Our Services

Cybersecurity capability built for critical environments

OneGUARD® helps organisations build resilience, meet compliance obligations and maintain trust through 18 integrated specialist domains.

Comprehensive services

From governance to operational assurance

Our work spans strategy and compliance, hands-on technical assessment, secure engineering, classified-network support and specialist capability development.

Engagements are scoped to your mission, regulatory obligations, threat environment and internal capability—not a generic service catalogue.

18 specialist domains

Explore our capabilities

01Governance, Risk & ComplianceSecurity governance, risk management and assurance grounded in Australian regulatory and government frameworks.

Capabilities

  • Security strategy, operating models, ISM-aligned policy suites and board reporting
  • Risk assessments, threat and risk assessments, privacy impact assessments and risk registers
  • IRAP, Essential Eight, ISO 27001, APRA CPS 234, SOCI CIRMP and NIST CSF alignment

Representative outputs: Strategies and roadmaps, assessment reports, risk registers, compliance mappings, evidence packs and prioritised uplift plans.

Discuss this capability
02Security Architecture & EngineeringSecure architectures and engineering controls that connect strategic intent with practical implementation.

Capabilities

  • Enterprise, cloud, hybrid and Zero Trust architecture design and review
  • Secure configuration baselines, platform hardening and segmentation
  • DevSecOps, infrastructure-as-code, container and Kubernetes security reviews

Representative outputs: Reference architectures, security patterns, design reviews, hardening standards and implementation roadmaps.

Discuss this capability
03Identity & Access ManagementIdentity governance and privileged-access controls that support Zero Trust and Essential Eight outcomes.

Capabilities

  • Identity lifecycle, RBAC and ABAC design, access certification and service-account governance
  • MFA, phishing-resistant authentication, conditional access, SSO and federation
  • Privileged access discovery, PAM architecture, JIT/JEA and break-glass controls

Representative outputs: IAM strategies, access models, conditional-access policies, PAM designs and implementation plans.

Discuss this capability
04Endpoint, Application & Data SecurityProtection across endpoints, applications, information holdings and resilient backup arrangements.

Capabilities

  • Application control, patching, macro controls, user application hardening and endpoint baselines
  • Application, API and software-supply-chain security reviews
  • Data classification, encryption, key management, DLP and backup restoration validation

Representative outputs: Control designs, configuration standards, application findings, data-protection plans and backup assurance reports.

Discuss this capability
05Penetration Testing & Red Team ServicesObjective, intelligence-led testing of technical and human controls under authorised attack conditions.

Capabilities

  • External, internal, wireless, segmentation and Active Directory testing
  • OWASP-aligned web, API, mobile, authentication and business-logic testing
  • Social engineering, adversary simulation and MITRE ATT&CK-mapped red and purple teaming

Representative outputs: Executive and technical reports, reproducible evidence, risk-ranked findings and remediation validation.

Discuss this capability
06Network, OT & Critical Infrastructure SecurityAssessment and design for enterprise networks, operational technology and SOCI-regulated environments.

Capabilities

  • Network architecture, firewall rulebase, IDS/IPS, segmentation and secure remote-access reviews
  • OT/ICS assessment aligned to ISA/IEC 62443 and safe non-disruptive testing practices
  • IT/OT convergence, CIRMP cyber-hazard support and OT incident-response planning

Representative outputs: Architecture findings, segmentation designs, control-gap assessments, CIRMP inputs and treatment roadmaps.

Discuss this capability
07Vulnerability & Threat ManagementSustained exposure management informed by asset criticality, exploitability and relevant threat activity.

Capabilities

  • Vulnerability scanning, attack-surface review and configuration weakness assessment
  • CVSS, EPSS and mission-impact prioritisation aligned to Essential Eight patching timeframes
  • Threat landscapes, MITRE ATT&CK modelling, threat hunting and intelligence-program design

Representative outputs: Prioritised exposure registers, remediation plans, threat briefings and repeatable operating procedures.

Discuss this capability
08Security Operations & Incident ResponseDetection, monitoring and response capability designed to work with internal teams and service providers.

Capabilities

  • Monitoring strategy, SIEM architecture, log onboarding, detection engineering and alert tuning
  • Incident-response plans, playbooks, tabletop exercises and digital-forensics procedures
  • Ransomware readiness, crisis coordination and post-incident review

Representative outputs: Monitoring designs, detection use cases, incident playbooks, exercise reports and improvement plans.

Discuss this capability
09Business Resilience & RecoveryBusiness continuity and disaster recovery arrangements that protect critical services during disruption.

Capabilities

  • Business impact analysis, continuity planning and crisis-management frameworks
  • Recovery objectives, disaster-recovery planning and cloud recovery architecture
  • Exercises, restoration testing and Essential Eight-aligned backup assurance

Representative outputs: BIAs, BCPs, DR plans, exercise scenarios, test reports and remediation priorities.

Discuss this capability
10People, Training & Security AwarenessPractical programs that build professional capability and make secure behaviour part of normal operations.

Capabilities

  • IRAP Assessor, Essential Eight practitioner, ISM, PSPF and privileged-user training
  • Executive and board briefings, developer secure-coding training and role-based education
  • Awareness programs, phishing simulations and security-culture assessment

Representative outputs: Tailored courseware, exercises, capability assessments, training delivery and uplift recommendations.

Discuss this capability
11Third-Party & Supply Chain SecurityRisk-based assurance across suppliers, software dependencies and critical technology supply chains.

Capabilities

  • Supplier due diligence, risk tiering, contractual control review and ongoing monitoring
  • Software supply-chain assessment, SBOM and open-source dependency review
  • Critical supplier identification, hardware supply-chain risk and ownership-control support

Representative outputs: Supplier registers, assessment reports, contract recommendations and supply-chain treatment plans.

Discuss this capability
12Strategic Advisory & Virtual CISOSenior security leadership and transformation support available through flexible retained arrangements.

Capabilities

  • Security leadership, governance, investment planning and executive reporting
  • Regulatory engagement, risk acceptance support and incident command advice
  • Maturity assessment, multi-year transformation planning and cyber due diligence

Representative outputs: Board reporting, security plans, investment cases, transformation roadmaps and governance cadence.

Discuss this capability
13Classified Networks & Authority to OperateDesign, assessment and in-service assurance for protected and classified ICT environments, subject to scope and authorisation.

Capabilities

  • Secure architecture, classified network integration, data guards and cryptographic-system design
  • Security assessment, SSP and SRMP development, evidence packs and ATO support
  • Embedded security support, change assessment, artefact maintenance and annual reviews

Representative outputs: Architectures, security documentation, assessment evidence, authorisation packs and monitoring plans.

Discuss this capability
14CMMC 2.0 & Defence Supply Chain ReadinessReadiness and uplift support for Australian organisations handling US Defence information or pursuing DISP obligations.

Capabilities

  • CUI scoping, NIST SP 800-171 gap assessment, SSP review and SPRS-score support
  • CMMC control uplift, evidence preparation, mock assessment and POA&M management
  • DISP application support, obligations review and ongoing compliance preparation

Representative outputs: Readiness reports, scoped control plans, evidence indexes, POA&Ms and DISP uplift roadmaps.

Discuss this capability
15Security Test & EvaluationEngineering evaluation of hardware, firmware, software, sensors and operational technologies beyond conventional penetration testing.

Capabilities

  • Hardware interfaces, firmware, secure boot and trusted-platform evaluation
  • OT, ICS, IoT, industrial protocol and unmanned-system security assessment
  • Verification and validation, security acceptance testing, RF and sensor-security advisory

Representative outputs: Test plans, engineering findings, verification evidence, acceptance reports and remediation advice.

Discuss this capability
16Cyber Range, Simulation & WargamingRealistic environments and exercises for developing, testing and measuring operational cyber capability.

Capabilities

  • On-premises, cloud and hybrid cyber-range architecture and target-environment replication
  • Tabletop, functional, live-fire, red-versus-blue and purple-team exercises
  • SOC, incident response, threat hunting, adversary-emulation and OT training

Representative outputs: Range designs, exercise plans, injects, scoring models, delivery support and after-action reports.

Discuss this capability
17Electronic, Information & Space Warfare AdvisoryCybersecurity advice across converging electronic warfare, information operations and space-system domains.

Capabilities

  • Cyber–EW convergence, spectrum-dependent system risk and counter-UAS advisory
  • Information-operation threat assessment, OSINT exposure and resilience planning
  • Ground, link and space-segment security, GNSS/PNT resilience and incident planning

Representative outputs: Threat models, architecture reviews, exposure assessments, resilience plans and exercise support.

Discuss this capability
18Secure AI Architecture & AI GovernanceSecure adoption and governance of AI systems, informed by Australian guidance and the NIST AI RMF.

Capabilities

  • AI and LLM architecture review, prompt-injection and data-exfiltration assessment
  • AI supply-chain, platform, API, training-data sovereignty and access-control design
  • AI risk registers, acceptable-use standards, governance and incident-response planning

Representative outputs: AI risk assessments, secure architectures, governance frameworks, policies and red-team findings.

Discuss this capability

Our Process

A disciplined path from risk to assurance

  1. UnderstandLearn your environment, mission and risk profile.
  2. AssessIdentify exposure, gaps and obligations.
  3. AdviseSet defensible priorities and a practical roadmap.
  4. ImplementWork with your team to embed improvement.
  5. ValidateConfirm outcomes and ongoing effectiveness.

Frequently Asked Questions

What clients ask us

Do you only work with government clients?

No. Our foundations are in government and Defence, and we also work with critical infrastructure, financial services, health, technology and other enterprises seeking the same rigorous standards.

Are your assessments recognised under Australian frameworks?

Our work aligns with the PSPF, ISM and ACSC Essential Eight. IRAP assessments are delivered by appropriately endorsed assessors; recognition and authorisation remain subject to the applicable program and system owner.

Do you provide post-assessment support?

Yes. We can help prioritise findings, develop remediation roadmaps, support uplift activities and validate that agreed improvements have been implemented effectively.

What does an engagement look like?

We deliver defined assessments, structured uplift programs, retained advisory and scope-defined project work. Scope, evidence needs, timing and deliverables are confirmed in a Statement of Work after an initial consultation.

Can you support work connected to overseas requirements?

Yes. We support Australian organisations aligning with international standards and supply-chain requirements, including NIST and CMMC readiness. Formal certifications are performed only by the relevant authorised assessment body.

Ready to strengthen your security?

Talk with an experienced cybersecurity specialist.

Contact OneGUARD®