Skip to content
Cyber Solutions

Security Testing and Assurance

Test your defences before someone else does.

Security Testing and Assurance
Scope → Test → Retest
Overview

Most organisations know roughly where they are exposed. Far fewer can prove which exposures are exploitable, which controls hold under a real penetration test, and which of the hundreds of findings in last quarter's vulnerability assessment deserves budget first.

Meanwhile the bar keeps rising: customers and insurers increasingly expect independent testing as a condition of doing business, and the enhanced CIRMP Rules require eligible critical infrastructure entities to meet maturity baselines, not periodic check-ins. Avocado runs the testing and assurance cycle end to end including penetration testing, vulnerability, technical, data security, threat and IoT assessments and translates the results into a prioritised, costed remediation program your engineers and executives can both act on.

Who is this for?

You'll recognise the situation

You know roughly where you're exposed but can't prove which exposures are actually exploitable.

Customers and insurers increasingly expect independent testing as a condition of doing business.

Hundreds of findings from last quarter's vulnerability scan sit untriaged, with no clear answer on what deserves budget first.

You're an eligible critical infrastructure entity that needs to meet maturity baselines under the enhanced CIRMP Rules, not just pass a periodic check-in.

What's included

The full testing and assurance cycle

Penetration Testing

Independent, specialist-delivered penetration testing — scoped, managed and quality-assured by Avocado.

Application Security and DevSecOps

Build security into your applications and pipelines so every release ships tested, not hopeful.

Data Security

Discover and assess how your sensitive data is classified, protected and controlled across its lifecycle.

Vulnerability Assessments

Tool-based scanning with Nessus, Qualys and Microsoft Defender, triaged into a prioritised remediation plan.

Technical Assessments

Configuration reviews of Active Directory, cloud, operating system and EAP builds against CIS and Microsoft benchmarks.

Threat Assessment

Understand which threat actors and techniques actually matter to your environment — and test against those.

IoT Risk Assessment

Discover and assess the connected devices your standard tooling can't see.

In detail

How each capability works

01

Penetration Testing

Independence, twice over. Testing is delivered by vetted specialist penetration testing partners, so the people attacking your systems are career testers doing nothing else — and because they are not us, nobody is marking their own homework. Avocado owns everything around the test: threat-led scoping, quality assurance of findings, translation of the report into a remediation plan, and retest to confirm the fix.

Our approach
  • Threat-led scoping — what an attacker would target, what a breach would cost, and therefore what to test, aligned to the OWASP Testing Guide and MITRE ATT&CK.
  • Test types matched to the question — external and internal network, web application, API, mobile, wireless and cloud environment testing, and social engineering where agreed.
  • Delivery managed end-to-end by Avocado, under your legal and data handling requirements.
  • Quality assurance of findings — every reported issue validated, rated for exploitability and business impact, and stripped of false positives.
  • Remediation planning with your engineering teams, with fixes sequenced by risk, and retest and closure evidence suitable for customers, auditors and insurers.
02

Application Security and DevSecOps

Avocado's DNA is delivery automation: we have spent more than two decades building and automating delivery pipelines for regulated Australian enterprises. Our consultants have run the pipelines they are securing. We embed controls into the toolchain your teams already use, so the secure path is also the fast path and security stops being the team that says no.

Our approach
  • Secure SDLC and DevSecOps maturity assessment against OWASP SAMM, with a prioritised uplift roadmap.
  • Threat modelling for critical applications, including STRIDE analysis, integrated into design and refinement.
  • Security tooling in the pipeline — SAST, DAST, software composition analysis and secrets detection wired into CI/CD with tuned, actionable gates.
  • Secure code review of critical components and remediation guidance developers can apply.
  • API, container and infrastructure-as-code security controls and hardening; secrets management and software supply chain controls.
  • Developer security capability uplift, delivered with our Cyber Security Training service.
03

Vulnerability, Technical and Data Security Assessments

Anyone can run a scanner. The value is in what happens next. We benchmark configurations against recognised baselines — CIS Benchmarks and Microsoft security baselines — so a finding is a measured deviation from a defensible standard, not a consultant's preference. Then we triage by exploitability and business context and, where it changes the decision, can quantify the exposure in dollars using FAIR. Because we assess once and report many, the same evidence feeds your Essential Eight, ISO 27001 and CIRMP reporting through our Governance, Risk and Compliance service.

Our approach
  • Authenticated and unauthenticated vulnerability scanning across infrastructure, endpoints and web applications using Nessus, Qualys and Microsoft Defender.
  • Triage combining CVSS severity, known exploitation and business context, not raw scanner scores, with a prioritised remediation plan and rescan evidence.
  • Technical assessments: Active Directory and Entra ID, cloud platform configurations (AWS, Azure, Google Cloud), OS builds (Windows, Linux) and EAP/network authentication, each against CIS Benchmarks and Microsoft security baselines.
  • Data security assessments: discovery and classification review, protection controls (encryption, key management, DLP, access control), lifecycle controls, and breach readiness supporting the 30-day Notifiable Data Breach obligation.
04

Threat and IoT Risk Assessment

Generic threat reports tell you what is happening to everyone. Our threat assessments tell you what is likely to happen to you. We map the threat actors and techniques relevant to your sector and footprint using MITRE ATT&CK, then test your controls against those specific techniques. We extend that lens to the estate most organisations can't even inventory: IoT and connected devices, from building management and physical security systems to medical and industrial devices.

Our approach
  • Threat actor identification and profiling relevant to your sector, geography and technology footprint, using MITRE ATT&CK to test controls against those specific techniques.
  • Device discovery and inventory across IoT and connected estates, including configuration, firmware currency, and default credentials.
  • Network segmentation review which discovers what a compromised device can reach, with a prioritised remediation and ownership model.
How do we deliver it?

Scope, test, quantify, retest

01

Scope

Scope the engagement around what an attacker would target and what a breach would cost, so you're testing the right thing, not the biggest thing.

02

Test

Run penetration testing, vulnerability, technical, data security, threat and IoT assessments with our own certified practitioners and vetted specialist partners.

03

Quantify

Translate findings into a risk profile where you know what fixing (or not fixing) something really impacts.

04

Retest

Confirm fixes actually worked, with retest evidence suitable for customers, auditors and insurers, not just a closed ticket.

Book a discovery

Book a discovery with our cyber team

Tell us what keeps you up at night and we'll tell you which assessment answers it — and which you don't need.

What tools and technology do we use?

The tools and methods behind the testing

Nessus, Qualys and Microsoft Defender for vulnerability scanning; CIS Benchmarks and Microsoft security baselines for technical assessments; the OWASP Testing Guide, OWASP SAMM, and MITRE ATT&CK for penetration testing and threat assessment methodology; SAST, DAST, software composition analysis and secrets detection tooling wired into CI/CD for application security. Findings are able to be quantified using FAIR, the same approach used across our Governance, Risk and Compliance service.

What outcomes can you expect?

What you walk away with

Understand exploitability, not just vulnerability. That is, what an attacker can actually do, chained end to end.
Meet customer, regulator and insurer expectations for independent testing.
One prioritised, costed remediation program instead of three competing spreadsheets of scanner output.
The same assessment evidence reused across Essential Eight, ISO 27001 and CIRMP obligations.
Proof · Case study

Security testing during an organisational transformation

How is this engagement structured?

We start with discovery to understand what your cyber resilience needs are, depending on drivers such as business complexity and sector. Contact us for a tailored quote.

FAQ

Common questions

Does Avocado deliver penetration testing in-house?

No — penetration testing is delivered by vetted specialist assurance partners under Avocado's management. Avocado handles threat-led scoping, quality assurance of findings, remediation planning, and retest — so you get specialist offensive depth with a single accountable partner.

How often should we run penetration testing?

Annually is the common baseline most compliance frameworks treat as the de facto standard, but frequency should track your rate of change, not just the calendar — a platform shipping weekly changes faster than an annual test can see. Many organisations rotate scope across the year instead of testing everything at once: external network one quarter, applications another, cloud infrastructure a third. A significant change (new systems, major releases, network topology changes) or a suspected incident should trigger a retest regardless of where you sit in the cycle.

What's the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment is tool-based scanning that identifies potential weaknesses at scale. A penetration test is a hands-on, specialist-led attempt to actually exploit weaknesses end to end. Most organisations need both, on different cadences.

Do you provide live incident response if a test reveals an active compromise?

No — Avocado does not offer live incident engagement, containment, or digital forensics. Testing and assurance are separate from incident response.

How does this connect to our compliance obligations?

The same assessment evidence — vulnerability, technical, and data security findings — can feed Essential Eight, ISO 27001, and CIRMP reporting through our Governance, Risk and Compliance service, rather than requiring a separate assessment for each.

Can this cover IoT and connected devices, not just IT systems?

Yes — Threat and IoT Risk Assessment specifically covers connected devices standard tooling misses, including building management, physical security, and medical or industrial devices.

Deliver with certainty

Get evidence your defences hold

Talk to our security testing and assurance specialists about which assessment answers your question (and what to fix first).