Cyber Security Case Studies
& Validated Findings.

RTCS focuses on exploitable findings, clear evidence, and reports that security teams can reproduce. Where client or disclosure restrictions apply, we keep technical detail limited until it is safe to publish.

Real Findings, Real Targets

A sample of disclosed security research. Some engagement details are withheld for client confidentiality and responsible disclosure.

"Thank you for the great report. We were able to reproduce the issue on mobile devices ... and have validated this as a DOM-based cross-site scripting (XSS). We appreciate the effort you put into identifying this issue."

MTN Group Security Team - Report Validation
MTN Group logo
Bug Bounty - Telecommunications
MTN Group
DOM XSSTriaged & Validated2026
DOM-Based Cross-Site Scripting

The finding: A DOM-based cross-site scripting vulnerability in the web platform of MTN Group, one of the largest telecommunications groups in the world. The issue was exploitable through ordinary user interaction, with no developer tools or special access required.

The outcome: MTN Group's security team reproduced and validated the report, confirming it as a DOM-based XSS and triaging it for remediation. Full technical detail is withheld here until a fix is in place.

This is the standard behind RTCS: finding real, exploitable issues in the platforms of organisations that already have security teams.

Internal Penetration Test - Financial Services
ASX-Listed Financial Services Group
Active DirectoryDomain Admin Path2026
Standard User to Domain Admin in Four Days

The engagement: An assumed-breach internal penetration test simulating a phished workstation with a standard domain account. The brief was to determine how far an attacker could escalate before reaching the organisation's crown-jewel data stores.

The finding: A three-step attack path to Domain Admin within four working days, chaining credential material exposed on an open file share, Kerberoasting of a legacy service account, and abuse of unconstrained delegation on a forgotten member server. Once Domain Admin was reached, access to the primary financial data store was demonstrated end to end with no detection by the existing monitoring stack.

The outcome: All critical findings were remediated within 30 days. A 90-day retest confirmed full closure of the chain, and the underlying control gaps were rolled into the client's Essential Eight uplift roadmap. Client name withheld under NDA.

No zero-days, no exotic tooling. Just the attack paths every Australian enterprise should be testing for, before someone else finds them first.

"RTCS delivered exactly what they promised. The report was clear, the findings were ranked in a way that made remediation planning straightforward, and the team took the time to understand our environment before the engagement started. No jargon for the sake of it, no hand-waving. Practical, evidence-based work we could action straight away."

Boulevard Group - Engagement Feedback

Industries We Service

RTCS works with Australian organisations where the stakes are real, from regulated enterprises and government through to the small businesses that can't afford to get security wrong.

01
Government

Federal, state, and local agencies with Essential Eight, ISM, and PSPF obligations.

02
Critical Infrastructure

SOCI Act entities across utilities, water, and transport, including OT and ICS environments.

03
Energy & Resources

Mining, oil and gas, and energy operators securing both corporate and operational technology.

04
Financial Services

Banks, insurers, and fintechs under APRA CPS 234 and constant attacker attention.

05
Healthcare

Providers and networks protecting clinical systems and sensitive patient data.

06
Professional Services

Legal, accounting, and consulting firms holding highly confidential client information.

07
Technology & SaaS

Software and cloud businesses that need their products tested the way attackers test them.

08
Small & Medium Business

Growing Australian businesses that deserve real security without enterprise overhead.