Practice · Security
Cyber security services
Penetration testing, red teaming, digital forensics and incident response, vCISO services and governance across Essential Eight, ISO 27001 and SOC 2. The practice is led by our Chief Information Security Officer and serves regulated and commercial organisations across Australia.
The practice
Offensive, defensive and governance, together.
Most security firms do one of three things: test systems, respond to incidents, or write governance documents. Our practice does all three under one CISO-led team, which changes the quality of each. Testers who have worked incidents write findings that matter. Responders who know the compliance frameworks capture evidence that survives scrutiny. Governance written by practitioners describes controls that exist.
The practice serves clients directly and secures the systems our other practices build, from Dynamics 365 estates to cloud platforms and custom software.
What we deliver
Four lines of work.
OFFENSIVE
Penetration testing and red team
Our penetration testing services cover web application, API, mobile, cloud and network testing, scoped to what an attacker would actually target rather than what a template lists. Red team engagements test detection and response across people, process and technology.
Reports are written for two audiences: executives get risk in business terms, engineers get reproduction steps and remediation guidance they can action without a follow-up meeting. Retesting after remediation is included, not sold separately. Testing is delivered by our Sydney based team for clients across Australia.
RESPONSE
Digital forensics and incident response
Incident response for active compromises: containment, investigation, eradication and recovery, with forensic evidence handled so it holds up for insurers, regulators and, where needed, courts. The practice also runs readiness work, response plans, tabletop exercises and rehearsals, because an incident response plan that has never been rehearsed is a document, not a capability.
LEADERSHIP
vCISO
Security leadership as a service for organisations that need CISO-level judgement without a full-time hire: risk assessment, security roadmap, vendor and board reporting, and a standing point of accountability for security decisions. vCISO arrangements run on a retained basis and typically follow an initial assessment that establishes the baseline.
GOVERNANCE
GRC and compliance
Assessment and uplift against Essential Eight, ISO 27001 and SOC 2, run by practitioners who treat the frameworks as a floor rather than a finish line. The work covers gap assessment, control implementation, policy that matches practice, and audit preparation, with the aim that certification reflects an operating reality rather than a documentation exercise.
For organisations asked for an Essential Eight maturity level by an insurer, a customer or the board, our Essential Eight assessment rates every control on evidence and ends with a costed uplift plan.
Delivery
How engagements run.
Scoped against risk, not templates
Engagements start from what the organisation actually holds and who would want it. A pentest scope, an Essential Eight uplift or a response plan built from that starting point costs the same as a templated one and is worth considerably more.
Findings that get fixed
Every assessment ends with a prioritised remediation path, an offer to help deliver it, and retesting to confirm it worked. Where remediation needs engineering, our cloud and software practices do the work rather than leaving a report on the table.
Confidentiality as standard
Security work runs under strict confidentiality, with NDA, defined data handling and Australian-based storage of engagement material. Reports name what was found, not who found it easiest.
Perspectives and events
What the practice is watching.
EXECUTIVE BRIEFING · 27 OCTOBER 2026
How North Korean operatives are getting through legitimate hiring processes and into Australian software teams
Ben Jones, Cyber Security Practice Manager, with Dan Elliott, Field CISO at Recorded Future. How fabricated candidates pass AI-assisted interviews, the warning signs teams miss, and how fake recruiters target developers with malicious coding tests. Online, 12:00pm to 1:00pm AEDT. Attendees receive the Human Verification Checklist.
PERSPECTIVES ON CYBER RISK · 2026
The real cost of a data breach in Australia
Breach notifications at a record 1,205 in 2025, the first civil penalty under the Privacy Act, a statutory right to sue for privacy invasion, ransomware payments reportable within 72 hours, and AI in one in four malicious breaches. What a breach costs in 2026, where the money goes, and five decisions for the board.
Common questions
Security, answered plainly.
How often should we run a penetration test?
What do the Essential Eight maturity levels mean for us?
How long does ISO 27001 certification take?
We think we have an active incident. What happens first?
Is a vCISO enough, or do we need a full-time hire?
Do you test systems you also built?
Start here
Tell us what you need tested, or what has happened.
A pentest before a launch, an Essential Eight uplift, a compliance deadline, or an incident in progress. A practitioner replies within one business day.