We'd rather show you the work than describe it.
An Australian non-bank lender financing vehicles and equipment through a national broker network. Its entire environment was on-premises, and the business needed a complete rebuild at very short notice, with no appetite for a phased migration.
We designed and built a new environment in Microsoft Azure from scratch and had the business operating in it within two weeks. That bought the room to do the real work: modernising the rest of the stack and, just as importantly, the way it gets run day to day. Identity, endpoint, security operations, the controls underneath all of it, and the documentation and process to hold the standard once we'd set it.
Nine months from the start of the rebuild, the lender achieved ISO 27001 certification. The first time in the company's history.
A 250-person Australian funds manager, reviewing its security as part of continuous improvement. A management mandate to adopt AI meant a wide range of AI tools were in use with little visibility of which, or what data they touched. Remote access ran on a legacy VPN, and the incumbent mail filter was quarantining legitimate business email.
A white-glove deployment of Netskope across company-owned devices: Secure Web Gateway with inline CASB and DLP to identify and secure AI tool use and web traffic, and Netskope Private Access to replace the legacy VPN with zero trust access to internal applications. Developer workflows tied to CI/CD were scoped separately so builds weren't disrupted. We also replaced the legacy mail filter with Abnormal.
Business-impacting email false positives cut by over 95%. AI tool use across the business is now quantified and governed, and the legacy VPN is gone for corporate users. All delivered in under three months.
A renewable energy generator with sites across every mainland state. Its infrastructure sat in a managed on-premises environment that couldn't move at the pace the portfolio was growing, and the operational technology behind generation needed separating from corporate IT to the standard critical infrastructure now demands.
We migrated the estate to VMware Cloud on AWS in under six months. Then we doubled the platform to carry a fully segmented OT network, designed in line with SOCI Act expectations for critical infrastructure. We manage the network connecting generation facilities across all mainland states.
Full migration in under six months. Platform capacity doubled to carry segmented OT. A national, multi-site network under management, at critical infrastructure standard.
A renewable energy generator with a Palo Alto Networks firewall at each generation site, managed through a single Panorama instance. The site firewall fleet was ageing, Panorama was struggling with the scale of work it was doing, and log retention of just under three months fell short of what the business needed.
We modernised internal and external firewalls across 12 sites in NSW, Victoria, Queensland, South Australia and Western Australia, replacing the ageing site fleet with current Palo Alto Networks hardware. We upgraded Panorama to handle centralised policy management and logging at the new scale, with retention extended to at least six months. We continue to manage the environment.
Twelve sites on current firewall hardware, managed and logged from one place. Better aligned to SOCI Act and AESCSF requirements, in line with industry best practice.
The same generator needed to meet its global parent's standard for privileged access management, across both corporate IT and the operational technology behind generation.
We designed and implemented CyberArk Privilege Cloud as a SaaS platform, storing, rotating and isolating credentials for people and service accounts alike. Privileged Session Manager covers both environments, with OT sessions designed to keep working without depending on cloud connectivity. Authentication runs through the group's global Microsoft Entra ID.
One privileged access platform across IT and OT, aligned to the group standard, without the overhead of running CyberArk on premises.
A national building products manufacturer with 350+ users across ten sites around Australia, supported by an internal team of four. Frontline support sat with an MSP and the SOC with a separate MSSP, so any change to security tooling touched three parties.
We deployed CrowdStrike Falcon across 470 servers and user devices using a three-stage policy rollout that kept production running, then replaced the incumbent endpoint protection and fed telemetry into the MSSP's SIEM. Falcon Identity Protection now watches Active Directory. Netskope secures internet use on and off the network and replaces the legacy VPN with zero trust access, and Abnormal protects email. We led the design with the MSP and MSSP at the table from the start.
A modern, largely automated security stack across the whole Australian estate, with the MSP, MSSP and internal team aligned on a single outcome that works for all of them.
The lender from our Azure story above had outgrown an inflexible, unresponsive legacy carrier. Internet access was contended and expensive, and there was no carrier-level redundancy.
We moved internet to Vocus (primary) and Superloop (secondary) links for 5 to 10 times the bandwidth, with Meraki cloud-managed high availability and a controlled cutover. Voice moved to Vocus Calling for Microsoft Teams, using carrier-managed SBCs and Teams Direct Routing. We manage the services ongoing.
Costs cut by over 80%, with zero service disruption at cutover. Faster links, carrier diversity and a more responsive partner.
An Australian fundraising platform relying on the limited filtering built into Microsoft 365, which was letting multiple potential threat emails through every week. As a platform that emails supporters on behalf of schools and community groups, deliverability matters as much as protection.
We implemented and manage email security that works alongside Microsoft Defender through direct API integration, with Exchange Online Protection tuned to Microsoft's recommended settings. We also optimised DMARC, DKIM and SPF across the platform's sending domains.
Email threats cut by over 95%, and deliverability at 99%+ every month since implementation.
A long-established Australian private debt firm operating across several states. The business needed its environment rebuilt, quickly, and then needed it run properly by a partner working alongside a small internal team rather than around them.
We rebuilt the environment in Microsoft Azure and had the business functional within two weeks. We now run cloud, network, telephony, backup, disaster recovery, email security and managed detection and response across every site, hand in hand with the internal team.
Multiple sites across several states, one accountable partner, and an internal team spending its time on the business rather than on infrastructure.
A long-running online youth mental-health service, building a risk-based information security management system to ISO 27001, aligned with the NIST Cybersecurity Framework and the Essential Eight, on a not-for-profit's budget.
We implemented JumpCloud for identity and device management, including a hardened standard operating environment, SSO, low-touch device deployment and OS patching. CrowdStrike Falcon protects every device, including against data leaving via USB, and Netskope provides web filtering and DLP wherever people work. We also built a new Ubiquiti UniFi network for their new city office, and provide ongoing IT support.
Significant progress toward ISO 27001, NIST CSF and Essential Eight, with identity, devices, web and the office network all run from a small number of cloud platforms.
A statutory fund with around 300 users was running a separate identity provider alongside Microsoft 365, which meant two places to manage identity and a login experience built around passwords.
We consolidated identity onto Microsoft Entra ID with a passwordless-first design: Windows Hello for Business biometrics as the primary sign-in, with Microsoft Authenticator push as the fallback. Applications moved across in planned waves, each with its own runbook, covering SAML, WS-Federation and SCIM integrations, and Conditional Access was redesigned for the new model.
Migration completed in under three months. One identity platform to run, and a faster, more secure sign-in for every user.
An energy company standing up new corporate offices in the Brisbane CBD, starting from a greenfield site.
We designed and deployed a modern, cloud-managed Ubiquiti LAN through the new headquarters, along with Microsoft Teams Rooms conferencing across six rooms for immersive meeting experiences.
Six Teams Rooms and a cloud-managed network, simple for a lean team to run from anywhere.
Rising Star, Deloitte Technology Fast50 Australia, 2024.
Tell us what's not working in your environment. We'll tell you what we'd do about it, or point you in the right direction.