Skip to content
TYPE8

Cybersecurity & digital trust

Security maturity is not a score. It is a set of controls with owners, evidence and a tested failure path. We build the evidence, not the certificate theatre.

A$4.5BPROGRAMME · PENDING VERIFICATION · C-001

Launch model

Core advisory; partner deep operations

Boundary

Offensive operations and 24×7 SOC are partner-delivered, named on engagement.

Accountable principal

Sim Cuthbert

When to engage

Four observable triggers.

  • 01An Essential Eight or ISM assessment is overdue.
  • 02AI adoption has outrun the control environment.
  • 03Identity sprawl blocks a modernisation programme.
  • 04Supplier risk is tracked in a spreadsheet.

What we deliver

Modules, artefacts and ownership.

Client inputs, dependencies and the operating owner are agreed before the first sprint, not discovered during it.

  • Security strategy and architecture
  • GRC, Essential Eight and ISM mapping
  • Data and cloud security
  • Identity and access management
  • AI assurance and resilience testing

Proof

Programme intelligence for a national broadband rollout

A programme data platform with an explicit KPI contract, reconciled site status model, governed pipelines and an executive intelligence layer with alerting.

Delivered by our principal while at a national delivery organisation.

Read the full outcome

Risk and assurance

Security, privacy, AI assurance, accessibility, data quality and human oversight are tested as acceptance criteria on this practice — not appended as a closing report.

Standards
WCAG 2.2 AA, Essential Eight and ISM mapping where in scope.
Data residency
Australian by default; offshore processing named and approved in writing.
Support boundary
Offensive operations and 24×7 SOC are partner-delivered, named on engagement.
Response standard
Principal response within one business day, AWST.
Open the Trust Centre