Practice · Security
Cyber security services
Penetration testing, red teaming, digital forensics and incident response, vCISO services and governance across Essential Eight, ISO 27001 and SOC 2. The practice is led by our Chief Information Security Officer and serves regulated and commercial organisations across Australia.
The practice
Offensive, defensive and governance, together.
Most security firms do one of three things: test systems, respond to incidents, or write governance documents. Our practice does all three under one CISO-led team, which changes the quality of each. Testers who have worked incidents write findings that matter. Responders who know the compliance frameworks capture evidence that survives scrutiny. Governance written by practitioners describes controls that exist.
The practice serves clients directly and secures the systems our other practices build, from Dynamics 365 estates to cloud platforms and custom software.
What we deliver
Four lines of work.
OFFENSIVE
Penetration testing and red team
Web application, API, mobile, cloud and network penetration testing, scoped to what an attacker would actually target rather than what a template lists. Red team engagements test detection and response across people, process and technology.
Reports are written for two audiences: executives get risk in business terms, engineers get reproduction steps and remediation guidance they can action without a follow-up meeting. Retesting after remediation is included, not sold separately.
RESPONSE
Digital forensics and incident response
Incident response for active compromises: containment, investigation, eradication and recovery, with forensic evidence handled so it holds up for insurers, regulators and, where needed, courts. The practice also runs readiness work, response plans, tabletop exercises and rehearsals, because an incident response plan that has never been rehearsed is a document, not a capability.
LEADERSHIP
vCISO
Security leadership as a service for organisations that need CISO-level judgement without a full-time hire: risk assessment, security roadmap, vendor and board reporting, and a standing point of accountability for security decisions. vCISO arrangements run on a retained basis and typically follow an initial assessment that establishes the baseline.
GOVERNANCE
GRC and compliance
Assessment and uplift against Essential Eight, ISO 27001 and SOC 2, run by practitioners who treat the frameworks as a floor rather than a finish line. The work covers gap assessment, control implementation, policy that matches practice, and audit preparation, with the aim that certification reflects an operating reality rather than a documentation exercise.
Delivery
How engagements run.
Scoped against risk, not templates
Engagements start from what the organisation actually holds and who would want it. A pentest scope, an Essential Eight uplift or a response plan built from that starting point costs the same as a templated one and is worth considerably more.
Findings that get fixed
Every assessment ends with a prioritised remediation path, an offer to help deliver it, and retesting to confirm it worked. Where remediation needs engineering, our cloud and software practices do the work rather than leaving a report on the table.
Confidentiality as standard
Security work runs under strict confidentiality, with NDA, defined data handling and Australian-based storage of engagement material. Reports name what was found, not who found it easiest.
Common questions
Security, answered plainly.
How often should we run a penetration test?
What do the Essential Eight maturity levels mean for us?
How long does ISO 27001 certification take?
We think we have an active incident. What happens first?
Is a vCISO enough, or do we need a full-time hire?
Do you test systems you also built?
Start here
Tell us what you need tested, or what has happened.
A pentest before a launch, an Essential Eight uplift, a compliance deadline, or an incident in progress. A practitioner replies within one business day.