Contact Us

Address: Surry Hills, Sydney NSW 2010

Hours: 9:00 - 17:30, Mon - Fri

Phone: 0409 771 748

Council staff reviewing a community services, infrastructure and cybersecurity dashboard, with a coastal town and town hall visible through the window.

Cybersecurity built for local government

Councils run more than most people realise - rates and property systems, records and document management, GIS, online services, and the water, sewerage and emergency systems a community depends on. We help you find and fix the gaps before someone else does, and we know the systems you actually run.

Book a security assessment
The risk for councils

A wide attack surface and a community that depends on it

A council holds ratepayer records, property and planning data, and the documents behind every decision - and it runs services people cannot do without. Attackers know the surface is large and often stretched thin. Ransomware can stop services for a whole region. Public portals leak information that was meant to stay internal. And the systems behind water, sewerage and emergency response were never meant to be reachable from the internet. When something goes wrong, you need answers fast.

What we work across

We understand how a council is put together

Council IT is its own world. We have tested the kinds of systems you rely on every day and understand how they connect - so testing is faster, sharper, and we are not learning on your time.

Ratepayer details, property records and planning data sit in portals that face the public. We test them for the flaws that let one resident read another's information, or reach records that were never meant to be public.

Councils hold a huge volume of documents, and the line between public and internal is easy to cross by accident. We check that internal drawings, correspondence and case files stay internal, and that public search does not hand over more than it should.

The systems behind water, sewerage and other essential services carry real-world consequences. We look at how they are exposed and how they connect to the corporate network, so an office breach cannot become an operational one.

Flood cameras, warning pages and disaster dashboards have to work on the worst day of the year. We test them for the weaknesses that would let someone take them down or feed the public bad information when it matters most.

Enquiry forms, request tracking, consultation portals and online payments are the front door to the council. We test them the way an attacker would, and check the third-party services behind them.

Email, remote access, staff accounts and the internal network are where a foothold turns into a full compromise. We test the corporate estate and your Microsoft 365 and Azure setup for the gaps that let an attacker move.
What we do for councils

Security work that fits how councils run

Penetration Testing

Internal and external testing of your network, plus web and mobile apps - your property, rates and online service portals - to find what an attacker would.

Microsoft 365 & Azure Reviews

Most councils run on Microsoft. We review your 365 and Azure setup for the misconfigurations that expose mailboxes, files and resident data.

Essential 8 Assessments

A clear, honest read on where you sit against the ACSC Essential 8 - and a practical plan to lift your maturity that your IT team can actually deliver.

Incident Response

If you have been breached, or think you have, we help you contain it, work out what happened, and keep services running. Calm, fast, no jargon.

Phishing & Staff Awareness

Realistic phishing and phone-based tests, plus training that sticks - so staff across the council become the layer that stops an attack, not the one that lets it in.

Dark Web & Breach Investigation

We check whether your council's data or staff credentials are already exposed online, and when something goes wrong we investigate what happened and how far it went.

Public vs internal

Keeping the internal side internal

A council is built to publish. Registers, maps, minutes and notices are meant to be open. But the same systems also hold internal correspondence, draft decisions, personal details and commercial documents that are not. The hard part is the line between the two, and it is easy to cross without noticing. We test where public access quietly reaches internal records, and help you draw that line where it should be.

The systems councils run

We know the ground you are standing on

We have worked across the system families a council depends on, so we start with an understanding of how they fit together and where they tend to go wrong.

Property, rates & planning systems

The public-facing portals that hold ratepayer and property records.

Records & document management

The document, drawing and correspondence registers behind every decision.

GIS & spatial data

Mapping and imagery services, and the data they expose.

Online services & payments

Enquiry, request, consultation and payment portals, and the services behind them.

Water, sewerage & emergency systems

The operational and public-safety systems a community cannot do without.

Corporate network, email & remote access

The internal estate, Microsoft 365, and the ways staff get in from outside.

Why councils choose Clearnet Labs

People who have done this before

We understand local government

We know how councils are built, the systems you run, and the difference between public and internal information. We speak your language and respect the community you serve.

Former law enforcement

Our team includes ex-law-enforcement investigators. When the stakes are high - a breach, a sensitive incident, a council that needs answers - that experience matters.

Plain-English reports

You get findings your IT team can act on and a summary your executive and councillors can read. No 200-page wall of noise.

Let's protect your council and your community

Book a no-pressure call. We will talk through where you are, what is worth doing first, and what it costs.

Book a call