NHMRC Penetration Testing
Tender Overview
About this tender
This Tender is invited by the Issuer. Purpose of arranging this pen testing exercise is Assess effectiveness of cyber controls Assess configuration of network and Wi-Fi Assess resilience of cloud infrastructure against external hacking attempts. Assets: Assets included in this exercise are: 1. External facing infrastructure Firewalls and network Azure Cloud tenancies NHMRC's technology stack includes Azure, Zscaler, Aruba Central, M365, and Virtual Desktop Interface (VDI - Azure Virtual Desktop) 2. Wi-Fi & network exercise Wi-Fi assessment from an adjacent attacker perspective on site Test lateral movement and compromise of standard Azure Virtual Desktop session or M365 credentials in network Out of Scope Social engineering and 3rd party systems Pentest Engagement Information: Identify the attack surface External infrastructure and asset discovery exercise Grey-box discovery exercise, starting with gaining understanding of NHMRC's infrastructure Discover additional information Gain unauthenticated access at services NHMRC have exposed, notably: Azure M365 Buyer contact: it.contracts@nhmrc.gov.au
How to respond to this tender
A strong tender response is clear, compliant, and backed by evidence. These steps apply to most Australian and New Zealand public tenders.
Read the requirements in full
Open the official listing and download the full tender pack. Note the response schedules, evaluation criteria, mandatory conditions, and the exact closing time and lodgement method.
Confirm you are eligible and it is worth bidding
Check licences, insurances, certifications, and any conformance requirements before you commit. A quick bid or no-bid decision saves days of wasted effort on a tender you cannot win.
Answer every criterion with evidence
Respond to each evaluation criterion directly and back your claims with concrete examples, referees, and past performance. Address the buyer’s stated need, not a generic capability statement.
Lodge early through the official portal
Submit through the source portal well before the deadline. Late or incorrectly lodged bids are almost always rejected, so leave time for uploads, portal errors, and last-minute questions.
