Menu
Proof

Ask our customers.

We'd rather show you the work than describe it.

01 — Case studies

Twelve engagements, delivered and run.

Non-bank lending
This is some text inside of a div block.
Professional services + managed services

A brand new Azure environment in two weeks. ISO 27001 nine months later.

Read the full story →
The situation

An Australian non-bank lender financing vehicles and equipment through a national broker network. Its entire environment was on-premises, and the business needed a complete rebuild at very short notice, with no appetite for a phased migration.

What we did

We designed and built a new environment in Microsoft Azure from scratch and had the business operating in it within two weeks. That bought the room to do the real work: modernising the rest of the stack and, just as importantly, the way it gets run day to day. Identity, endpoint, security operations, the controls underneath all of it, and the documentation and process to hold the standard once we'd set it.

The outcome

Nine months from the start of the rebuild, the lender achieved ISO 27001 certification. The first time in the company's history.

Funds management
This is some text inside of a div block.
Professional services

AI usage quantified, a legacy VPN retired, and 95% fewer false positives in email. In under three months.

Read the full story →
The situation

A 250-person Australian funds manager, reviewing its security as part of continuous improvement. A management mandate to adopt AI meant a wide range of AI tools were in use with little visibility of which, or what data they touched. Remote access ran on a legacy VPN, and the incumbent mail filter was quarantining legitimate business email.

What we did

A white-glove deployment of Netskope across company-owned devices: Secure Web Gateway with inline CASB and DLP to identify and secure AI tool use and web traffic, and Netskope Private Access to replace the legacy VPN with zero trust access to internal applications. Developer workflows tied to CI/CD were scoped separately so builds weren't disrupted. We also replaced the legacy mail filter with Abnormal.

The outcome

Business-impacting email false positives cut by over 95%. AI tool use across the business is now quantified and governed, and the legacy VPN is gone for corporate users. All delivered in under three months.

Renewable energy
This is some text inside of a div block.
Cloud migration + managed services

A national generation estate moved to VMware Cloud on AWS in under six months. Then doubled, to segment OT properly.

Read the full story →
The situation

A renewable energy generator with sites across every mainland state. Its infrastructure sat in a managed on-premises environment that couldn't move at the pace the portfolio was growing, and the operational technology behind generation needed separating from corporate IT to the standard critical infrastructure now demands.

What we did

We migrated the estate to VMware Cloud on AWS in under six months. Then we doubled the platform to carry a fully segmented OT network, designed in line with SOCI Act expectations for critical infrastructure. We manage the network connecting generation facilities across all mainland states.

The outcome

Full migration in under six months. Platform capacity doubled to carry segmented OT. A national, multi-site network under management, at critical infrastructure standard.

Renewable energy
This is some text inside of a div block.
Professional services + managed services

Firewalls renewed across 12 generation sites in five states, with management and logging rebuilt to match.

Read the full story →
The situation

A renewable energy generator with a Palo Alto Networks firewall at each generation site, managed through a single Panorama instance. The site firewall fleet was ageing, Panorama was struggling with the scale of work it was doing, and log retention of just under three months fell short of what the business needed.

What we did

We modernised internal and external firewalls across 12 sites in NSW, Victoria, Queensland, South Australia and Western Australia, replacing the ageing site fleet with current Palo Alto Networks hardware. We upgraded Panorama to handle centralised policy management and logging at the new scale, with retention extended to at least six months. We continue to manage the environment.

The outcome

Twelve sites on current firewall hardware, managed and logged from one place. Better aligned to SOCI Act and AESCSF requirements, in line with industry best practice.

Renewable energy
This is some text inside of a div block.
Professional services

Privileged access brought under control across IT and OT.

Read the full story →
The situation

The same generator needed to meet its global parent's standard for privileged access management, across both corporate IT and the operational technology behind generation.

What we did

We designed and implemented CyberArk Privilege Cloud as a SaaS platform, storing, rotating and isolating credentials for people and service accounts alike. Privileged Session Manager covers both environments, with OT sessions designed to keep working without depending on cloud connectivity. Authentication runs through the group's global Microsoft Entra ID.

The outcome

One privileged access platform across IT and OT, aligned to the group standard, without the overhead of running CyberArk on premises.

Manufacturing
This is some text inside of a div block.
Professional services

Enterprise-grade security operations for a four-person IT team.

Read the full story →
The situation

A national building products manufacturer with 350+ users across ten sites around Australia, supported by an internal team of four. Frontline support sat with an MSP and the SOC with a separate MSSP, so any change to security tooling touched three parties.

What we did

We deployed CrowdStrike Falcon across 470 servers and user devices using a three-stage policy rollout that kept production running, then replaced the incumbent endpoint protection and fed telemetry into the MSSP's SIEM. Falcon Identity Protection now watches Active Directory. Netskope secures internet use on and off the network and replaces the legacy VPN with zero trust access, and Abnormal protects email. We led the design with the MSP and MSSP at the table from the start.

The outcome

A modern, largely automated security stack across the whole Australian estate, with the MSP, MSSP and internal team aligned on a single outcome that works for all of them.

Non-bank lending
This is some text inside of a div block.
Professional services + managed services

Internet and voice off a legacy carrier with zero disruption, and costs down by more than 80%.

Read the full story →
The situation

The lender from our Azure story above had outgrown an inflexible, unresponsive legacy carrier. Internet access was contended and expensive, and there was no carrier-level redundancy.

What we did

We moved internet to Vocus (primary) and Superloop (secondary) links for 5 to 10 times the bandwidth, with Meraki cloud-managed high availability and a controlled cutover. Voice moved to Vocus Calling for Microsoft Teams, using carrier-managed SBCs and Teams Direct Routing. We manage the services ongoing.

The outcome

Costs cut by over 80%, with zero service disruption at cutover. Faster links, carrier diversity and a more responsive partner.

Fundraising platform
This is some text inside of a div block.
Professional services + managed services

Email threats down more than 95%, and 99%+ deliverability every month.

Read the full story →
The situation

An Australian fundraising platform relying on the limited filtering built into Microsoft 365, which was letting multiple potential threat emails through every week. As a platform that emails supporters on behalf of schools and community groups, deliverability matters as much as protection.

What we did

We implemented and manage email security that works alongside Microsoft Defender through direct API integration, with Exchange Online Protection tuned to Microsoft's recommended settings. We also optimised DMARC, DKIM and SPF across the platform's sending domains.

The outcome

Email threats cut by over 95%, and deliverability at 99%+ every month since implementation.

Private debt
This is some text inside of a div block.
Professional services + full managed services

Rebuilt in Azure in a fortnight. Now run end to end across multiple sites.

Read the full story →
The situation

A long-established Australian private debt firm operating across several states. The business needed its environment rebuilt, quickly, and then needed it run properly by a partner working alongside a small internal team rather than around them.

What we did

We rebuilt the environment in Microsoft Azure and had the business functional within two weeks. We now run cloud, network, telephony, backup, disaster recovery, email security and managed detection and response across every site, hand in hand with the internal team.

The outcome

Multiple sites across several states, one accountable partner, and an internal team spending its time on the business rather than on infrastructure.

For-purpose
This is some text inside of a div block.
Professional services + managed services

Security uplift toward ISO 27001 for a national youth mental-health service.

Read the full story →
The situation

A long-running online youth mental-health service, building a risk-based information security management system to ISO 27001, aligned with the NIST Cybersecurity Framework and the Essential Eight, on a not-for-profit's budget.

What we did

We implemented JumpCloud for identity and device management, including a hardened standard operating environment, SSO, low-touch device deployment and OS patching. CrowdStrike Falcon protects every device, including against data leaving via USB, and Netskope provides web filtering and DLP wherever people work. We also built a new Ubiquiti UniFi network for their new city office, and provide ongoing IT support.

The outcome

Significant progress toward ISO 27001, NIST CSF and Essential Eight, with identity, devices, web and the office network all run from a small number of cloud platforms.

Statutory fund
This is some text inside of a div block.
Professional services

One identity provider on Entra ID, and passwordless biometric login for 300 users, in under three months.

Read the full story →
The situation

A statutory fund with around 300 users was running a separate identity provider alongside Microsoft 365, which meant two places to manage identity and a login experience built around passwords.

What we did

We consolidated identity onto Microsoft Entra ID with a passwordless-first design: Windows Hello for Business biometrics as the primary sign-in, with Microsoft Authenticator push as the fallback. Applications moved across in planned waves, each with its own runbook, covering SAML, WS-Federation and SCIM integrations, and Conditional Access was redesigned for the new model.

The outcome

Migration completed in under three months. One identity platform to run, and a faster, more secure sign-in for every user.

Energy
This is some text inside of a div block.
Professional services

A new Brisbane head office, network and meeting rooms ready on day one.

Read the full story →
The situation

An energy company standing up new corporate offices in the Brisbane CBD, starting from a greenfield site.

What we did

We designed and deployed a modern, cloud-managed Ubiquiti LAN through the new headquarters, along with Microsoft Teams Rooms conferencing across six rooms for immersive meeting experiences.

The outcome

Six Teams Rooms and a cloud-managed network, simple for a lean team to run from anywhere.

02 — Partners

Certified across the stack we recommend.

We're a services business first. We've done the work to be genuinely good at these platforms, which is a different thing from purely reselling them.

Bring the intelligence to your technology.

Tell us what's not working in your environment. We'll tell you what we'd do about it, or point you in the right direction.

Chats are free, book one here