Australia & New Zealand EdTech

    Penetration Testing for ST4S Assessment Evidence

    Independent manual testing for education technology suppliers that need clear, service-specific security evidence for Safer Technologies 4 Schools assessment preparation.

    Framework content reviewed against ST4S Supplier Guide 2026.1 on 12 September 2026.

    T1 testing cadence

    The current guide places penetration testing within a continuous monitoring plan and describes testing after a major change or at least annually.

    Its strongest response option includes external independent resources conducting the penetration test.

    EV10 report evidence

    The guide lists the most recent redacted penetration-testing report for the assessed service as EV10 evidence related to T1.

    The report must remain specific to the service and scope actually tested.

    Source: ST4S Supplier Guide 2026.1 . Requirements can change; confirm the current guide and assessment-team instructions before submission.

    Security scope for an education platform

    Scope is agreed around the product version, roles, integrations and infrastructure that need evidence. Testing is performed only with written authorization.

    Web applications used by students, teachers and administrators
    REST, GraphQL and other APIs that exchange education data
    Authentication, role boundaries and multi-tenant separation
    Mobile applications and their supporting APIs
    Cloud configuration and externally exposed infrastructure
    Business-logic paths that automated vulnerability scans may not exercise

    Evidence-ready deliverables

    Executive summary explaining material risk and testing scope
    Technical report with reproducible evidence and prioritized remediation
    A separately redacted report version when agreed for assessment evidence
    Remediation register that product and engineering teams can action
    Re-test results confirming whether agreed fixes address the reported issues

    Prior assessment-evidence experience

    CyberSecurityArm has delivered recurring penetration testing for an online education provider whose report was submitted during an ST4S assessment and accepted as supporting evidence.

    No confidential report or assessment content is reproduced, and this experience does not imply an ST4S endorsement of CyberSecurityArm.

    Public EdTech client feedback

    “We work with Florjan every year for our penetration and vulnerability testing.”

    Zenva Schools · 5.0 public Upwork feedback · July 2026

    This feedback verifies recurring EdTech security work; it is not presented as proof of the separate ST4S evidence statement above.

    View the public Upwork profile

    A controlled engagement from scope to re-test

    1

    Confirm the assessed service, version, roles, integrations, evidence needs and authorized boundaries.

    2

    Agree rules of engagement, safe testing windows, escalation contacts and sensitive-data handling.

    3

    Perform manual-led testing with targeted tooling and record reproducible evidence.

    4

    Deliver technical and executive reporting, then support remediation questions.

    5

    Re-test agreed fixes and issue an updated status without changing the original scope silently.

    Frequently asked questions

    Important assessment boundary

    CyberSecurityArm is an independent security-testing provider. It is not ST4S, Education Services Australia, NSIP or an education authority. A penetration test supports only part of the broader assessment and does not create or guarantee an ST4S outcome, endorsement, recommendation or product approval. CyberSecurityArm does not use or issue the ST4S Product Badge.

    Scope an ST4S evidence-focused penetration test

    Share the product type, approximate roles and integrations, target timing and assessment version. Do not include credentials or vulnerability details.

    Do not include passwords, API keys, vulnerability details or other sensitive system information.

    By submitting, you ask CyberSecurityArm to use this information to evaluate and respond to your request. See the Privacy Policy.