The largest category: roughly 45 checks spanning reconnaissance, passive analysis, enumeration, injection, API testing, business-logic abuse, and both Nikto-style and Nuclei-style vulnerability scanning — run in phases, not as one flat checklist.
Platform · SentryLine
Automated penetration testing, on demand.
Real, automated scans against your actual attack surface — not a checklist audit. Structured, evidence-backed findings, CVE/CVSS-referenced, severity-rated and business-risk-framed, delivered as a full technical report. Run it before a client audit, after a major release, or on a schedule.
Port scanning and service enumeration via real nmap, SSH/SMB/SNMP enumeration, TLS configuration audit, and default-credential testing.
A dedicated wireless pentest agent — physical or virtual appliance — testing for WEP, WPS, rogue access points and weak passphrases, and capturing handshakes for offline analysis. Most competitors in this space don't offer it.
How a scan actually runs
Unauthenticated or authenticated
Supply credentials for a deeper, logged-in assessment, or run black-box.
Intensity is a real dial
From a fast, lighter-touch pass up to an aggressive mode that brings in additional external tools (Nuclei, subfinder, amass) alongside SentryLine's own engine — trade speed against depth deliberately.
Triggered three ways
On demand from the dashboard, on a recurring schedule, or launched from inside a CISO on Demand workspace via 'Launch SentryLine' and SSO hand-off.
Signed Authorization to Test, every scan
Real, current legal consent scoped to the specific targets and testing categories — not a one-time checkbox buried in onboarding. It's what makes 'automated' and 'lawful' true at the same time.
Live, not a black box
Scan progress streams to the dashboard in real time as it happens, not a 'come back later' spinner.
Turnaround
Scans complete automatically once launched — duration scales with scope and chosen intensity, not a fixed multi-day engagement window. Findings land in the dashboard, and in your CISO on Demand findings register, the moment the scan finishes.
We don't cry wolf.
Critical and High findings must clear real evidence — an out-of-band callback, an actual exploit run, or a proven gadget chain — before they're shown at that severity. Otherwise they're automatically downgraded. A Critical finding on your dashboard means we proved it, not guessed it.
Every finding, in plain English.
Any individual finding can be re-expressed without the jargon, so the person who has to approve the fix understands the risk as well as the person who found it.
SentryLine pricing
SentryLine is priced and bought separately from CISO on Demand advisory engagements — it's an automated platform capability, not a scoped human-led engagement. Tier detail is pending final confirmation and will be published here.
Ask us for current pricingNeed current evidence, not last year's report?
Talk to us about SentryLine — including how scan credits work inside a CISO on Demand subscription.
sales@cisoondemand.com.au