An endorsed IRAP assessor, engaged directly
Registered with the Australian Signals Directorate to independently assess the systems Australia depends on — and available to yours, without an account team in between.
Engage an Assessor
ASD-endorsed IRAP · ISM · Essential Eight · PSPF
We assess and secure mission-critical systems to the highest assurance standards set by the Australian Signals Directorate — for Defence, government, and the enterprises that support them.
Why Secure Blue
Registered with the Australian Signals Directorate to independently assess the systems Australia depends on — and available to yours, without an account team in between.
More than a decade of military cyber security engineering — from cutting-edge aviation systems to classified networks, capability authorisations and national cyber policy.
Security cleared and trusted in highly classified and sensitive environments, assuring the most critical Australian capabilities.
IRAP, demystified
The Infosec Registered Assessors Program is run by the Australian Signals Directorate. Endorsed assessors independently examine how well a system implements the Information Security Manual — then hand your decision-makers the evidence to authorise it with confidence. An assessor doesn't certify or accredit; they give you an expert, independent view you can act on.
Agree the system boundary, classification and the ISM controls in play — before a single control is examined.
Evidence, interviews and technical verification: are the controls implemented, and are they actually effective?
A security assessment report that states what stands up, what doesn't, and what to fix first — in plain language.
Your authorising officer makes the call — backed by independent evidence instead of self-assessment.
“Endorsed IRAP assessors assist in securing your systems and data by independently assessing your cyber security posture, identifying security risks and suggesting mitigation measures.”
— Australian Signals Directorate
The same assessment discipline works anywhere assurance matters: Essential Eight maturity reviews, cloud security assessments, supplier and supply-chain assurance, and independent security reviews for private organisations.
Read ASD's IRAP consumer guide ↗Capabilities
From scoping call to final report, your assessment is delivered end-to-end by the assessor you first spoke to — for systems at OFFICIAL through to classified environments.
Book an assessment scope callSecurity strategy, policy and governance built around the ISM, PSPF and Essential Eight — with ongoing advisory that keeps you aligned as the frameworks evolve, without hiring a full-time security executive.
TRAs and Security Risk Management Plans that tie cyber risk to mission risk — so investment decisions get made on evidence, and residual risk is owned deliberately rather than discovered later.
Essential Eight maturity evaluations, control validation and technical assurance that verify your safeguards work as documented — not just as intended. Findings arrive with fixes, not just severity ratings.
Secure-by-design AWS and Azure architectures, assessed and documented against the ISM's cloud controls and ACSC guidance — so your cloud uplift lands authorised, not stalled at assessment.
System Security Plans, SRMPs, incident response plans and architecture artefacts written to pass assessment the first time — by someone who has sat on the other side of the table and assessed hundreds of them.
A senior security partner on call — periodic posture reviews, roadmap ownership and board-ready reporting. The continuity of an in-house CISO, scaled to what your organisation actually needs.
Deliberately boutique
The big firms bring an account team. Secure Blue brings the principal — a senior Air Force cyber security engineering officer turned consultant, whose career runs from avionics software engineering on cutting-edge aviation systems, through building classified cyber capability, to leading the team that assessed and authorised hundreds of Defence networks.
That experience shaped national policy too: security controls and guidance developed through the Australian Cyber Security Centre for the ISM and Essential Eight, and strategic input into Australia's cyber security strategies for government and Defence.
Every engagement is scoped, delivered and stood behind by that same person. No juniors learning on your budget. No handoffs. Advice contextualised to your system, your threat environment and your mission.
Secure Blue on LinkedIn ↗Credentials
Every credential below is held personally by the principal consultant — not spread across a bench of juniors.
ASD-endorsedEducation & Training
Everyone gets trained here — boards and executives, engineers and operators, government and private, from a two-hour briefing to a full program. Designed and delivered by a qualified military instructor who has taught at the Air Force Officers' Training School and presented at Australia's major security conferences.
No off-the-shelf slide decks: every session is built around your systems, your threat profile and your people — in person in Canberra, or live online anywhere in Australia.
Software & Solutions
Custom security software built for automation and improvement — taking the manual drudgery out of compliance, evidence collection, reporting and security operations, using leading technologies shaped to how you actually work.
Not another generic platform: tooling custom-made for your environment and your frameworks — Australian government standards or your own — designed by someone who has lived inside the workflows it automates.
Start a software conversationWho we work with
Contact
An assessment, an uplift program, tailored training, a piece of software — or just a conversation about where to start. You'll be talking to the person who does the work.