OSINT & Social Engineering · 3 Mar 2026 · 5 min read
Shadow IT Discovery: Finding the Systems Nobody Approved
Shadow IT, the SaaS, cloud and dev environments nobody approved, is a common source of breaches. Here's why it accumulates and how to find yours.
OSINT & Social Engineering · 17 Feb 2026 · 5 min read
Vishing and Smishing: Phone and SMS Attacks Explained
Vishing and smishing attacks target your help desk and MFA. How phone and SMS pretexts, MFA-reset abuse and MFA fatigue work, and how to harden your processes.
Pentesting · 27 Jan 2026 · 5 min read
Assumed Breach Testing Explained: What Happens After the Phish
Assumed breach testing shows what an attacker can do after the first phish lands. What it is, how it differs from external testing, and why it matters.
Pentesting · 6 Jan 2026 · 5 min read
Web Application Penetration Testing Methodology: A Full Guide
A practical web application penetration testing methodology: recon, authentication, access control, business logic, injection and reporting, step by step.
Pentesting · 16 Dec 2025 · 5 min read
GraphQL Security Testing: Common Vulnerabilities and How to Test
GraphQL security explained: introspection exposure, query depth abuse, batching attacks and field-level authorisation, plus how to test for each.
OSINT & Social Engineering · 25 Nov 2025 · 5 min read
Leaked Credentials: How to Check Exposure and Respond
Leaked credentials turn up in breaches, stealer logs, pastes and public repos. Here's how to check whether yours are exposed and what to do about it.
Government · 4 Nov 2025 · 5 min read
The Essential Eight Explained for Australian Organisations
The ACSC Essential Eight explained: the eight mitigation strategies, the four maturity levels, who must comply and how testing proves your controls work.
Pentesting · 14 Oct 2025 · 5 min read
Bug Bounty vs Penetration Testing: Which Do You Need?
Bug bounty vs penetration testing: what each is good at, where each falls short, and why mature security programs run both instead of choosing one.
Pentesting · 23 Sep 2025 · 5 min read
Red Team vs Penetration Test: What's the Difference?
Red team vs penetration test: how they differ in scope, goals, duration and cost, and how to work out which one your organisation should buy.
Pentesting · 2 Sep 2025 · 5 min read
Common AWS Security Misconfigurations That Cause Breaches
The AWS security misconfigurations that actually cause breaches: public S3 buckets, over-privileged IAM, exposed snapshots, metadata abuse and flat networks.
Put this into practice
A senior Ironbark Cyber consultant will scope your engagement on a free 30-minute call and give you a fixed quote within one business day.