About

An independent security practice, based in Sydney.

We work with Australian businesses that need security handled properly but cannot justify hiring for it, and with providers who need a specialist behind them on a particular job.

What we do

Three things, and they connect. We run managed security month to month: detection on your endpoints, monitoring across your domains and certificates, and posture work against the Essential Eight. We take project and contract work with a defined scope: assessments, incident response and digital forensics, cloud reviews. And we build and hold the web layer underneath, because that is where a great deal of small business risk actually lives.

A meaningful share of our work is subcontract. MSPs, IT providers and consultancies bring us in when a job needs a forensics specialist or simply another pair of hands, and we work under their brand.

We carry professional indemnity and cyber liability insurance, and can provide a certificate of currency for vendor onboarding.

How we work

Attacker mindset

We look for real paths to compromise, not checkbox compliance. What matters is what someone could actually do, not how many boxes are unticked.

Engineer grade reporting

Findings are written for the person who has to fix them: specific, reproducible, with remediation advice that names the actual change.

No lock in

We document as we go and hand it over. Knowledge transfer is part of the engagement, not an upsell.

Open by default

We build security tools and give them away, because better tooling raises the baseline for everyone.

Start with a conversation.

Tell us what you are trying to protect. If you do not need us yet, we will say so.

Book a scoping call →