Core Sentinel runs penetration testing engagements out of Governor Phillip Tower in Sydney, founded in 2015 by Steve McLaughlin, a tester holding OSCE, OSCP and CREST certifications who has worked with high-profile and multinational organisations. The firm operates on a senior-only, fixed-price model, meaning every engagement is carried out by a certified tester rather than passed to junior staff.
Testing scope covers web and mobile applications and APIs, external perimeter systems, internal networks and Active Directory environments, and on-site wireless infrastructure. Engagements also assess resilience against phishing, ransomware and broader social-engineering tactics, giving clients a picture of both technical exposure and human-layer risk. Alongside offensive testing, Core Sentinel produces compliance and governance reporting aligned to Essential Eight, ISO 27001 and ST4S requirements, with engagements structured to suit APRA CPS 234 obligations, IRAP alignment and SOCI readiness.
This combination of technical testing and framework-aligned reporting suits organisations that need penetration testing results mapped directly to regulatory or governance requirements rather than delivered as a standalone technical exercise. Internal network and Active Directory exploitation sits alongside external perimeter and application testing, so engagements can cover both the outward-facing attack surface and what happens once a foothold is gained internally. Wireless testing is conducted on-site, and social-engineering assessments extend the scope beyond infrastructure to staff behaviour under phishing and ransomware scenarios. The fixed-price, senior-only structure removes variability in who performs the work, with Steve McLaughlin's own certifications reflecting the standard applied across engagements.