ASD-endorsed IRAP · ISM · Essential Eight · PSPF

Cyber security for
Australian Defence
and Government

We assess and secure mission-critical systems to the highest assurance standards set by the Australian Signals Directorate — for Defence, government, and the enterprises that support them.

Why Secure Blue

An endorsed IRAP assessor, engaged directly

Registered with the Australian Signals Directorate to independently assess the systems Australia depends on — and available to yours, without an account team in between.

Forged in Defence's hardest environments

More than a decade of military cyber security engineering — from cutting-edge aviation systems to classified networks, capability authorisations and national cyber policy.

Cleared and proven where it matters most

Security cleared and trusted in highly classified and sensitive environments, assuring the most critical Australian capabilities.

IRAP, demystified

What an IRAP assessor
actually does.

The Infosec Registered Assessors Program is run by the Australian Signals Directorate. Endorsed assessors independently examine how well a system implements the Information Security Manual — then hand your decision-makers the evidence to authorise it with confidence. An assessor doesn't certify or accredit; they give you an expert, independent view you can act on.

  1. 01

    Plan & scope

    Agree the system boundary, classification and the ISM controls in play — before a single control is examined.

  2. 02

    Assess

    Evidence, interviews and technical verification: are the controls implemented, and are they actually effective?

  3. 03

    Report

    A security assessment report that states what stands up, what doesn't, and what to fix first — in plain language.

  4. 04

    Authorise

    Your authorising officer makes the call — backed by independent evidence instead of self-assessment.

“Endorsed IRAP assessors assist in securing your systems and data by independently assessing your cyber security posture, identifying security risks and suggesting mitigation measures.”

— Australian Signals Directorate

Not just for government

The same assessment discipline works anywhere assurance matters: Essential Eight maturity reviews, cloud security assessments, supplier and supply-chain assurance, and independent security reviews for private organisations.

Read ASD's IRAP consumer guide ↗

Capabilities

Defence-grade rigour,
across the full assurance lifecycle.

IRAP Security Assessments

From scoping call to final report, your assessment is delivered end-to-end by the assessor you first spoke to — for systems at OFFICIAL through to classified environments.

Book an assessment scope call
  • New system authorisations
  • Reassessments & annual reviews
  • Cloud service assessments
  • Gap analysis before formal assessment
  • Remediation roadmaps that survive contact with ASD

Governance, Risk & Compliance

Security strategy, policy and governance built around the ISM, PSPF and Essential Eight — with ongoing advisory that keeps you aligned as the frameworks evolve, without hiring a full-time security executive.

Threat & Risk Assessment

TRAs and Security Risk Management Plans that tie cyber risk to mission risk — so investment decisions get made on evidence, and residual risk is owned deliberately rather than discovered later.

Security Testing & Assurance

Essential Eight maturity evaluations, control validation and technical assurance that verify your safeguards work as documented — not just as intended. Findings arrive with fixes, not just severity ratings.

Cloud Security & Compliance

Secure-by-design AWS and Azure architectures, assessed and documented against the ISM's cloud controls and ACSC guidance — so your cloud uplift lands authorised, not stalled at assessment.

Security Documentation & Architecture

System Security Plans, SRMPs, incident response plans and architecture artefacts written to pass assessment the first time — by someone who has sat on the other side of the table and assessed hundreds of them.

Advisory & Uplift Partnership

A senior security partner on call — periodic posture reviews, roadmap ownership and board-ready reporting. The continuity of an in-house CISO, scaled to what your organisation actually needs.

Deliberately boutique

The expert you meet is the expert who does the work.

The big firms bring an account team. Secure Blue brings the principal — a senior Air Force cyber security engineering officer turned consultant, whose career runs from avionics software engineering on cutting-edge aviation systems, through building classified cyber capability, to leading the team that assessed and authorised hundreds of Defence networks.

That experience shaped national policy too: security controls and guidance developed through the Australian Cyber Security Centre for the ISM and Essential Eight, and strategic input into Australia's cyber security strategies for government and Defence.

Every engagement is scoped, delivered and stood behind by that same person. No juniors learning on your budget. No handoffs. Advice contextualised to your system, your threat environment and your mission.

Secure Blue on LinkedIn ↗
  • 12+years in the Defence sector
  • 400+ICT systems in the assessment portfolio led
  • 18specialists led across audit & risk
  • 2national cyber strategies contributed to
  • Direct access One accountable senior assessor, start to finish
  • Security cleared Vetted for classified and sensitive environments
  • Assessor's eye Advice from someone who has assessed hundreds of systems
  • Canberra-based On-site across the ACT · online Australia-wide

Credentials

Certified across every discipline we practise.

Every credential below is held personally by the principal consultant — not spread across a bench of juniors.

IRAP — Infosec Registered Assessors Program ASD-endorsed
IRAP Assessor
  • CISSPISC2 — information security leadership
  • SABSAChartered Information Security Architect
  • GIAC ×5GCED · GCCC · GCIH · GSNA · GSDA
  • ISO 27001& ISO 9001 management-system auditor
  • M.CyberSecMasters — digital forensics
  • MBAMasters of Business Administration
  • B.Eng (Hons I)Electronics & communications
  • Clearedfor classified engagements

Education & Training

Training tailored for your organisation.

Everyone gets trained here — boards and executives, engineers and operators, government and private, from a two-hour briefing to a full program. Designed and delivered by a qualified military instructor who has taught at the Air Force Officers' Training School and presented at Australia's major security conferences.

No off-the-shelf slide decks: every session is built around your systems, your threat profile and your people — in person in Canberra, or live online anywhere in Australia.

  • Executive & board cyber-risk briefings
  • ISM, PSPF & Essential Eight practitioner training
  • Preparing your team for IRAP assessment
  • Secure-by-design workshops for engineering teams
  • Whole-of-organisation security awareness
Design a program

Software & Solutions

Security software, tailored to your environment.

Custom security software built for automation and improvement — taking the manual drudgery out of compliance, evidence collection, reporting and security operations, using leading technologies shaped to how you actually work.

Not another generic platform: tooling custom-made for your environment and your frameworks — Australian government standards or your own — designed by someone who has lived inside the workflows it automates.

Start a software conversation

Who we work with

Built for Defence.
Available beyond it.

Defence & National Security Our home ground — cyberworthiness, classified systems and capability assurance Specialty
Federal Government ISM, PSPF and authorisation support across the APS
Defence Industry DISP-aligned uplift for primes and SMEs in the supply chain
State & Local Government Pragmatic security uplift mapped to your obligations
Critical Infrastructure Assurance for operators with SOCI obligations
Enterprise & SMB Senior advice scaled to fit — without big-firm overhead

Contact

Engage a cyber
specialist directly.

An assessment, an uplift program, tailored training, a piece of software — or just a conversation about where to start. You'll be talking to the person who does the work.

Send a message

Sending opens your email client with the message pre-filled.