Real Findings, Real Targets
A sample of disclosed security research. Some engagement details are withheld for client confidentiality and responsible disclosure.
"Thank you for the great report. We were able to reproduce the issue on mobile devices ... and have validated this as a DOM-based cross-site scripting (XSS). We appreciate the effort you put into identifying this issue."

The finding: A DOM-based cross-site scripting vulnerability in the web platform of MTN Group, one of the largest telecommunications groups in the world. The issue was exploitable through ordinary user interaction, with no developer tools or special access required.
The outcome: MTN Group's security team reproduced and validated the report, confirming it as a DOM-based XSS and triaging it for remediation. Full technical detail is withheld here until a fix is in place.
This is the standard behind RTCS: finding real, exploitable issues in the platforms of organisations that already have security teams.
The engagement: An assumed-breach internal penetration test simulating a phished workstation with a standard domain account. The brief was to determine how far an attacker could escalate before reaching the organisation's crown-jewel data stores.
The finding: A three-step attack path to Domain Admin within four working days, chaining credential material exposed on an open file share, Kerberoasting of a legacy service account, and abuse of unconstrained delegation on a forgotten member server. Once Domain Admin was reached, access to the primary financial data store was demonstrated end to end with no detection by the existing monitoring stack.
The outcome: All critical findings were remediated within 30 days. A 90-day retest confirmed full closure of the chain, and the underlying control gaps were rolled into the client's Essential Eight uplift roadmap. Client name withheld under NDA.
No zero-days, no exotic tooling. Just the attack paths every Australian enterprise should be testing for, before someone else finds them first.
"RTCS delivered exactly what they promised. The report was clear, the findings were ranked in a way that made remediation planning straightforward, and the team took the time to understand our environment before the engagement started. No jargon for the sake of it, no hand-waving. Practical, evidence-based work we could action straight away."
Industries We Service
RTCS works with Australian organisations where the stakes are real, from regulated enterprises and government through to the small businesses that can't afford to get security wrong.
Federal, state, and local agencies with Essential Eight, ISM, and PSPF obligations.
SOCI Act entities across utilities, water, and transport, including OT and ICS environments.
Mining, oil and gas, and energy operators securing both corporate and operational technology.
Banks, insurers, and fintechs under APRA CPS 234 and constant attacker attention.
Providers and networks protecting clinical systems and sensitive patient data.
Legal, accounting, and consulting firms holding highly confidential client information.
Software and cloud businesses that need their products tested the way attackers test them.
Growing Australian businesses that deserve real security without enterprise overhead.