Protect · Cyber Security

Protect. Cyber security built on enterprise foundations.

Senior consultants with backgrounds at the firms that wrote the cyber security playbook for Australia's banks and regulators — now working with the mid-market businesses those firms used to charge enterprise rates. Adelaide-led, framework-anchored, board-defensible.

Security operations centre with analyst workstations

Framework Expertise

  • NIST CSF
    2.0 · Tier 1–4
  • Essential 8
    ACSC ISM
  • ISO 27001:2022
    ISMS
  • APRA CPS 234
    Information Security
  • SOC 2
    Type I & II
  • PCI DSS
    v4.0
  • SABSA
    Architecture
  • MITRE ATT&CK
    Adversary Tactics

Why Mid-Market Enterprises Hire Us

Enterprise expertise. Mid-market focus.

Our principal consultants have run cyber practices at Big Four firms, held CISO roles at Australian banks, and advised boards and audit committees as independent directors. The frameworks, the playbooks, the regulator conversations — we've been on the other side of them.

We've moved into the mid-market for a reason. The enterprise and federation space is well-served by the major consulting firms and Tier-1 cyber providers. The mid-market — Australian businesses with 200 to 2,000 staff, often in regulated industries, often with cyber obligations they don't have the internal capability to address — is where the gap is widest. These are the businesses that need enterprise-grade cyber thinking but can't economically buy enterprise-rate consulting.

That's the gap we sit in. Senior consultants who know the frameworks because they helped operationalise them at the larger firms. A delivery model designed for mid-market budgets and timelines. Engagements that mid-market boards and audit committees can actually defend.

Banks

Cyber leadership and consulting at Tier-1 Australian banks

Federations

Independent advisory at Australian federations and member-led bodies

Big Four

Senior consulting leadership in advisory and risk practices

Boards

Trusted advisor relationships at board and audit committee level

CRISC, CISSP, CC

Across the team

ISO 27001 Lead Auditor

Certified for certification readiness

OSCP, Blue + Red

Penetration testing, defence and incident response

20+ yrs

Average tenure at principal consultant level

Industries We Protect

Cyber for the businesses Australia depends on.

Our cyber security engagements cluster in eight industries — each with its own regulatory pressure, its own threat profile, and its own definition of "good enough". We work where the stakes are real.

Architectural exterior of an Australian bank building.

Banking

Tier-1 and mid-market bank cyber programmes. APRA CPS 234 capability uplift, ISMS, and the third-party assurance regulators ask for.

APRA CPS 234ISO 27001
Australian insurance and financial services workplace.

Insurance

General insurers, life insurers and brokerage groups navigating APRA-aligned cyber posture and third-party risk under CPG 234.

APRA CPS 234ISO 27001
Modern fintech workplace with team and screens.

Fintech

Scale-up fintechs needing enterprise-grade security architecture without the enterprise team. Pre-IPO readiness, AFSL-aligned controls, SOC 2 for US customers.

SOC 2ISO 27001
Medical technology research environment.

MedTech

Australian MedTech firms — clinical device security, TGA-adjacent compliance, IP protection across global supply chain partners.

ISO 27001IEC 62304
Australian agribusiness operation.

Agribusiness

ASX-listed and family-held agribusinesses with operational technology exposure, supply chain risk, and the cyber footprint of precision agriculture.

SOCI ActICS/OT
Satellite ground station antenna.

Space Technology

Australia's growing space sector — satellite operators, ground stations, space-tech scale-ups. Sovereign capability protection and SOCI Act compliance.

SOCI ActAS 9100
Aeromedical service operation.

Aeromedical & Critical Services

Critical service providers where cyber resilience means operational continuity — aeromedical, emergency services, member-funded essential services.

SOCI ActISO 22301
Member organisation workplace.

Non-profit & Membership

Federations and large member-based organisations balancing constrained budgets, member-data sensitivity and corporate sponsor expectations.

Australian Privacy ActISO 27001

Engagement specifics are confidential. We're happy to arrange a reference conversation during discovery for qualified prospects.

The Service Menu

Three things buyers come to us for.

Whether you need to know where you stand, prove your controls hold up, or run secure operations day to day — we deliver across all three. Most clients start with one and expand.

01 · Assess & Plan

Know where you stand.

Framework-anchored assessment of your current posture, capability gaps and the roadmap your audit committee can actually defend.

Strategic planning workshop.

Compliance Assessment

Growth

Independent gap assessment against NIST CSF, ISO 27001, Essential 8, APRA CPS 234, PCI DSS, Privacy Act, SOCI Act.

2–4 months
NISTISO 27001Essential 8APRA

Cyber Maturity Assessment

Growth

Systematic posture evaluation, benchmarked, with a three-year strategic roadmap.

3–6 months
NISTISO 27001Essential 8

ISMS Advisory (ISO 27001)

Growth

End-to-end ISMS implementation, policy, risk assessment, audit prep.

6 months
ISO 27001:2022

Enterprise Security Architecture

Growth

SABSA-based architecture, blueprint, control mapping, roadmap.

3–6 months
SABSANIST

Cyber Risk Management

Growth

Framework, asset classification, treatment planning, quantification dashboard.

3–6 months
ISO 27005NIST RMFOpen FAIR

Third Party Risk Assessment

Growth

Vendor inventory, due diligence, control assessment, risk scoring.

3–6 months
SIGNISTVRMMM

ICS/OT Security Assurance

Enterprise

Industrial control and operational technology security for defence, energy, water, space ground stations.

6–12 months
IEC 62443NIST

Cyber Transformation (M&A)

Enterprise

Pre/post-M&A due diligence, control harmonisation, integration.

12–24 months
NISTISO 27001SABSA
02 · Test & Validate

Prove the controls hold.

Offensive testing and validation under realistic conditions. The audit committee gets a compliance document; we give you the proof.

Controlled security testing environment.

Vulnerability Assessment & Penetration Testing

Starter

OWASP, OSSTMM, CVSS-based testing across applications, networks and cloud.

2 weeks–3 months
OWASPOSSTMMCVSS

Red Team Exercise

Growth

Simulated targeted attack from an adversary's perspective.

1–3 months
MITRE ATT&CKCyber Kill Chain

Compromise Assessment

Starter

Identify existing/past breaches, IOC hunting, scope, remediation.

2–8 weeks
MITRE ATT&CKCyber Kill Chain

Table-Top Exercise

Starter

Simulated incident scenarios to stress-test response plans.

1–3 months
NISTMITRE ATT&CKISO 22301

SOC Maturity Assessment

Growth

Evaluate an existing SOC against benchmarks.

2–4 months
NISTMITRE ATT&CK
03 · Defend & Operate

Run secure operations every day.

Ongoing managed services and operational defence — monitoring, hunting, responding and improving, at mid-market scale with enterprise-grade capability.

Cyber operations centre.

Cyber-Security Operation Centre (C-SOC)

Enterprise

Co-Managed, Fully Managed, or AI-Enhanced models.

Ongoing
MITRE ATT&CKNIST

Cyber Threat Intelligence

Enterprise

Managed, Hybrid, Platform-Based or Consultant-Driven CTI.

Ongoing
MITRE ATT&CKSTIX/TAXII

Centralised AI-Enabled Data Lake

Enterprise

Log ingestion, enterprise-wide visibility, correlation.

20–24 months
AI-NativeMITRE ATT&CK

Ransomware Prevention Deployment

Enterprise

Multi-layered controls, detection, training, backups, patching.

6–12 months
NISTEssential 8

The Platform · FortSight

FortSight. See the threat before it lands.

FortSight is our AI-native security platform — deployed and configured for clients who need continuous visibility, not point-in-time reports. Six integrated modules that turn your security data into board-ready intelligence, proactive defence and automated compliance. AI does the heavy lifting; your team makes the decisions.

Executive security dashboard displaying real-time risk metrics

FortSight Dashboard

A unified, AI-powered view of your security posture and risk landscape — built for the board, not just the SOC.

  • Unified security posture visualisation across all environments
  • Real-time threat landscape monitoring and alerts
  • Executive-level KPI tracking and security metrics
  • Automated reporting for board presentations

FortSight Advisor

A virtual AI security advisor providing instant guidance and decision support — like a CISO on call, 24/7.

  • 24/7 AI-powered security advisory and decision support
  • Incident response guidance with automated playbook recommendations
  • Strategic security planning and roadmap development
  • Compliance status monitoring with proactive alerts

FortSight Threat Intelligence

Adversarial AI threat intelligence mapped to the MITRE ATLAS framework — proactive defence against the threats aimed at you.

  • Real-time threat feed integration from global sources
  • MITRE ATLAS alignment for adversarial AI threats
  • Behavioural pattern analysis for unknown threat detection
  • Predictive threat modelling by industry and geography

FortSight Red Team

AI-driven attack simulation that tests your defences the way a real adversary would — continuously, at scale.

  • Autonomous attack simulation using AI-driven adversarial tactics
  • MITRE ATT&CK framework mapping
  • Social engineering simulation with AI-generated phishing
  • Detailed attack reports with remediation prioritisation

FortSight Risk Quantification

Transform complex cyber risk into quantified, dollar-denominated business insight your board and CFO can act on.

  • Financial impact modelling for cyber risks
  • Monte Carlo simulation for risk probability
  • ROI analysis for security investments
  • Executive risk reporting with business-focused metrics

FortSight GRC

Automated governance, risk and compliance with AI-powered controls and real-time policy enforcement across every framework you answer to.

  • Automated compliance monitoring (ISO 27001, SOC 2, PCI DSS, GDPR, APRA CPS 234)
  • Real-time policy enforcement with AI rule validation
  • Automated evidence collection and audit trail generation
  • AI-powered gap analysis and remediation recommendations

FortSight is deployed and configured to your environment — hosted in Australia, aligned to your frameworks, integrated with your existing security stack. We scope the right modules during a discovery call.

Deployment options include Australian-hosted, private cloud and on-premises configurations for data-residency-sensitive clients.

Related · AI Security Advisory

Securing the AI you're about to build.

AI agents introduce new attack surfaces — prompt injection, over-privileged tool access, data exfiltration through model memory, identity sprawl. Our AI Security Advisory practice handles the AI-specific cyber work — model security, red-teaming for LLM applications, MLSecOps and AI governance.

Traditional CyberHybrid (Cloud, IAM, APIs)AI-SpecificModels · Agents · Prompts

HOW WE WORK

Four phases. Each one defensible.

Engagement model designed for the boards, audit committees and risk functions that will read the deliverables.

01

Discover

Understand the business and the risk universe.

A 30–60 minute scoped session with executives and risk leaders. Threat landscape, regulatory obligations, target outcome. Free.

02

Assess

Baseline against the framework.

Framework-anchored evaluation. Gap report, control mapping, quantified residual risk.

03

Roadmap

A plan the audit committee can defend.

Prioritised, costed, sequenced remediation. Governance, capability uplift, reporting cadence.

04

Operate

Embedded delivery, not project-and-bounce.

Programme execution, managed services, board reporting, continuous improvement. Built for multi-year relationships.

ENGAGEMENT TIERS

Three engagement scales.

Starter

Starter

Single, scoped engagement. 2 to 12 weeks. Fixed scope, fixed fee. The right entry point for businesses testing fit or addressing a specific obligation.

Typical: VAPT · Compromise Assessment · Table-Top · Compliance Assessment

Growth

Growth

Multi-phase programme. 3 to 12 months. Strategic deliverable with governance. The bulk of our engagements.

Typical: ISMS Advisory · Cyber Maturity · Risk Management · Enterprise Architecture · Red Team

Enterprise

Enterprise

Transformation or managed service. 12 months+, often multi-year. The deepest engagements.

Typical: Managed SOC · Threat Intelligence · Cyber Transformation · Ransomware Prevention

START HERE

One discovery call. Then a roadmap your board can defend.

30 minutes with a principal consultant. We listen to the obligation, the threat, the constraints — and tell you honestly whether we can help, and where to start if we can.

Active geographies

Australia · New Zealand

Cyber security delivery stays Australia + NZ-focused. Our consulting and AI practices extend across the broader Asia Pacific.

COMMON QUESTIONS

Before the discovery call.

We're under 200 staff — can you still help us?

Most of our cyber engagements run for mid-market businesses of 200 to 2,000 staff, where regulated obligations and risk profile justify our depth. For smaller businesses we can run Starter-tier engagements (compromise assessments, penetration tests, table-tops) and we'll be direct during discovery about whether a fuller programme makes economic sense at your size.

We're a federation or member-funded organisation — different cyber risk model. Do you understand that?

Yes. Federations and member-funded organisations have a distinct cyber profile — distributed governance, member-data sensitivity, constrained budgets, rising expectations from corporate partners and grant funders. Several of our principal consultants have advised directly at this organisational level.

What's the difference between a Cyber Maturity Assessment and a Compliance Assessment?

A Compliance Assessment answers "are we meeting this specific standard?" — typically ISO 27001, Essential 8, APRA CPS 234. A Cyber Maturity Assessment is broader — it evaluates posture and capability across the whole cyber function, benchmarked against maturity models, and produces a three-year roadmap. Most clients start with maturity, then layer compliance onto specific frameworks.

We're working towards SOC 2 for our US customers. Can you take us through it?

Yes. SOC 2 Type I and Type II readiness is a regular engagement — particularly for Australian fintechs, SaaS and MedTech firms selling into the US. We scope the trust services criteria that apply, identify control gaps, and run remediation up to and through the formal audit with a US-registered SOC 2 auditor.

We're an aged care provider or healthcare service. Does cyber really apply to us?

Materially, yes. Australian Privacy Act, the Notifiable Data Breaches scheme, clinical system security, the Aged Care Quality Standards' information management expectations, and third-party risk flowing through your funders all converge on cyber as a board topic. We work with aged care providers, allied health groups and MedTech firms.

How does your delivery model work for clients outside Adelaide?

We're remote-first by default — most engagements run through video, secure document collaboration and structured working sessions. We attend on-site for kick-off, key workshops, board presentations and incident response when scope requires it. The mid-market efficiency depends on a remote-first model.

What's the typical cost of a mid-market cyber engagement?

It depends on tier and scope. Starter engagements (VAPT, compromise assessments, table-tops, basic gap assessments) typically run in the low-to-mid five figures. Growth engagements (ISMS Advisory, full Cyber Maturity Assessment, Risk Management) run mid-five to low-six figures depending on complexity. Enterprise managed services and transformation work is quoted specifically. We quote precisely after a discovery call.