Blog

Research and field notes on AI security, penetration testing and offensive security from the Ironbark Cyber team.

How to scope an AI red team engagement (and what it should cost in Australia)

How to scope an AI red team engagement (and what it should cost in Australia)

A practical guide to scoping an AI red team: choosing objectives, setting boundaries, and what a well-run engagement should cost an Australian organisation.

LLM penetration testing methodology: what we actually test

LLM penetration testing methodology: what we actually test

Inside Ironbark Cyber's LLM pentest methodology: the attack surface of a model-backed application, what gets tested, and why the checklist is the floor, not the method.

Australia's mandatory AI standards: what CISOs should do before 2027

Australia's mandatory AI standards: what CISOs should do before 2027

Australia has an Office of AI, its first mandatory AI standards flagged, and broader legislation expected in 2027. A pragmatic pre-compliance plan for CISOs.

ISO 42001 explained for Australian companies

ISO 42001 explained for Australian companies

ISO/IEC 42001 is the certifiable management-system standard for AI. What it covers, who is asking for it, and how Australian companies should approach certification.

The Australian Government AI Technical Standard: a security engineer's reading

The Australian Government AI Technical Standard: a security engineer's reading

The AI Technical Standard sets the Commonwealth's technical baseline for AI systems. What it actually asks for, read by someone who tests AI systems for a living.

Prompt injection in agentic systems: a field guide

Prompt injection in agentic systems: a field guide

When an LLM can take actions, prompt injection stops being a content problem and becomes an incident. A field guide to injection paths in agentic systems.

Essential Eight is being retired: what the ASD 'Essentials' series means for agencies

Essential Eight is being retired: what the ASD 'Essentials' series means for agencies

The ASD is evolving beyond the Essential Eight toward a broader "Essentials" series. What agencies should keep doing, stop doing, and start planning for.

How to buy penetration testing as a Commonwealth agency under the $500k SME exemption

How to buy penetration testing as a Commonwealth agency under the $500k SME exemption

The Commonwealth Procurement Rules let agencies engage SMEs directly for procurements up to $500,000. How to use that pathway to buy penetration testing well.

NSW Directive DCS-2025-04 and third-party risk: a practical checklist

NSW Directive DCS-2025-04 and third-party risk: a practical checklist

NSW Directive DCS-2025-04 requires agencies to get serious about third-party technology risk. A practical checklist for building the inventory and acting on it.

AI vendor security questionnaire: the 40 questions that matter

AI vendor security questionnaire: the 40 questions that matter

Most AI vendor questionnaires ask the wrong things. The 40 questions that actually reveal whether a vendor's AI product is safe to put in your environment.

Put this into practice

A senior Ironbark Cyber consultant will scope your engagement on a free 30-minute call and give you a fixed quote within one business day.