.com/proxied-execution-via-custom-trace-listeners/) - Gain insights into the security risks of custom TraceListeners in .NET, how they can bypass detection, and practical solutions to safeguard enterprise systems. - [DLL side-loading - Part 2](https://www.dotsec.com/dll-side-loading-part-2/) - Part two of dotSec's investigation into DLL sideloading attacks on .NET executables, exploring how attackers bypass strong-name signature verification. - [Why your staff click spelling-mistake laden emails (and how to actually stop them)](https://www.dotsec.com/why-your-staff-click-spelling-mistake-laden-emails-and-how-to-actually-stop-them/) - Move beyond blame in cybersecurity. Insights on implementing technical guardrails like Secure Web Gateways and FIDO2. Reduce click risk and improve resilience. - [Bypassing Windows application whitelisting](https://www.dotsec.com/insecure-deserialisation-app-control-bypass/) - How an insecure deserialisation in imgmgr.exe (Windows ADK) can bypass Application Control. CVE-2026-25166 details and block list recommendation. - [Sophisticated, state-based actors?​](https://www.dotsec.com/worried-about-sophisticated-state-based-cyber-actors/) - Are sophisticated state-based cyber actors really targeting your organisation? Understanding the actual risks and how to respond proportionately. - [Your developers work for Cyber Gangs](https://www.dotsec.com/your-developers-work-for-cyber-gangs/) - Hidden corporate risks grows as supply chain campaigns hit in-house developers, infecting 1,000+ cloud environments, and many organisations don't know. - [Why ransomware victims pay, and what smart organisations do instead](https://www.dotsec.com/why-ransomware-victims-pay/) - Ransomware follows rational economics. dotSec examines why Australian organisations pay and how preparation, not hope, prevents catastrophic outcomes. - [FIIG fined: Federal Court orders $2.5M penalty for cyber security failures](https://www.dotsec.com/fiig-federal-court-penalty/) - Federal Court orders FIIG Securities to pay $2.5M in civil penalties for cyber security failures. What the judgment means for Australian organisations. - [ASIC sues for systemic and prolonged cybersecurity failures](https://www.dotsec.com/asic-sues-fiig/) - ASIC sues FIIG Securities for systemic and prolonged cybersecurity failures. Ask dotSec about managing cyber risk with managed SOC and managed SIEM - [Case study: data loss detection for national law firm](https://www.dotsec.com/case-study-data-loss-detection-for-national-law-firm/) - Implementation case study: A national Australian law firm uses DEXRR on Splunk ES to detect data exfiltration, with Australian MDR and SIEM delivery. - [Abusing Internet shortcuts for access and persistence​](https://www.dotsec.com/internet-shortcuts-and-dll-hijacking/) - Internet shortcut (.url) files are traditionally used to link to an (Internet-based) URL on Windows systems and trigger the browser to navigate to that URL. - [Hey nice business!](https://www.dotsec.com/hey-nice-business/) - Ransomware and extortion attacks are more common than many realise. Learn why Australian organisations must invest in cybersecurity maturity. - [What? It's borked?](https://www.dotsec.com/what-its-borked-when-on-earth-did-that-happen/) - Why deploying security services without proper design, testing and review leads to failure. Lessons from real-world security incidents. - [SIEM solutions for incident management](https://www.dotsec.com/actual-posts-from-therealmsiem/) - Discover how SIEM solutions enhance incident management with real-world use cases, preventing costly security breaches through early detection and automation. - [Magento as the coal-miner's canary](https://www.dotsec.com/magento-as-the-coal-miners-canary/) - How analysis of web application logs can reveal vulnerabilities beyond the application itself. A practical guide using Magento as an example. - [The human factor: How to undermine your PCI DSS compliance](https://www.dotsec.com/the-human-factor-how-to-undermine-your-pci-dss-compliance/) - Find out how comprehensive employee training can prevent compliance failures and strengthen your organization's security posture. - [Is your candidate real? North Korea scams](https://www.dotsec.com/4hr/) - Discover how North Korea-linked schemes use stolen identities to access US companies and funnel millions back home. Learn more now. - [Scareware v1 - Just silly... probably](https://www.dotsec.com/scareware-v1-just-silly-probably/) - Received a threatening email claiming to have your password and webcam footage? Learn why these scareware attempts are usually just bluffs. - [Security for Australian law firms](https://www.dotsec.com/survey-results-security-for-australian-law-firms-2022-23/) - Results from the 2023 survey on cyber security maturity in Australian law firms, covering approaches, motivations and management practices. - [Cyber insurance: A risky business](https://www.dotsec.com/cyber-insurance-a-risky-business/) - As cyber attack frequency rises and recovery costs increase, understanding cyber insurance coverage is essential for Australian businesses. - [Dangling DNS (2) - Still dangling!](https://www.dotsec.com/dangling-dns-records-part-2-still-dangling/) - Continuing our investigation into dangling DNS records, examining risks beyond Azure including AWS S3 buckets and other cloud services. - [Relax! it's not my first time!](https://www.dotsec.com/relax-its-not-my-first-time/) - The Optus breach feels like deja vu. A look at recurring patterns in Australian data breaches and what organisations should learn from them. - [Not the patches you're looking for](https://www.dotsec.com/pci-dss-confusion-these-are-not-the-patches-youre-looking-for/) - Clarifying a common PCI DSS confusion: when do missing OS or application patches need to be applied for compliance? - [Penetration testing over two years](https://www.dotsec.com/penetration-testing-stats-from-the-past-two-years/) - Case study tracking penetration testing results across two years, showing how regular testing improves an organisation's security posture over time. - [It's in the trees! It's coming!](https://www.dotsec.com/its-in-the-trees-its-coming/) - Lessons from recent cyber incidents: common security failures, attacker tactics and practical steps to improve your organisation's cyber resilience. - [Happy memories of an old hack](https://www.dotsec.com/happy-memories-of-an-old-internet-banking-hack/) - A look back at a 25-year-old internet banking hack that exposed authentication weaknesses in browser-based banking applications. - [SharpC2 in the real world](https://www.dotsec.com/sharpc2-in-the-real-world/) - Practical techniques for bypassing Microsoft Defender using SharpC2 .NET drones and obfuscation, from dotSec's red teaming and EDR-evasion testing. - [It's still borked?](https://www.dotsec.com/its-still-borked-the-amazing-tale-of-the-second-breach/) - Neiman Marcus was breached twice. Examining what went wrong, the class action aftermath, and lessons for Australian organisations. - [Dangling DNS (3) - The final pluck!](https://www.dotsec.com/dangling-dns-records-part-3-the-final-pluck/) - Exploring how attackers exploit abandoned elastic IP addresses in AWS, Azure and GCP to hijack subdomains and mount phishing attacks. - [Dangling DNS (1) - Abandon, despair!](https://www.dotsec.com/dangling-dns-records-part-1-abandon-and-dispair/) - How abandoned DNS CNAME records enable subdomain takeover attacks. Learn the risks and how to protect your organisation's cloud infrastructure. - [TPSP AOCs save you money!](https://www.dotsec.com/tpsp-aocs-scoring-goals-and-saving-money/) - Discover how using a Third Party Service Provider AOC can reduce PCI DSS compliance costs for businesses handling cardholder data. - [Case study: IRAP compliance](https://www.dotsec.com/irap-case-study/) - Case study: How dotSec guided an international service provider through 18 months of work to achieve IRAP-compliant information security management. - [DotSec's AOC saves you money!](https://www.dotsec.com/good-news-dotsecs-aoc-for-service-providers-saves-you-money/) - Learn how dotSec's PCI DSS Attestation of Compliance helps Australian organisations reduce compliance costs and streamline cardholder data security. - [Law Firms And Cyber Tech](https://www.dotsec.com/law-firms-and-cyber-tech-dont-just-do-it/) - Prevent cyber incidents with a risk-driven cybersecurity strategy. Find out how law firms can prioritize threats and choose the right tech solutions. - [2023 State of Cyber Maturity for Australian Law Firm](https://www.dotsec.com/2023-state-of-cyber-maturity-for-australian-law-firm/) - Discover the 2023 cyber security landscape for Australian law firms, including motivations, maturity levels, and management strategies to enhance your defenses. - [It's not what you know...](https://www.dotsec.com/its-not-what-you-know/) - Proactively safeguard your online business with DotSec's expert logging, incident response, and threat detection for Australian web sites and services. - [Cyber news](https://www.dotsec.com/cyber-news/) - Explore the latest cyber threats including deepfake scams, North Korean operatives, insider risks, and how organisations can strengthen their defences. - [Using the NIST Cyber Security Framework (CSF) v2​](https://www.dotsec.com/excellence-then-is-not-an-act-but-a-habit/) - Discover how to leverage the new NIST CSF v2 for effective cyber risk management and resilience in a comprehensive, light-hearted guide. - [Case study: ISO 27001 compliance](https://www.dotsec.com/case-study-iso-27001-compliance/) - Discover how our hands-on ISO 27001 compliance experience ensures practical, effective ISMS implementation for robust information security. - [Case study: Penetration testing for cross-business improvement](https://www.dotsec.com/case-study-penetration-testing-for-cross-business-improvement/) - Discover how dotSec penetration testing helped a multi-business client enhance cybersecurity across locations with consistent, measurable improvements. - [Managed SOC/SIEM use cases​](https://www.dotsec.com/video-four-siem-case-studies/) - Discover how four real-world SIEM use cases demonstrate the power of SIEM and MDR solutions in strengthening security and preventing costly cyber incidents. - [Case study: Using SAQ A to ease PCI DSS compliance](https://www.dotsec.com/case-study-using-saq-a-to-ease-pci-dss-compliance/) - We'll describe how you can use SAQ A to reduce your PCI DSS compliance reporting load. Ask dotSec about Australian PCI DSS consulting services. - [A long life with ISO 27001!](https://www.dotsec.com/happiness-and-long-life-with-iso-27001/) - The consequences of data breaches can be devastating. ISO 27001 offers a way to manage risks, helping to effectively protect information and reputation. ## Pages - [Australian Cyber Security Company | Penetration Testing & GRC Services | DotSec](https://www.dotsec.com/) - DotSec. Brisbane cyber security company: testing and assessment, managed security services, SOC/SIEM/MDR, and governance, risk and compliance. - [PCI DSS compliance for Australian organisations​](https://www.dotsec.com/pci-dss-compliance/) - PCI DSS v4.0.1 compliance for Australian organisations. DotSec is a registered QSA Company — full ROC, gap analysis, SAQ preparation. Fixed pricing available. - [About us](https://www.dotsec.com/about-us/) - dotSec has delivered cyber security services since 2000. Learn about our history, values and approach to protecting Australian organisations. - [Web application penetration testing for Australian organisations](https://www.dotsec.com/web-application-penetration-testing/) - Web application penetration testing for Australian organisations. OWASP-aligned methodology, manual testing, API security, PCI DSS compliance. Brisbane-based, CREST-accredited. - [Penetration testing services for Australian organisations](https://www.dotsec.com/penetration-testing/) - Penetration testing services for Australian government and enterprise. Web app, external network, AI, and red team assessments. CREST-accredited, 25+ years' experience. - [ISO 27001 compliance for Australian organisations​](https://www.dotsec.com/iso-27001-compliance/) - ISO 27001 compliance Australia. 25+ years of practical security work. Gap analysis, implementation, certification. Fixed-fee or capped pricing. Certified staff. - [Brisbane Cyber Security Company | Penetration Testing & GRC Services | DotSec](https://www.dotsec.com/cyber-security-brisbane/) - DotSec is a leading Australian cyber security company (est. 2000) providing expert penetration testing, managed SOC, CIS 18 assessments, and GRC services. - [ACSC Essential Eight Assessments and Uplift​](https://www.dotsec.com/essential-eight/) - Independent ACSC Essential Eight maturity assessments and uplift for Australian organisations. Appropriate maturity-level selection and practical improvements. - [Managed SOC, SIEM and EDR](https://www.dotsec.com/managed-soc-siem-edr/) - 24/7 managed detection and response from DotSec's Australian SOC. Splunk ES and CrowdStrike Falcon in per-customer AWS tenancies. SAIINT AI triage. - [Managed system hardening and secure configuration](https://www.dotsec.com/managed-system-hardening/) - Enhance your security posture with DotSec's system hardening solutions, aligning with industry frameworks to reduce attack surfaces and ensure compliance. - [Managed Web Application Firewall (WAF)](https://www.dotsec.com/managed-waf/) - Learn why Australian organizations rely on WAFs like AWS, Azure, or Cloudflare to safeguard web applications, APIs, and customer portals effectively. - [Tabletop Exercises for Executive & Technical Teams](https://www.dotsec.com/tabletop-exercises/) - Discover how tailored cybersecurity tabletop exercises can strengthen your team’s readiness, improve response plans, and foster a culture of security awareness. - [Red team and adversary simulation for Australian organisations](https://www.dotsec.com/red-teaming/) - dotSec conducts collaborative red and purple team exercises for Australian organisations with mature security controls. Multi-stage detection boundary testing, custom tooling, ADCS assessment. - [Practical Cyber Maturity for Australian Organisations](https://www.dotsec.com/cyber-maturity-reviews/) - Discover how a structured capability maturity review can enhance your organisation's cybersecurity, governance, and risk management practices. - [Pentesting AI](https://www.dotsec.com/pentesting-ai/) - dotSec tests AI systems and LLMs for Australian organisations, targeting prompt injection, data poisoning, and other AI-specific vulnerabilities. - [Identity and access management](https://www.dotsec.com/identity-and-access-management/) - Explore MFA and SSO solutions including Duo, Azure and Okta, designed to protect sensitive data and meet Australian compliance standards. - [Identify and prioritise risk​](https://www.dotsec.com/prioritise-risk/) - Discover how dotSec's structured risk identification and prioritisation services help your organization navigate cybersecurity threats effectively. - [External Network Penetration Testing for Australian Organisations](https://www.dotsec.com/external-network-penetration-testing/) - dotSec provides external network penetration testing for Australian government and enterprise organisations. CREST-accredited, Brisbane-based. Identify and remediate internet-facing vulnerabilities. - [CIS 18 Critical Security Controls Assessment](https://www.dotsec.com/cis-controls-assessment/) - Independent CIS 18 Critical Security Controls assessments for Australian organisations. Identify gaps, reduce risk, and build measurable security maturity. - [Apply cyber security controls​](https://www.dotsec.com/apply-controls/) - Learn how targeted, risk-driven security controls, supported by standards like ISO 27001, CIS 18 and ISO 27001, protect your business from cyber threats. - [AI-augmented penetration testing for Australian organisations](https://www.dotsec.com/ai-augmented-penetration-testing/) - dotSec combines 25+ years of pen testing expertise with AI-augmented tools for faster, broader security assessments across Australian organisations. - [Vulnerability scanning and assessment services](https://www.dotsec.com/vulnerability-scanning/) - Managed vulnerability scanning and assessment for Australian organisations. Continuous monitoring, prioritised remediation, penetration testing integration. - [Verify control effect​](https://www.dotsec.com/verify-effect/) - Learn why continuous control verification is vital. Explore dotSec’s expert services in penetration testing, social engineering, and adversary emulation. - [Social engineering and phishing exercises](https://www.dotsec.com/social-engineering-phishing/) - Test your team's resilience with dotSec's social engineering and phishing exercises, designed to assess staff response and strengthen defences. - [SAIINT: Secure AI-integrated notable triage](https://www.dotsec.com/saiint/) - Understand how AI-powered SAIINT strengthens DotSec’s Managed SOC with enhanced accuracy, transparency, and compliance for your security needs. - [Testing and assessment](https://www.dotsec.com/testing-and-assessment/) - Testing and assessment services Australian security testing expertise Independent security testing helps you confirm that your controls are working as intended, and helps you prioritise your remediation activities if they are not.DotSec’s testing and assessment services help Australian organisations identify weaknesses, validate controls, and prioritise improvement actions so that boards, executives, and technical teams can - [News and updates](https://www.dotsec.com/news-and-updates/) - Gather insights and learn from dotSec's 25+ years of cyber security experience. IRAP, EDR-evasion, ISO 27001 and PCI DSS, ACSC Esseantial Eight and more! - [Cyber security services](https://www.dotsec.com/cyber-security-services/) - dotSec delivers practical cyber security services including penetration testing, GRC, managed SOC and incident response for Australian organisations. - [Our team](https://www.dotsec.com/our-team/) - Meet the dotSec cyber security team. Our consultants bring decades of experience in penetration testing, GRC, managed SOC and incident response. - [Contact us](https://www.dotsec.com/contact-us/) - Get in touch with dotSec's cyber security team for penetration testing, GRC services, managed SOC and security consulting across Australia. ## Categories - [Uncategorized](https://www.dotsec.com/category/uncategorized/) - [Testing](https://www.dotsec.com/category/testing/) - [Risk](https://www.dotsec.com/category/risk/) - [Services](https://www.dotsec.com/category/services/) - [Success stories](https://www.dotsec.com/category/success-stories/)