An Australian industrial business validated what an attacker could actually achieve, not just what a scanner could flag
The business is an Australian industrial business, supporting customers through specialist equipment, service and operational capability. For an industrial business, cyber risk is not theoretical: email, remote access, endpoints, business systems, vendor relationships, Microsoft 365, backup and network services all support daily operations. A vulnerability scan can identify known weaknesses, but it cannot always show whether those weaknesses can be exploited in the specific environment.
Inlight IT supported the business with engineer-led penetration testing to validate real-world exploitability across the agreed scope. The engagement used defined rules of engagement, controlled execution, proof-of-concept evidence, prioritised findings and remediation guidance. The outcome was clearer security evidence — what could be reached, what could be exploited, what needed remediation first and where the environment should be strengthened.
- Client
- Australian industrial business
- Industry
- Industrial
- Starting point
- A vulnerability scan can flag known weaknesses, but it cannot always show whether those weaknesses can be exploited in the specific environment
- Engagement type
- Engineer-led penetration testing to validate exploitable risk beyond automated vulnerability scanning
- Scope
- Scoped, authorised testing with rules of engagement, controlled execution and evidence-based reporting across agreed exposure areas
- Testing surfaces
- External and access-path testing, internal or assumed-compromise testing, and cloud and identity configuration review
- Outcome
- A practical view of what an attacker could actually achieve, with findings translated into remediation actions and security improvement priorities
An Australian industrial business — engineer-led penetration testing
Evidence of what an attacker could actually achieve, gathered across an agreed and authorised scope.
Evidence of exploitability, not a longer vulnerability list
Scope and rules of engagement, external and access-path testing, internal or assumed-compromise testing, cloud and identity review, and reporting built for remediation.
The external attack surface, realistic internal or assumed-compromise footholds, and Microsoft 365 and cloud identity configuration.
Each finding showed what was found, how it was proven, why it mattered and what should be fixed first.
A defined path to retest findings after remediation, so closure could be evidenced rather than assumed.
A penetration test is not a search for theoretical weakness — it is evidence of what can actually be exploited
The business operates in a practical industrial environment where technology supports customer response, business administration, operational coordination and access to systems.
The value of penetration testing in that environment is not a long vulnerability list. It is clarity — which weaknesses are exploitable, which ones are blocked by existing controls, which issues create a path to sensitive systems, which findings matter most because they affect access, identity, remote connectivity, business systems or backup.
Inlight IT's role was to test within agreed boundaries, document what was proven, translate findings into remediation actions and provide a clear path for closure and retesting.
The business needed exploitable-risk evidence, not another theoretical vulnerability report
Industrial businesses often have mixed environments — office users, operational systems, remote access, vendor tools, cloud services, local infrastructure and backup dependencies. A scan can flag possible weaknesses, but it does not always show how those weaknesses combine into a real attack path.
Industrial systems create mixed attack paths
An attacker does not usually move through a business in one clean step. Access can start through email, credentials, remote access, exposed services, weak configurations, cloud access or a compromised endpoint. Testing needed to consider how weaknesses could combine, not only whether individual vulnerabilities existed.
Automated scanning could not answer the real question
A vulnerability scan is useful, but it is not the same as a penetration test. A scanner may flag critical issues that are not exploitable in practice, and miss business logic weaknesses, chained misconfigurations and privilege escalation paths. The business needed evidence of what could actually be done in the environment.
Remote access and identity needed validation
Industrial and operational businesses often rely on remote access, supplier access, Microsoft 365, cloud services and shared systems. These access pathways can create risk if MFA, permissions, admin privileges or Conditional Access are not correctly implemented. Testing helped validate where the access model held and where it needed improvement.
Backup and recovery had to be considered through an attacker lens
Modern attacks frequently target backup systems and recovery paths. Internal or assumed-compromise testing can identify whether backup platforms, credentials or management systems are reachable from a compromised position — backup is only resilient if attackers cannot easily disable, alter or delete the recovery layer.
Findings needed to be usable by engineers
A penetration test only creates value if the findings can be remediated. The report needed to provide proof, impact, priority and remediation guidance that could be actioned through the managed IT and security operating model.
Engineer-led penetration testing with scoped execution, exploitability evidence and remediation guidance
Inlight IT structured the engagement around practical offensive testing disciplines — scope definition, rules of engagement, controlled testing, proof-of-concept evidence, risk-rated findings, remediation prioritisation and retest readiness.
01Scope and rules of engagement
Penetration testing needs clear authorisation, target boundaries and stop conditions. Target systems and environments were defined, in-scope and out-of-scope boundaries agreed, the testing window established, stop conditions documented, authorisation and escalation contacts confirmed, and production-safety considerations included.
02External and access-path testing
The engagement considered the systems most likely to be visible or reachable from outside the business, including internet-facing services and remote access pathways where included in scope, with evidence collected for exploitable findings.
03Internal or assumed-compromise testing
Modern attacks often begin with credentials, phishing or endpoint compromise. Internal or assumed-compromise testing helped show what an attacker could do from a realistic foothold, including whether backup and management platforms were reachable.
04Cloud and identity configuration review
For many businesses, Microsoft 365 and cloud identity have become the real control plane. Testing considered whether identity, permissions, MFA, admin roles and cloud configuration could be abused.
05Reporting, remediation and retest readiness
The output was designed for remediation, not filing. Each finding showed what was found, how it was proven, why it mattered and what should be fixed first, with a retest pathway available for closure evidence.
Five stages, from scoping to remediation evidence
Select a stage to trace how the engagement moved from authorised scope to closure evidence.
Australian organisations are under more cyber pressure, and evidence matters
Penetration testing is increasingly used to validate whether controls work in practice, especially where insurance, customer assurance or Essential Eight maturity conversations require independent evidence. The ASD Annual Cyber Threat Report 2024-25 shows that when serious incidents do occur, half of them involve compromise of network and infrastructure layers — which is precisely what penetration testing is designed to validate before an attacker does.
Cybersecurity incidents the Australian Cyber Security Centre responded to in FY2024-25 — an 11% increase from the previous year.
Proactive ACSC notifications to entities about potentially malicious cyber activity in FY2024-25 — an 83% increase year-on-year.
Of C3-and-above incidents involved compromised assets, networks or infrastructure. Categories may overlap.
Of C3-and-above incidents involved compromised accounts or credentials; 34% involved cyber attacks. Categories may overlap.
The business gained a clearer view of exploitable cyber risk across its industrial operating environment
The engagement gave the business more than a list of vulnerabilities. It produced evidence of practical exploitability, prioritised remediation and a clearer path to strengthen the environment through managed IT and cyber-first improvement.
Exploitability clarity
The business could distinguish theoretical risk from practical risk, with clearer evidence of which weaknesses represented practical exploitability and which should be prioritised first.
Findings were translated into action
The report provided remediation guidance that could be used by engineers to close issues rather than simply record them.
Testing informed access-control priorities
Access, identity and privilege findings could be linked back to Microsoft 365, Entra ID, remote access and administrative-control improvements.
Recovery considered from an attacker perspective
Where backup or management reachability formed part of the test scope, the engagement helped identify whether recovery dependencies needed stronger segmentation, access control or monitoring.
Evidence for assurance
The output could support insurance, customer assurance, Essential Eight maturity conversations and internal cyber improvement planning.
Remediation could be validated after fixes
The engagement created a path to retest findings after remediation so closure could be evidenced, not assumed.
The value was not a longer vulnerability list. It was clarity about which weaknesses were exploitable and what needed remediation first.
Testing scoped to the question that needed answering
Rules of engagement defined
Targets, exclusions, timing and stop conditions agreed before testing began.
Attack surface tested
Public-facing services and access pathways reviewed where included in scope.
Assumed-compromise risk considered
Internal exposure, privilege escalation and lateral movement paths considered where scoped.
Identity and Microsoft 365 reviewed
Cloud and identity configuration considered where included in scope.
Proof-of-concept findings provided
Findings supported by exploitability evidence and remediation guidance.
Closure pathway available
Retesting could confirm whether remediation had closed the findings.
The work connected offensive testing, identity validation and evidence-based remediation
Offensive testing
6- Penetration testing
- External network testing
- Internal network testing
- Assumed-compromise testing
- Privilege escalation testing
- Lateral movement review
Access and identity
6- Identity and access testing
- Remote access pathway testing
- MFA and Conditional Access testing
- Admin role exposure review
- Credential and session risk checks
- OAuth and consent risk review
Cloud and Microsoft 365
6- Microsoft 365 security review
- Cloud configuration review
- Entra ID access and privilege review
- Public service enumeration
- Exposed management interface checks
- Backup platform reachability
Evidence and remediation
6- Proof-of-concept evidence
- Risk rating and business impact
- Prioritised remediation plan
- Essential Eight mapping
- Retest pathway
- Rules of engagement and stop conditions
Need evidence of what an attacker could actually achieve?
Engineer-led testing that shows what an attacker could achieve and what to fix first.
Discuss your cyber security position