Home / Case Studies / Penetration Testing
Case Study · Industrial · Penetration Testing

An Australian industrial business validated what an attacker could actually achieve, not just what a scanner could flag

The business is an Australian industrial business, supporting customers through specialist equipment, service and operational capability. For an industrial business, cyber risk is not theoretical: email, remote access, endpoints, business systems, vendor relationships, Microsoft 365, backup and network services all support daily operations. A vulnerability scan can identify known weaknesses, but it cannot always show whether those weaknesses can be exploited in the specific environment.

Inlight IT supported the business with engineer-led penetration testing to validate real-world exploitability across the agreed scope. The engagement used defined rules of engagement, controlled execution, proof-of-concept evidence, prioritised findings and remediation guidance. The outcome was clearer security evidence — what could be reached, what could be exploited, what needed remediation first and where the environment should be strengthened.

EXTERNALFOOTHOLDTARGET VALIDATED ATTACK PATH ENTRYFOOTHOLDPROOF INDUSTRIAL / PENETRATION TEST SCOPED / AUTHORISED / EVIDENCE-BASED
Engagement at a glance

An Australian industrial business — engineer-led penetration testing

Evidence of what an attacker could actually achieve, gathered across an agreed and authorised scope.

Client
Australian industrial business
Industry
Industrial
Starting point
A vulnerability scan can flag known weaknesses, but it cannot always show whether those weaknesses can be exploited in the specific environment
Engagement type
Engineer-led penetration testing to validate exploitable risk beyond automated vulnerability scanning
Scope
Scoped, authorised testing with rules of engagement, controlled execution and evidence-based reporting across agreed exposure areas
Testing surfaces
External and access-path testing, internal or assumed-compromise testing, and cloud and identity configuration review
Outcome
A practical view of what an attacker could actually achieve, with findings translated into remediation actions and security improvement priorities
Key project stats

Evidence of exploitability, not a longer vulnerability list

5
delivery disciplines

Scope and rules of engagement, external and access-path testing, internal or assumed-compromise testing, cloud and identity review, and reporting built for remediation.

3
testing surfaces

The external attack surface, realistic internal or assumed-compromise footholds, and Microsoft 365 and cloud identity configuration.

PoC
evidence per finding

Each finding showed what was found, how it was proven, why it mattered and what should be fixed first.

1
retest pathway

A defined path to retest findings after remediation, so closure could be evidenced rather than assumed.

Operating context

A penetration test is not a search for theoretical weakness — it is evidence of what can actually be exploited

The business operates in a practical industrial environment where technology supports customer response, business administration, operational coordination and access to systems.

The value of penetration testing in that environment is not a long vulnerability list. It is clarity — which weaknesses are exploitable, which ones are blocked by existing controls, which issues create a path to sensitive systems, which findings matter most because they affect access, identity, remote connectivity, business systems or backup.

Inlight IT's role was to test within agreed boundaries, document what was proven, translate findings into remediation actions and provide a clear path for closure and retesting.

Why this work mattered

The business needed exploitable-risk evidence, not another theoretical vulnerability report

Industrial businesses often have mixed environments — office users, operational systems, remote access, vendor tools, cloud services, local infrastructure and backup dependencies. A scan can flag possible weaknesses, but it does not always show how those weaknesses combine into a real attack path.

01

Industrial systems create mixed attack paths

An attacker does not usually move through a business in one clean step. Access can start through email, credentials, remote access, exposed services, weak configurations, cloud access or a compromised endpoint. Testing needed to consider how weaknesses could combine, not only whether individual vulnerabilities existed.

02

Automated scanning could not answer the real question

A vulnerability scan is useful, but it is not the same as a penetration test. A scanner may flag critical issues that are not exploitable in practice, and miss business logic weaknesses, chained misconfigurations and privilege escalation paths. The business needed evidence of what could actually be done in the environment.

03

Remote access and identity needed validation

Industrial and operational businesses often rely on remote access, supplier access, Microsoft 365, cloud services and shared systems. These access pathways can create risk if MFA, permissions, admin privileges or Conditional Access are not correctly implemented. Testing helped validate where the access model held and where it needed improvement.

04

Backup and recovery had to be considered through an attacker lens

Modern attacks frequently target backup systems and recovery paths. Internal or assumed-compromise testing can identify whether backup platforms, credentials or management systems are reachable from a compromised position — backup is only resilient if attackers cannot easily disable, alter or delete the recovery layer.

05

Findings needed to be usable by engineers

A penetration test only creates value if the findings can be remediated. The report needed to provide proof, impact, priority and remediation guidance that could be actioned through the managed IT and security operating model.

What Inlight IT delivered

Engineer-led penetration testing with scoped execution, exploitability evidence and remediation guidance

Inlight IT structured the engagement around practical offensive testing disciplines — scope definition, rules of engagement, controlled testing, proof-of-concept evidence, risk-rated findings, remediation prioritisation and retest readiness.

01

Scope and rules of engagement

Penetration testing needs clear authorisation, target boundaries and stop conditions. Target systems and environments were defined, in-scope and out-of-scope boundaries agreed, the testing window established, stop conditions documented, authorisation and escalation contacts confirmed, and production-safety considerations included.

Included
Defined target boundariesIn-scope and out-of-scope agreementTesting windowStop conditionsAuthorisation and escalation contactsProduction-safety considerations
02

External and access-path testing

The engagement considered the systems most likely to be visible or reachable from outside the business, including internet-facing services and remote access pathways where included in scope, with evidence collected for exploitable findings.

Included
External attack surface reviewPublic service enumerationRemote access pathway testingExposed management interface checksKnown vulnerability validationMisconfiguration testingEvidence collection
03

Internal or assumed-compromise testing

Modern attacks often begin with credentials, phishing or endpoint compromise. Internal or assumed-compromise testing helped show what an attacker could do from a realistic foothold, including whether backup and management platforms were reachable.

Included
Internal network exposure reviewPrivilege escalation testingLateral movement pathway reviewCredential and session risk checksShared service and file access reviewBackup platform reachabilityExploitable path evidence
04

Cloud and identity configuration review

For many businesses, Microsoft 365 and cloud identity have become the real control plane. Testing considered whether identity, permissions, MFA, admin roles and cloud configuration could be abused.

Included
Microsoft 365 configuration reviewEntra ID access and privilege reviewMFA and Conditional Access testingAdmin role exposure reviewCloud misconfiguration reviewOAuth and consent risk reviewPrivileged account risk review
05

Reporting, remediation and retest readiness

The output was designed for remediation, not filing. Each finding showed what was found, how it was proven, why it mattered and what should be fixed first, with a retest pathway available for closure evidence.

Included
Technical findings reportProof-of-concept evidenceRisk rating and business impactPrioritised remediation planEssential Eight mappingRetest pathway
Delivery approach

Five stages, from scoping to remediation evidence

Select a stage to trace how the engagement moved from authorised scope to closure evidence.

External threat signals

Australian organisations are under more cyber pressure, and evidence matters

Penetration testing is increasingly used to validate whether controls work in practice, especially where insurance, customer assurance or Essential Eight maturity conversations require independent evidence. The ASD Annual Cyber Threat Report 2024-25 shows that when serious incidents do occur, half of them involve compromise of network and infrastructure layers — which is precisely what penetration testing is designed to validate before an attacker does.

1,200+

Cybersecurity incidents the Australian Cyber Security Centre responded to in FY2024-25 — an 11% increase from the previous year.

1,700+

Proactive ACSC notifications to entities about potentially malicious cyber activity in FY2024-25 — an 83% increase year-on-year.

50%

Of C3-and-above incidents involved compromised assets, networks or infrastructure. Categories may overlap.

42%

Of C3-and-above incidents involved compromised accounts or credentials; 34% involved cyber attacks. Categories may overlap.

Australian Signals DirectorateASD Annual Cyber Threat Report 2024-25
What changed for the client

The business gained a clearer view of exploitable cyber risk across its industrial operating environment

The engagement gave the business more than a list of vulnerabilities. It produced evidence of practical exploitability, prioritised remediation and a clearer path to strengthen the environment through managed IT and cyber-first improvement.

O·01

Exploitability clarity

The business could distinguish theoretical risk from practical risk, with clearer evidence of which weaknesses represented practical exploitability and which should be prioritised first.

O·02

Findings were translated into action

The report provided remediation guidance that could be used by engineers to close issues rather than simply record them.

O·03

Testing informed access-control priorities

Access, identity and privilege findings could be linked back to Microsoft 365, Entra ID, remote access and administrative-control improvements.

O·04

Recovery considered from an attacker perspective

Where backup or management reachability formed part of the test scope, the engagement helped identify whether recovery dependencies needed stronger segmentation, access control or monitoring.

O·05

Evidence for assurance

The output could support insurance, customer assurance, Essential Eight maturity conversations and internal cyber improvement planning.

O·06

Remediation could be validated after fixes

The engagement created a path to retest findings after remediation so closure could be evidenced, not assumed.

Net position

The value was not a longer vulnerability list. It was clarity about which weaknesses were exploitable and what needed remediation first.

Project outcomes

Testing scoped to the question that needed answering

Outcome 01

Rules of engagement defined

Targets, exclusions, timing and stop conditions agreed before testing began.

Outcome 02

Attack surface tested

Public-facing services and access pathways reviewed where included in scope.

Outcome 03

Assumed-compromise risk considered

Internal exposure, privilege escalation and lateral movement paths considered where scoped.

Outcome 04

Identity and Microsoft 365 reviewed

Cloud and identity configuration considered where included in scope.

Outcome 05

Proof-of-concept findings provided

Findings supported by exploitability evidence and remediation guidance.

Outcome 06

Closure pathway available

Retesting could confirm whether remediation had closed the findings.

Technology and service scope

The work connected offensive testing, identity validation and evidence-based remediation

Offensive testing

6
  • Penetration testing
  • External network testing
  • Internal network testing
  • Assumed-compromise testing
  • Privilege escalation testing
  • Lateral movement review

Access and identity

6
  • Identity and access testing
  • Remote access pathway testing
  • MFA and Conditional Access testing
  • Admin role exposure review
  • Credential and session risk checks
  • OAuth and consent risk review

Cloud and Microsoft 365

6
  • Microsoft 365 security review
  • Cloud configuration review
  • Entra ID access and privilege review
  • Public service enumeration
  • Exposed management interface checks
  • Backup platform reachability

Evidence and remediation

6
  • Proof-of-concept evidence
  • Risk rating and business impact
  • Prioritised remediation plan
  • Essential Eight mapping
  • Retest pathway
  • Rules of engagement and stop conditions
Practical next step

Need evidence of what an attacker could actually achieve?

Engineer-led testing that shows what an attacker could achieve and what to fix first.

Discuss your cyber security position