The risk for councils
A wide attack surface and a community that depends on it
A council holds ratepayer records, property and planning data, and the documents behind every decision - and it runs services people cannot do without. Attackers know the surface is large and often stretched thin. Ransomware can stop services for a whole region. Public portals leak information that was meant to stay internal. And the systems behind water, sewerage and emergency response were never meant to be reachable from the internet. When something goes wrong, you need answers fast.
What we work across
We understand how a council is put together
Council IT is its own world. We have tested the kinds of systems you rely on every day and understand how they connect - so testing is faster, sharper, and we are not learning on your time.
What we do for councils
Security work that fits how councils run
Penetration Testing
Internal and external testing of your network, plus web and mobile apps - your property, rates and online service portals - to find what an attacker would.
Microsoft 365 & Azure Reviews
Most councils run on Microsoft. We review your 365 and Azure setup for the misconfigurations that expose mailboxes, files and resident data.
Essential 8 Assessments
A clear, honest read on where you sit against the ACSC Essential 8 - and a practical plan to lift your maturity that your IT team can actually deliver.
Incident Response
If you have been breached, or think you have, we help you contain it, work out what happened, and keep services running. Calm, fast, no jargon.
Phishing & Staff Awareness
Realistic phishing and phone-based tests, plus training that sticks - so staff across the council become the layer that stops an attack, not the one that lets it in.
Dark Web & Breach Investigation
We check whether your council's data or staff credentials are already exposed online, and when something goes wrong we investigate what happened and how far it went.
Public vs internal
Keeping the internal side internal
A council is built to publish. Registers, maps, minutes and notices are meant to be open. But the same systems also hold internal correspondence, draft decisions, personal details and commercial documents that are not. The hard part is the line between the two, and it is easy to cross without noticing. We test where public access quietly reaches internal records, and help you draw that line where it should be.
The systems councils run
We know the ground you are standing on
We have worked across the system families a council depends on, so we start with an understanding of how they fit together and where they tend to go wrong.
Property, rates & planning systems
The public-facing portals that hold ratepayer and property records.
Records & document management
The document, drawing and correspondence registers behind every decision.
GIS & spatial data
Mapping and imagery services, and the data they expose.
Online services & payments
Enquiry, request, consultation and payment portals, and the services behind them.
Water, sewerage & emergency systems
The operational and public-safety systems a community cannot do without.
Corporate network, email & remote access
The internal estate, Microsoft 365, and the ways staff get in from outside.
Why councils choose Clearnet Labs
People who have done this before
We understand local government
We know how councils are built, the systems you run, and the difference between public and internal information. We speak your language and respect the community you serve.
Former law enforcement
Our team includes ex-law-enforcement investigators. When the stakes are high - a breach, a sensitive incident, a council that needs answers - that experience matters.
Plain-English reports
You get findings your IT team can act on and a summary your executive and councillors can read. No 200-page wall of noise.
Let's protect your council and your community
Book a no-pressure call. We will talk through where you are, what is worth doing first, and what it costs.
Book a call