Pen testing · Public sector & education
Penetration Testing for Public Agencies & Crown Corporations
Privacy Horizon penetration testing shows a public body how its citizen portals, file-transfer services and network boundaries hold up against the attack patterns that actually hit Canadian government institutions. Testing is usually commissioned before a system goes to production under GO-ITS 25.0, after a peer incident like MOVEit raises board questions, or when an audit committee wants independent evidence rather than vendor assurances.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
The attack surface unique to agencies and Crown corps
A testing scope for this niche looks nothing like a private company's: public-facing program services, decades-old back ends and operational technology all connect to the same corporate core.
Citizen and account portals
Claims submission, licensing renewals, lottery and gaming accounts, utility self-service and fare systems expose authentication, session handling and business logic to anyone on the internet.
Managed file transfer services
MFT platforms move program data between institutions, vendors and ministries; the Nova Scotia MOVEit compromise proved a single such service can expose an entire jurisdiction's records.
Remote access and identity infrastructure
VPN concentrators, SSO and administrative access paths deserve adversarial attention, since Global Affairs Canada was penetrated through remote-access infrastructure run by its central provider.
The IT-to-OT boundary
For power, water and transit operators, we probe whether a foothold on the corporate network can reach SCADA and control environments, using methods that never jeopardize live operations.
Legacy internal systems
End-of-life servers and unpatched middleware, the condition the IPC documented at Toronto Public Library, are what ransomware operators traverse once a first foothold exists.
Regulatory map
Why regulators and directives expect agencies to test
In this niche, testing is not a best practice you elect into; central standards and privacy statutes make untested systems a compliance question.
GO-ITS 25.0 pre-production testing
Ontario's baseline security standard, which the Agencies and Appointments Directive expects provincial agencies to align with, calls for security testing before systems enter production alongside TRAs and centralized logging.
FIPPA's safeguards duty
Since July 2025, Ontario institutions owe statutory safeguards for personal information, and a current penetration test is among the clearest evidence that safeguards were verified rather than assumed.
Reasonable security under FOIPPA s. 30
BC's OIPC assesses Schedule 2 Crown corporations against what a reasonable operator would do; after the MOVEit findings in Nova Scotia, untested internet-facing services are hard to defend as reasonable.
Cyber Centre critical-infrastructure guidance
National threat assessments urge critical-infrastructure operators to validate defences against state-sponsored tradecraft, which is directly relevant to Crown utilities and transport bodies.
What goes wrong
Attack paths we emulate for public bodies
Scenarios are drawn from the documented incident record of Canadian government institutions, not generic threat libraries.
Exploitation of internet-facing services
We hunt for the vulnerable file-transfer endpoints, portal flaws and exposed management interfaces that let the MOVEit campaign lift SINs, banking and health-card data at scale.
Pivoting from shared infrastructure
Where a central provider hosts your systems, testing examines what an attacker inside that shared environment could reach in yours, the scenario that played out through an SSC-managed VPN in January 2024.
Ransomware traversal and persistence
Starting from an assumed phishing foothold, we measure how far an intruder can spread and how long they could dwell, the question Toronto Public Library could not answer for two months.
Reaching the control systems
For operators of OT, we evaluate segmentation, shared credentials and jump-host discipline between corporate and operational zones, since state actors probing provincial networks are looking for exactly that path.
Our pen testing for public agencies & crown corporations
What an agency penetration test includes
Our service pillars, applied to the systems and constraints of a board-governed public body.

Vulnerability exploration across the estate
Applications, networks and systems in scope are examined for exploitable weaknesses, from citizen portals and MFT services to internal segments and legacy platforms.
Response capability observation
We note whether your monitoring, logging and alerting saw us at all, giving a realistic read on detection before a real adversary provides one.
OT-aware scoping
Control-system boundaries are assessed with non-disruptive methods agreed in advance with operations leadership, so testing never threatens service delivery.
Defensive improvement guidance
Findings come with directional remediation advice ranked by exploitability and by the data or operations at stake.
Standards-linked reporting
Results are mapped to the expectations your body answers to, such as GO-ITS 25.0 controls or TBS instruments, in language an audit committee and ministry reviewer can use.
How the engagement runs
Running a test without disrupting public services
Public bodies cannot tolerate outages in services citizens depend on, so scoping discipline matters as much as technical depth.
Step 1
Scope and authorize
We define targets, windows and rules of engagement with your CIO and operations leads, and obtain written authorization covering any systems hosted by central or third-party providers.
Step 2
Test in controlled phases
External services first, then internal and boundary work, with change freezes and out-of-hours windows respected for anything touching production or OT-adjacent segments.
Step 3
Debrief while it matters
Critical findings are escalated immediately rather than held for the report, so a exploitable portal flaw is not sitting open during report-writing.
Step 4
Report for two audiences
Technical detail for your IT and vendors, plus an executive summary written for the board's audit and risk committee and, where useful, ministry oversight staff.
What it costs
What determines testing cost for a public body
Price follows scope: the number of internet-facing applications and portals, the size of internal network ranges, whether OT boundary work is included, retesting after remediation, and the constraints of testing around live public services. A single-portal tribunal engagement and a multi-site utility assessment are different undertakings, and procurement rules such as the OPS Procurement Directive can shape how the work is tendered.
We provide a fixed quote after a scoping call that inventories targets and windows, so the figure your business plan carries is the figure you pay.
Public Agencies & Crown Corporations: Pen testing questions, answered
Yes, and that pairing is the most common scope we see in this niche. Portal testing covers authentication, session management, access control and business logic on the services citizens use; MFT testing covers the transfer platform itself, its patch state, exposed interfaces and the credentials and automation around it. The Nova Scotia experience showed the file-transfer layer can be the softest route to program data, so we treat it as a first-class target rather than an afterthought.
If you operate power, water or transit infrastructure, the boundary belongs in scope even when the OT itself is handled cautiously. Most real-world control-system incidents begin on the corporate side, so we test whether IT footholds can reach operational zones, examine segmentation and jump hosts, and use passive or read-only techniques inside OT environments. Rules of engagement are set with operations leadership so nothing we do can affect service delivery.
The standard expects security testing before production release, supported by a threat and risk assessment, multi-factor authentication where sensitive processing is involved, and centralized logging. For an Ontario agency aligned to it through the Agencies and Appointments Directive, that means a new portal, case system or integration should carry test evidence before go-live. We time engagements to project schedules so the test is a gate the project passes, not a delay bolted on afterward.
Usually yes, with the right authorization. Testing systems run by Shared Services Canada, a provincial data centre or a commercial host requires their consent alongside yours, and cloud platforms have their own permitted-testing rules. We handle that coordination during scoping and, where direct testing is off the table, we assess your side of the shared-responsibility line: configurations, identities, integrations and what an intruder in the provider's environment could reach in yours.
The report is built for that use. Directors get a plain-language summary of what was attempted, what succeeded, what it means for the risks they oversee, and how remediation is sequenced. The technical annex gives your teams reproduction detail. Because findings are mapped to the standard your body answers to, the same document serves ministry oversight responses and demonstrates to a commissioner that safeguards are verified in practice.
Treat testing as tied to change and to your assurance calendar rather than a fixed ritual. New or materially modified internet-facing systems should be tested before production, consistent with GO-ITS 25.0. Beyond that, a recurring cycle aligned to your business-plan year keeps evidence current for the audit committee, and a retest after major remediation confirms fixes actually closed the paths we found.
More for public agencies & crown corporations
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.