Get in touch

Cybersecurity services for Australian businesses

Cybersecurity services for Australian businesses

Serious cybersecurity incidents don’t stay contained in the IT department. They stop operations, trigger board notifications, and land in the press. The truly calamitous cases haunt brands for years.

These are the kind of examples that spur organisations into action. You’d be hard-pressed to find an Australian business that hasn’t invested in cybersecurity in some form.

But is it actually working? Most aren't sure. Not 100%. And that uncertainty is exactly what threat actors exploit.

Trust and resilience are two currencies Brennan measure cybersecurity worth in. Brennan is one of Australia's largest dedicated cybersecurity providers, with 300+ security specialists across consulting, engineering, and 24/7/365 Security Operations Centre (SOC) services.

We work with organisations in financial services, healthcare, government, utilities, and critical infrastructure: sectors where getting security wrong costs more than money.

Peter Soulsby
Director of Cyber Security & Government, Brennan

Cybersecurity incidents can erode trust, potentially affecting revenue and opportunities to generate new business. On the flipside, cybersecurity is an investment that will protect your operations, revenue and profit, as well as establish your brand as trusted and safe.”

Why the stakes are higher now

During FY24-25, the Australian Cyber Security Centre (ACSC) notified entities more than 1,700 times of potentially malicious cyber activity, an 83% increase on the year prior1. Volume is one problem. The nature of the threat is another.

AI has changed the attacker's toolkit. Phishing emails that once had obvious tells are now indistinguishable from legitimate correspondence. Attacks that required hours of manual effort now run at machine speed.

AI hits hardest at identity. Peter Soulsby, Brennan's Director of Cyber Security & Government, points to brute-force attacks on predictable passwords as the most underestimated AI-driven threat for mid-market organisations. AI works out the person's name from the username format, then runs through logical password combinations until something matches. What used to take a determined attacker weeks now runs in minutes.

Service accounts are the second weak point. Generic shared accounts (support@yourbusiness.com.au) often have passwords stored in plain text and lack the lifecycle management applied to individual user accounts. Once compromised, they become a foothold for lateral movement across the organisation.

There's also the legacy account problem. Credentials of former staff often remain valid 6 to 12 months after they left, and turn up in leaked credential databases years later.

AUD $4.26 million

 average data breach cost

IBM Cost of a Data Breach Report, August 2024

Business cybercrime

 costs surge by 50%

ASD Annual Cyber Threat Report, 2024-25

At the same time, the compliance environment is tightening. The Security of Critical Infrastructure (SOCI) Act now covers 11 sectors (energy, water, health, financial services, and data infrastructure among them) and mandates risk management programs, incident reporting, and government intervention powers.

APRA CPS 234 requires financial services organisations to maintain information security capability commensurate with their cyber risk. The Essential Eight Maturity Model, developed by the Australian Signals Directorate (ASD), has become the de facto security baseline for government, and an increasing number of private sector organisations are adopting it too.

For many CIOs and IT managers, the live question is whether they can demonstrate compliance; and whether compliance is translating into genuine security.

1: Source: Australian Signal Directorate, Annual Cyber Threat Report 2024-2025, Oct. 2025

What genuine cybersecurity looks like

Most organisations have some security in place. Antivirus. A firewall. Perhaps a managed detection tool. The problem is that point solutions applied to a threat environment that changes faster than they can track creates a false sense of security.

Each tool covers its own surface. The gaps between them are where breaches happen: the visibility blind spots, the unpatched systems, the overprivileged accounts.

Security is a discipline, built across four continuous stages.

Reducing the attack surface before threats materialise. This means hardening identity and access controls, managing privileged accounts, patching vulnerabilities on a defined schedule, and testing backup and recovery systems. The Essential Eight Maturity Model covers eight foundational controls at this layer, and for most organisations, reaching Maturity Level Two across all eight represents a meaningful security uplift from where they start.

Knowing when something is wrong, and how quickly. A Security Information and Event Management (SIEM) platform aggregates log data from across your environment and surfaces anomalies. A Security Operations Centre (SOC), staffed by analysts, acts on those signals around the clock.

The distinction, and correlation, is important. A SIEM without analyst coverage is a library few, if anyone, reads. Detection only has value when someone acts on it.

Brennan's SOC supports more than 50 organisations nationally, with continuous monitoring paired with Extended Detection and Response (XDR) across endpoint, network, and cloud environments.

What happens when something goes wrong. Incident response is about containing a breach, preserving evidence, communicating with stakeholders, and restoring operations as fast as possible. Speed matters: the longer an attacker has access, the greater the damage.

A tested incident response plan, and a partner with the experience to execute it, is the difference between a contained incident and a prolonged crisis.

Restoring operations and improving posture after an incident. This goes further than bringing systems back online. It includes forensic analysis of what happened, remediation of the exploited vulnerabilities, and a structured improvement programme so the same vector can't be used again. Recovery without improvement is an expensive reset.

The Essential Eight in practice

In June 2026, the Australian Signals Directorate announced it will retire the Essential Eight within two years. The replacement is a broader Essentials series with separate chapters for enterprise IT, operational technology, and cloud, built to handle shared-responsibility environments and SaaS architectures that the original framework wasn't designed for.

Deprecation begins around mid-2027. Until then, Essential Eight remains a live compliance requirement, and the ASD has confirmed that existing uplift work maps across.

Brennan's government practice is tracking the transition and advising clients on what the shift means for their security posture.

The Essential Eight Maturity Model is the Australian Signals Directorate's framework of eight priority security controls, each rated across four maturity levels (ML0 to ML3).

Initially developed for federal government agencies, it is now the most widely referenced security baseline in the country. For mid-market organisations, the practical questions are where to start and how far to go.

Peter Soulsby's read across Brennan customer engagements is consistent. Most arrive at ML0 to ML1 on initial assessment. The expectation gap between where leadership thinks the organisation sits and where it actually lands is wide.

ML0 to ML1 is the most expensive step. Most of the tooling spend lands here. So does the change management of locking down application control and Office macros, which is the point where users first encounter restrictions on what they can install or run.

ML1 to ML2 is mostly an operational uplift, with one notable exception: ML2 requires logging, which means investment in a SIEM and analyst coverage. ML3 sits at the edge of what most organisations can sustain. Patching critical vulnerabilities within 48 hours across a 1,000-server estate is hard, and it's a permanent operating commitment.

The Essential Eight is technical by design. Eight controls covering patching, application control, multi-factor authentication, privileged access, macro configuration, and backups.

It does not address process, people, or governance. Visitor registers, financial fraud controls, who is accountable for security inside the business: all sit outside the framework.

Brennan supports Essential Eight assessments and uplift across all eight controls and all four maturity levels. Where organisations have wider compliance obligations, we also work to the Information Security Manual (ISM) and the Protective Security Policy Framework (PSPF).

Peter Soulsby
Director of Cyber Security & Government, Brennan

Most customers arrive between ML0 and ML1 on initial assessment. There's an expectation gap between where they think they are and where the reality is.”

Sovereign security: compliance and operational fit

Sovereign security matters most where compliance demands it. For federal government agencies, the Information Security Manual (ISM) and Protective Security Policy Framework (PSPF) require Australian-hosted infrastructure, Australian-based analysts, and security-cleared personnel for engagements above PROTECTED. For organisations under APRA CPS 234, the SOCI Act, or the My Health Record framework, similar obligations apply across different sectors.

Beyond compliance, the case is operational. Peter Soulsby is direct on this: the commercial reasons for sovereignty are not sound. Offshoring SOC operations to a cheaper jurisdiction can deliver comparable service. The risks that matter are operational and cultural.

The first is lost-in-translation. A security analyst working in a second language, on a foreign network model, at 2am local time will move slower than one working in their first language on familiar systems.

The second is escalation. Some cultures hold strong hierarchical norms about who an analyst can contact directly. In a critical incident, whether an offshore analyst can call an Australian executive directly (or has to route through a chain of approvals) is the difference between a 30-minute response and a 6-hour one.

For organisations outside those compliance regimes, sovereignty is a judgment call. Where does the operational and cultural risk sit?

Brennan operates a sovereign SOC with Australian-based analysts, Australian-hosted infrastructure, and security-cleared personnel for engagements that require it. We support six federal government agencies and work with regulated organisations in health, finance, and critical infrastructure.

Peter Soulsby
Director of Cyber Security & Government, Brennan

In a critical incident, the question is whether the analyst on the call can reach the Australian executive directly. That's the difference between a 30-minute response and a six-hour one.”

What to look for in a cybersecurity partner

Most organisations have a cybersecurity partner of some kind. The more useful question is whether that partner matches the organisation's actual risk profile, and whether accountability is clearly defined in the contract and in practice.

Peter Soulsby's position on this is sharp. Risk doesn't transfer with the contract. A service provider delivers a service. The customer keeps the risk. Under Australian consumer law, it's the customer that gets taken down when something goes wrong. The provider's accountability is the SLA. The customer's accountability is the business outcome.

The implication is practical. Signing a contract and walking away is the failure mode Peter has seen repeatedly. The right approach is to stay close to the contracted service: regular contact with the provider, current playbooks, current escalation matrices, and contacts that match the organisation as it is now rather than as it was 18 months ago. "

The provider is the subject-matter expert on the service. The customer is the subject-matter expert on the business. Neither role transfers.

When evaluating a cybersecurity provider, ask:

Do they cover prevention as well as detection?

Many Managed Security Service Providers (MSSPs) focus on monitoring and alerting. Risk reduction upstream is the other half of the job.

Do they work to your specific compliance framework: Essential Eight, ISM, PSPF, APRA CPS 234?

Compliance requires monitoring tied to the obligation. Generic dashboards leave audit findings open.

How is accountability defined? In the contract, in practice, or left vague?

The contract should name response times, escalation paths, and remediation ownership. A provider who can't answer those questions precisely before you sign probably won't answer them after.

Is their SOC local?

Onshore analyst coverage matters for regulated environments and for response speed.

Do they have sector experience?

A partner with operational technology experience in your industry understands the legacy systems and the safety constraints. A generalist needs ramp-up time you may not have.

Brennan's cybersecurity practice has grown significantly over the past two years, with headcount up 4.5x, revenue up 5x, and operating profit up 6x.

Frequently asked questions

A managed cybersecurity provider should cover four core areas:

  • Consulting and advisory: security strategy, governance, risk and compliance, virtual CISO, Essential Eight uplift, penetration testing.
  • Engineering: security architecture, identity and access management, cloud security, network security.
  • Managed security: 24/7 SOC, SIEM, XDR, vulnerability management.
  • Incident response: containment, forensics, recovery, post-incident improvement.

Brennan provides all four. Services follow Australian government frameworks including the Essential Eight, ISM, and PSPF. ISO 27001 certification covers Brennan's own information security management practices.

The Essential Eight Maturity Model is a set of eight priority security controls developed by the Australian Signals Directorate (ASD). It protects against the most common cyber threats facing Australian organisations.

  • The eight controls:
  • Application control
  • Application patching
  • Configuring Microsoft Office macros
  • User application hardening
  • Restricting administrative privileges
  • Operating systems patching
  • Multi-factor authentication
  • Regular backups

Each control has four maturity levels (ML0 to ML3). Most organisations arrive at an Essential Eight assessment with gaps across several controls, particularly privileged access management, application control, and patching.

An uplift project starts with a current-state assessment across all eight controls. From there, a prioritised action plan with measurable milestones moves the organisation toward ML2.

Brennan supports assessment, gap analysis, and implementation across all eight controls and all four maturity levels, with experience across federal government and regulated private sector engagements.

A SIEM (Security Information and Event Management) platform aggregates and correlates log data from across your IT environment to surface potential threats. A SOC (Security Operations Centre) is the team of analysts who monitor that data and act on it, 24 hours a day, 7 days a week.

A SIEM without analyst coverage generates alerts no-one investigates. Brennan's SOC pairs SIEM data with continuous analyst coverage, XDR (Extended Detection and Response), and SOAR (Security Orchestration, Automation and Response). Analysts triage and contain threats around the clock.

A sovereign SOC is a Security Operations Centre with Australian-hosted infrastructure, Australian-based analysts, and (where required) security-cleared personnel.

For government agencies and regulated industries, sovereignty is a compliance requirement under the Information Security Manual (ISM) and Protective Security Policy Framework (PSPF). For commercial organisations, sovereignty means data stays within Australian jurisdiction and incident response runs on Australian time zones.

Brennan operates a sovereign SOC supporting federal government agencies and organisations in regulated sectors including health and financial services.

A penetration test identifies and exploits vulnerabilities within a defined scope: an external network, a web application, a wireless environment, or a cloud configuration. The output is a report listing what was found, how it was exploited, and how to remediate it.

A red team engagement tests detection and response capability under realistic attack conditions. The red team operates with limited prior knowledge, uses tactics modelled on real adversaries, and the engagement runs over weeks or months. The output measures how the organisation’s controls perform against active threats.

Brennan’s offensive security team runs both. Penetration tests cover external and internal networks, web applications, wireless environments, and cloud infrastructure. Red team engagements suit organisations with established detection capability that want to test how it performs under pressure.

he Information Security Registered Assessors Program (IRAP) is the Australian framework that certifies cybersecurity professionals to assess organisations against the Australian Government Information Security Manual (ISM). IRAP assessments are required for systems processing PROTECTED-level government information.

Providers that can deliver IRAP-assessed services employ IRAP-endorsed assessors and hold the security clearances their engagements require. Brennan supports IRAP assessments and works with federal government agencies and private sector organisations operating under the ISM and PSPF.

The Security of Critical Infrastructure (SOCI) Act covers 11 sectors of the Australian economy: communications, data storage and processing, defence industry, energy, financial services and markets, food and grocery, health care and medical, higher education and research, space technology, transport, and water and sewerage.

Organisations operating critical infrastructure assets in these sectors must:

  • Maintain a Critical Infrastructure Risk Management Program (CIRMP).
  • Report cyber security incidents to the Cyber and Infrastructure Security Centre (CISC).
  • Notify changes in operational control or ownership.

Brennan supports SOCI-regulated organisations with cybersecurity risk management programs and incident response planning.

Compliance frameworks differ by sector: healthcare under My Health Record, financial services under APRA CPS 234, government under the ISM and PSPF, and critical infrastructure under the SOCI Act.

Providers that work credibly across these sectors hold ISO 27001 and IRAP credentials and operate sovereign infrastructure for sensitive workloads.

Brennan supports organisations across all four. Sector experience spans federal government engagements through to regulated private sector deployments in health, finance, utilities, and mining.

A virtual Chief Information Security Officer (vCISO) provides strategic security leadership on a fractional basis. It suits organisations that need executive-level security guidance without the scale to justify a full-time CISO hire.

A vCISO covers security strategy, board-level reporting, risk framework design, compliance programme management, and executive advisory. Brennan's vCISO service supports mid-market organisations with growing compliance obligations and tight budgets.

For a managed SOC, the practical response benchmark is 30 minutes from the point of detection for high or critical severity incidents. Low and medium severity events are typically triaged in batches across the day rather than chased individually. Containment within the first hour is the operating standard for serious incidents.

The speed of response is one measure. The point in the attack lifecycle where a SOC intervenes is the more important one. Cyber incidents follow a long arc. The Lockheed Martin Cyber Kill Chain breaks an attack into seven stages: reconnaissance, weaponisation, delivery, exploitation, installation, command and control, and actions on objective. The breaches that make the news reached stage seven because the signals at stages one through six went unanswered.

Brennan's SOC operates against the 30-minute benchmark for high and critical events. For sustained or sophisticated attacks, analysts work the kill chain from earliest detection through to confirmed eradication, in coordination with the customer's internal team and external incident response provider.

Yes. Brennan holds ISO 27001 certification, which covers information security management practices across Brennan's own systems and the services delivered to customers.

ISO 27001 is one component of a layered standards approach. Brennan also aligns to the Essential Eight, ISM, and PSPF, applying controls across both Brennan-managed and customer-shared environments.

Explore our solutions

Advanced Networking
From business-grade internet to next-gen data security, unified connectivity expertise starts here.
Learn more
Cloud & Infrastructure
Engineer a future-proofed cloud strategy, without compromising on performance or security.
Learn more
Cybersecurity
Protection that is as continuous, comprehensive and uncompromising as the risks you face.
Learn more
Data and AI
Innovate, grow and gain market advantage by unlocking the true value of your data.
Learn more
Hardware & Software
Cost-effective and customer-first solutions grounded in expert advice.
Learn more
Microsoft Dynamics
Harness the full potential of the Microsoft toolset and master true productivity.
Learn more
Modern Workplace
Create unified, efficient and empowering environments designed to make work ‘work’.
Learn more
Service Desk
Continuously improving, highly systemised, world-leading customer support.
Learn more
chevron-downarrow-right