
Banking
Tier-1 and mid-market bank cyber programmes. APRA CPS 234 capability uplift, ISMS, and the third-party assurance regulators ask for.
Protect · Cyber Security
Senior consultants with backgrounds at the firms that wrote the cyber security playbook for Australia's banks and regulators — now working with the mid-market businesses those firms used to charge enterprise rates. Adelaide-led, framework-anchored, board-defensible.

Framework Expertise
Why Mid-Market Enterprises Hire Us
Our principal consultants have run cyber practices at Big Four firms, held CISO roles at Australian banks, and advised boards and audit committees as independent directors. The frameworks, the playbooks, the regulator conversations — we've been on the other side of them.
We've moved into the mid-market for a reason. The enterprise and federation space is well-served by the major consulting firms and Tier-1 cyber providers. The mid-market — Australian businesses with 200 to 2,000 staff, often in regulated industries, often with cyber obligations they don't have the internal capability to address — is where the gap is widest. These are the businesses that need enterprise-grade cyber thinking but can't economically buy enterprise-rate consulting.
That's the gap we sit in. Senior consultants who know the frameworks because they helped operationalise them at the larger firms. A delivery model designed for mid-market budgets and timelines. Engagements that mid-market boards and audit committees can actually defend.
Cyber leadership and consulting at Tier-1 Australian banks
Independent advisory at Australian federations and member-led bodies
Senior consulting leadership in advisory and risk practices
Trusted advisor relationships at board and audit committee level
Across the team
Certified for certification readiness
Penetration testing, defence and incident response
Average tenure at principal consultant level
Industries We Protect
Our cyber security engagements cluster in eight industries — each with its own regulatory pressure, its own threat profile, and its own definition of "good enough". We work where the stakes are real.

Tier-1 and mid-market bank cyber programmes. APRA CPS 234 capability uplift, ISMS, and the third-party assurance regulators ask for.

General insurers, life insurers and brokerage groups navigating APRA-aligned cyber posture and third-party risk under CPG 234.

Scale-up fintechs needing enterprise-grade security architecture without the enterprise team. Pre-IPO readiness, AFSL-aligned controls, SOC 2 for US customers.

Australian MedTech firms — clinical device security, TGA-adjacent compliance, IP protection across global supply chain partners.

ASX-listed and family-held agribusinesses with operational technology exposure, supply chain risk, and the cyber footprint of precision agriculture.

Australia's growing space sector — satellite operators, ground stations, space-tech scale-ups. Sovereign capability protection and SOCI Act compliance.

Critical service providers where cyber resilience means operational continuity — aeromedical, emergency services, member-funded essential services.

Federations and large member-based organisations balancing constrained budgets, member-data sensitivity and corporate sponsor expectations.
Engagement specifics are confidential. We're happy to arrange a reference conversation during discovery for qualified prospects.
The Service Menu
Whether you need to know where you stand, prove your controls hold up, or run secure operations day to day — we deliver across all three. Most clients start with one and expand.
Framework-anchored assessment of your current posture, capability gaps and the roadmap your audit committee can actually defend.

Independent gap assessment against NIST CSF, ISO 27001, Essential 8, APRA CPS 234, PCI DSS, Privacy Act, SOCI Act.
Systematic posture evaluation, benchmarked, with a three-year strategic roadmap.
End-to-end ISMS implementation, policy, risk assessment, audit prep.
SABSA-based architecture, blueprint, control mapping, roadmap.
Framework, asset classification, treatment planning, quantification dashboard.
Vendor inventory, due diligence, control assessment, risk scoring.
Industrial control and operational technology security for defence, energy, water, space ground stations.
Pre/post-M&A due diligence, control harmonisation, integration.
Offensive testing and validation under realistic conditions. The audit committee gets a compliance document; we give you the proof.

OWASP, OSSTMM, CVSS-based testing across applications, networks and cloud.
Simulated targeted attack from an adversary's perspective.
Identify existing/past breaches, IOC hunting, scope, remediation.
Simulated incident scenarios to stress-test response plans.
Evaluate an existing SOC against benchmarks.
Ongoing managed services and operational defence — monitoring, hunting, responding and improving, at mid-market scale with enterprise-grade capability.

Co-Managed, Fully Managed, or AI-Enhanced models.
Managed, Hybrid, Platform-Based or Consultant-Driven CTI.
Log ingestion, enterprise-wide visibility, correlation.
Multi-layered controls, detection, training, backups, patching.
The Platform · FortSight
FortSight is our AI-native security platform — deployed and configured for clients who need continuous visibility, not point-in-time reports. Six integrated modules that turn your security data into board-ready intelligence, proactive defence and automated compliance. AI does the heavy lifting; your team makes the decisions.

A unified, AI-powered view of your security posture and risk landscape — built for the board, not just the SOC.
A virtual AI security advisor providing instant guidance and decision support — like a CISO on call, 24/7.
Adversarial AI threat intelligence mapped to the MITRE ATLAS framework — proactive defence against the threats aimed at you.
AI-driven attack simulation that tests your defences the way a real adversary would — continuously, at scale.
Transform complex cyber risk into quantified, dollar-denominated business insight your board and CFO can act on.
Automated governance, risk and compliance with AI-powered controls and real-time policy enforcement across every framework you answer to.
FortSight is deployed and configured to your environment — hosted in Australia, aligned to your frameworks, integrated with your existing security stack. We scope the right modules during a discovery call.
Deployment options include Australian-hosted, private cloud and on-premises configurations for data-residency-sensitive clients.
Related · AI Security Advisory
AI agents introduce new attack surfaces — prompt injection, over-privileged tool access, data exfiltration through model memory, identity sprawl. Our AI Security Advisory practice handles the AI-specific cyber work — model security, red-teaming for LLM applications, MLSecOps and AI governance.
HOW WE WORK
Engagement model designed for the boards, audit committees and risk functions that will read the deliverables.
01
Understand the business and the risk universe.
A 30–60 minute scoped session with executives and risk leaders. Threat landscape, regulatory obligations, target outcome. Free.
02
Baseline against the framework.
Framework-anchored evaluation. Gap report, control mapping, quantified residual risk.
03
A plan the audit committee can defend.
Prioritised, costed, sequenced remediation. Governance, capability uplift, reporting cadence.
04
Embedded delivery, not project-and-bounce.
Programme execution, managed services, board reporting, continuous improvement. Built for multi-year relationships.
ENGAGEMENT TIERS
Single, scoped engagement. 2 to 12 weeks. Fixed scope, fixed fee. The right entry point for businesses testing fit or addressing a specific obligation.
Typical: VAPT · Compromise Assessment · Table-Top · Compliance Assessment
Multi-phase programme. 3 to 12 months. Strategic deliverable with governance. The bulk of our engagements.
Typical: ISMS Advisory · Cyber Maturity · Risk Management · Enterprise Architecture · Red Team
Transformation or managed service. 12 months+, often multi-year. The deepest engagements.
Typical: Managed SOC · Threat Intelligence · Cyber Transformation · Ransomware Prevention
START HERE
30 minutes with a principal consultant. We listen to the obligation, the threat, the constraints — and tell you honestly whether we can help, and where to start if we can.
Active geographies
Australia · New Zealand
Cyber security delivery stays Australia + NZ-focused. Our consulting and AI practices extend across the broader Asia Pacific.
COMMON QUESTIONS
Most of our cyber engagements run for mid-market businesses of 200 to 2,000 staff, where regulated obligations and risk profile justify our depth. For smaller businesses we can run Starter-tier engagements (compromise assessments, penetration tests, table-tops) and we'll be direct during discovery about whether a fuller programme makes economic sense at your size.
Yes. Federations and member-funded organisations have a distinct cyber profile — distributed governance, member-data sensitivity, constrained budgets, rising expectations from corporate partners and grant funders. Several of our principal consultants have advised directly at this organisational level.
A Compliance Assessment answers "are we meeting this specific standard?" — typically ISO 27001, Essential 8, APRA CPS 234. A Cyber Maturity Assessment is broader — it evaluates posture and capability across the whole cyber function, benchmarked against maturity models, and produces a three-year roadmap. Most clients start with maturity, then layer compliance onto specific frameworks.
Yes. SOC 2 Type I and Type II readiness is a regular engagement — particularly for Australian fintechs, SaaS and MedTech firms selling into the US. We scope the trust services criteria that apply, identify control gaps, and run remediation up to and through the formal audit with a US-registered SOC 2 auditor.
Materially, yes. Australian Privacy Act, the Notifiable Data Breaches scheme, clinical system security, the Aged Care Quality Standards' information management expectations, and third-party risk flowing through your funders all converge on cyber as a board topic. We work with aged care providers, allied health groups and MedTech firms.
We're remote-first by default — most engagements run through video, secure document collaboration and structured working sessions. We attend on-site for kick-off, key workshops, board presentations and incident response when scope requires it. The mid-market efficiency depends on a remote-first model.
It depends on tier and scope. Starter engagements (VAPT, compromise assessments, table-tops, basic gap assessments) typically run in the low-to-mid five figures. Growth engagements (ISMS Advisory, full Cyber Maturity Assessment, Risk Management) run mid-five to low-six figures depending on complexity. Enterprise managed services and transformation work is quoted specifically. We quote precisely after a discovery call.