# Ironbark Cyber > Ironbark Cyber is an Australian AI security and penetration testing consultancy with two practices: AI Security & Assurance (LLM penetration testing, AI red teaming, agent security testing, ISO/IEC 42001 readiness, alignment with the Australian Government AI Technical Standard) and Offensive Security (penetration testing across web, API, network and cloud, social engineering, OSINT). Founded by Luke "hakluke" Stephens. A widely known bug bounty hunter and security researcher, author of open-source offensive tooling including hakrawler, featured by HackerOne on AI red teaming. Part of the Haksec group. Headquartered in Queensland, Australia; serves enterprise and government clients worldwide. Senior consultants do the work directly. The people who scope an engagement are the people who deliver it. Fixed-price quotes within one business day of a free scoping call, critical findings escalated live, findings ranked by real-world impact, and a free 90-day retest of fixed issues on every engagement. ## AI Security & Assurance - [AI Security & Assurance](https://ironbarkcyber.com/ai-security): Offensive testing and assurance for organisations building, buying or deploying AI. The lead practice, mapped to OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001 and the AU Government AI Technical Standard. - [LLM Penetration Testing](https://ironbarkcyber.com/llm-penetration-testing): Manual attack of LLM applications. Prompt injection, RAG data exfiltration, tool abuse, guardrail bypass and output handling, tested as one system. - [AI Red Teaming](https://ironbarkcyber.com/ai-red-teaming): Objective-driven adversarial campaigns against AI systems as deployed, including guardrails, monitoring and human oversight, structured around MITRE ATLAS. - [AI Agent Security Testing](https://ironbarkcyber.com/ai-agent-security-testing): Security testing for agentic systems. Tool and function abuse, excessive agency, memory poisoning, confused-deputy attacks and multi-agent trust boundaries. - [Secure AI Architecture Review](https://ironbarkcyber.com/secure-ai-architecture-review): Threat modelling and design review of AI stacks. Trust boundaries, data flows, tool permissions and tenant separation. Before mistakes get expensive. - [ISO 42001 Readiness](https://ironbarkcyber.com/iso-42001-readiness): Gap assessment, remediation roadmap and supporting technical testing for the certifiable AI management system standard. - [AI Governance & Assurance](https://ironbarkcyber.com/ai-governance-and-assurance): Alignment with the Australian Government AI Technical Standard, AI Impact Assessments, the NSW AI Assessment Framework and Queensland FAIRA. Backed by real testing. ## Offensive Security - [Penetration Testing](https://ironbarkcyber.com/penetration-testing): Manual, scope-tailored offensive testing across applications, networks, cloud and infrastructure. Typical engagements AU$6,000–18,000, fixed-price. - [Web Application Penetration Testing](https://ironbarkcyber.com/web-application-penetration-testing): Authentication, access control, business logic and the OWASP Top 10, tested by hand. Typically AU$8,000–18,000. - [API Penetration Testing](https://ironbarkcyber.com/api-penetration-testing): REST and GraphQL. BOLA/IDOR, broken authentication and business logic abuse. Typically AU$8,000–15,000. - [External Network Penetration Testing](https://ironbarkcyber.com/external-network-penetration-testing): Deep reconnaissance of the internet-facing attack surface followed by manual exploitation. Typically AU$6,000–12,000. - [Cloud Penetration Testing](https://ironbarkcyber.com/cloud-penetration-testing): AWS, Azure and GCP. IAM escalation paths, public exposure, assumed-breach scenarios. Typically AU$6,000–14,000. - [ISO 27001 Penetration Testing](https://ironbarkcyber.com/iso-27001-penetration-testing): Compliance-scoped testing with auditor-ready reporting; also satisfies SOC 2, PCI DSS and customer security reviews. Typically AU$8,000–16,000. - [Social Engineering](https://ironbarkcyber.com/social-engineering): Phishing, vishing, smishing and physical engagements, built to teach rather than embarrass. - [OSINT & Reconnaissance](https://ironbarkcyber.com/osint-and-reconnaissance): Executive exposure, supply chain risk, leaked credentials and threat actor profiling. - [Secure Development & AI Integrations](https://ironbarkcyber.com/development-and-ai-integrations): Security tooling, AI agents and automation built with a threat-model lens. ## Government - [Cyber and AI Security for Australian Government](https://ironbarkcyber.com/government): Essential Eight, ISM and PSPF-aligned testing, IRAP-readiness penetration testing and AI assurance for Commonwealth and state agencies. Australian-owned SME eligible for direct engagement under the Commonwealth Procurement Rules SME provisions (up to $500,000); also subcontracts sovereign delivery to primes. ## Compare - [AI Red Teaming vs Penetration Testing](https://ironbarkcyber.com/compare/ai-red-teaming-vs-penetration-testing): When to choose an objective-driven red team over a scoped pentest, with a comparison table. - [ISO 42001 vs NIST AI RMF](https://ironbarkcyber.com/compare/iso-42001-vs-nist-ai-rmf): The certifiable AI management standard versus the voluntary risk framework, and how they complement each other. - [Big Four vs Specialist AI Security Firm](https://ironbarkcyber.com/compare/big-four-vs-specialist-ai-security-firm): An honest comparison of large generalist consultancies and specialist firms for AI security work. - [Penetration Test vs Vulnerability Scan](https://ironbarkcyber.com/compare/penetration-test-vs-vulnerability-scan): Why a human-led pentest and an automated scan are different products at different prices. - [Bug Bounty vs Penetration Test](https://ironbarkcyber.com/compare/bug-bounty-vs-penetration-test): Continuous crowdsourced testing versus a scoped engagement, and the order to do them in. ## Resources - [Resources](https://ironbarkcyber.com/resources): Checklists, questionnaires and sample deliverables for security and AI assurance buyers. - [AI Security Assessment Checklist](https://ironbarkcyber.com/resources/ai-security-assessment-checklist): OWASP LLM Top 10 crosswalked to the Australian Government AI Technical Standard. - [Enterprise AI Vendor Security Questionnaire](https://ironbarkcyber.com/resources/enterprise-ai-vendor-security-questionnaire): The questions that matter when assessing AI vendors. - [Sample Penetration Test Report](https://ironbarkcyber.com/resources/sample-penetration-test-report): A redacted example of Ironbark Cyber's reporting standard. - [ISO 42001 Gap Checklist](https://ironbarkcyber.com/resources/iso-42001-gap-checklist): A self-assessment against the AI management system standard. - [Executive AI Security Briefing](https://ironbarkcyber.com/ai-security-briefing): A free 30-minute briefing for boards and executives on Australia's move toward AI regulation. ## Company - [About](https://ironbarkcyber.com/about): The firm, the founder, credentials and company facts. - [Contact](https://ironbarkcyber.com/contact): Book a scoping call or request a fixed quote. Answered within one business day. - [Blog](https://ironbarkcyber.com/blog): Research and field notes on AI security, penetration testing, OSINT and compliance. ## Facts - Founder: Luke Stephens (hakluke). Offensive security researcher, bug bounty hunter, creator of hakrawler and other open-source security tooling, featured by HackerOne on AI red teaming. - Headquarters: Queensland, Australia (Suite 214, 10 Albert Ave, Broadbeach QLD 4218). Clients worldwide. - ABN: 18 692 781 561. Australian owned and operated. Founded 2025. - Part of the Haksec group (https://haksec.io). Sister brand: Triagers (https://triagers.com). Outsourced vulnerability disclosure triage. - Delivery: senior consultants only; the people who scope the work do the work. Fixed-price quotes within one business day of a free 30-minute scoping call. Critical findings escalated live. Free 90-day retest of fixed issues. - Frameworks: OWASP Top 10 for LLM Applications, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, Australian Government AI Technical Standard, DTA Policy for responsible use of AI in government, NSW AI Assessment Framework, Queensland FAIRA, Essential Eight, ISM, PSPF.