Identifying and prioritising risk puts you in the driver’s seat, and risk-based controls put resources where they are needed most. The third part of a successful cyber strategy is verification.
years testing for government and enterprise
CREST-accredited through CREST ANZ
Controls must be verified to confirm they are effective and resilient, and that they keep delivering as your risks change.
Without frequent verification, controls that worked in the past can end up offering little more than a false sense of security.
Each service links to its own page with the detail.
For more than 25 years we have provided penetration testing for corporate and government organisations. Our testers do more than test: they build AWS-hosted services and IAM systems, have system hardening skills, and rotate through EDR and SIEM analyst roles.
That experience means practical, prioritised strategies that are reasonable to implement.
Phishing remains the most common form of social engineering, but attackers increasingly diversify their methods to get past technical safeguards.
Social engineering tests verify your awareness training and reporting controls, and support ISO/IEC 27001 (A.6.3), PCI DSS (12.6) and the ISM’s user education controls.
A capability maturity assessment measures how well your security processes and controls are designed, managed and improved over time, and builds a roadmap for improvement.
Assessments usually reference the CIS Controls v8.1, ISO/IEC 27002:2022 and the Australian Privacy Principles, with the NIST CSF or the Essential Eight where useful.
A tabletop exercise (TTX) is an interactive simulation that tests your incident response plan, capabilities and processes in a safe, controlled environment.
It shows where detection, containment and response need work, without the disruption and cost of an adversary emulation test.
Effective cyber security is a cycle: identify and prioritise your risks, apply controls that address them, then verify the controls work, and repeat as your risks change. See all our governance, risk and compliance services.
Want evidence that your controls work? We will scope testing and assessment around your risks and obligations.
Verification feeds back into risk prioritisation, so each cycle starts from better information.
Practical and experienced Australian ISO 27001 and ISMS consulting services. We will help you to establish, implement and maintain an effective information security management system (ISMS).
dotSec’s penetration tests are conducted by experienced, Australian testers who understand real-world attacks and secure-system development. Clear, actionable recommendations, every time.
dotSec stands out among other PCI DSS companies in Australia: We are not only a PCI QSA company, we are a PCI DSS-compliant service provider so we have first-hand compliance experience.
Web Application Firewalls (WAFs) are critical, protecting web apps and services by inspecting and filtering malicious requests before they reach your servers. Web page or API, a WAF is your first defence.
Multi-Factor Authentication (MFA) and Single Sign-On (SSO) reduce password risks, simplify access, letting verified and authorised users reach sensitive systems, services and apps.
dotSec provides comprehensive vulnerability management services. As part of this service, we analyse findings in the context of your specific environment, priorities and threat landscape.
We don’t just test whether users will click a suspicious link — we also run exercises, simulating phishing attacks that are capable of bypassing multi-factor authentication (MFA) protections.
dotSec’s penetration testing services help you identify and reduce technical security risks across your applications, cloud services and internal networks. Clear, actionable recommendations, every time!
dotSec has provided Australian managed SOC, SIEM and EDR services for 15 years. PCI DSS-compliant and ISO 27001-certified. Advanced log analytics, threat detection and expert investigation services.
We provide prioritised, practical guidance on how to implement secure configurations properly. Choose from automated deployment via Intune for Windows, Ansible for Linux or Cloud Formation for AWS.
Secure web hosting is fundamental to protecting online assets and customer data. We have over a decade of AWS experience providing highly secure, scalable, and reliable cloud infrastructure.
dotSec helps organisations to benefit from the ACSC Essential Eight by assessing maturity levels, applying practical security controls, assessing compliance, and improving resilience against attacks.
Evaluation against the CIS 18 Controls establishes a clear baseline for stakeholders, supporting evidence-based planning, budgeting, maturity-improvement and compliance decisions
We have over 25 years of cyber security experience, providing practical risk-based guidance, advisory and CISO services to a wide range of public and private organisations across Australia.