Cyber61, the Digital61 security practice

Sovereign security operations, run by people you can name

Cyber61 is our dedicated security business unit. We monitor, detect and respond around the clock from Australia, using the Microsoft security stack already licensed in most environments, and we produce the evidence your assessor, your insurer or your board will ask for.

Onshore. Cleared. IRAP assessed.
Trusted across Australian government and enterprise

A selection of the organisations our engineers deliver for.

Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client
01
Capability

What we deliver

Security is only worth what it changes. Every Cyber61 engagement is built to shorten the time between something happening and somebody competent acting on it, and to leave a record that proves it.

Continuous monitoring and response Round the clock detection and response from an Australian based team, with escalation paths agreed before an incident rather than improvised during one.
SIEM, SOAR and XDR, integrated Microsoft Sentinel, Defender XDR and automation built into one operating picture, so signals correlate instead of arriving as separate alerts in separate consoles.
Threat hunting and investigation Proactive hunting against current adversary tradecraft, with findings written up so a technical lead and a risk committee can both act on the same document.
Incident response support Containment, eradication and recovery run by responders who already know your environment, because in most cases we help operate it.
Attack surface and threat intelligence External exposure, vulnerability posture and dark web signals tracked continuously, ranked by what is actually reachable rather than by raw severity score.
Reporting and compliance evidence Dashboards and reporting mapped to the Essential Eight, the Information Security Manual and the Protective Security Policy Framework, produced as a by product of operating.
02
Clients

Who we work with

The controls are the same discipline either way. What changes is who has to be convinced and what evidence they accept.

Public sector
  • Who. Federal and state agencies, councils, statutory bodies, government owned corporations and critical infrastructure operators.
  • Drivers. Accreditation obligations, audit findings, SOCI and critical infrastructure duties, and ministerial exposure when an incident becomes public.
  • Evidence. Detections, response actions and posture mapped to the Information Security Manual, the Protective Security Policy Framework and the Essential Eight.
  • Sovereignty. Australian data residency, onshore delivery and AGSVA security cleared personnel to NV1 and NV2 where the environment requires it.
  • Procurement. Engagement through established government panels and arrangements, with IRAP assessed services and ISO 27001 certification behind them.
Private sector
  • Who. Australian mid market and enterprise organisations, usually at the point where the environment has outgrown how it is secured.
  • Drivers. Cyber insurance conditions, customer security questionnaires, a supply chain obligation, or a near miss that nobody wants repeated.
  • Evidence. The same control frameworks government relies on, translated into what an insurer, an enterprise customer or an acquirer will actually ask you to show.
  • Cost. Built on the Microsoft licensing you already hold wherever possible, so the spend goes into operating the capability rather than buying another console.
  • Continuity. Co-managed by design. Your people keep the context and the access, and we carry the hours nobody wants to roster.

Where you sit between the two, a government owned corporation, a defence supply chain participant or a regulated commercial operator, the mixed obligation set is familiar ground for us.

03
Method

How we engage

Security engagements start with a defined assessment, not an open ended retainer. You should know what you are buying and what you will hold at the end of it.

  1. FrameA working session to agree what you are protecting, what you are obliged to prove, and who signs off when something goes wrong.
  2. AssessDiscovery across identity, endpoint, cloud, network and existing telemetry, measured against the Essential Eight and the relevant control set.
  3. OnboardLog sources connected, detections tuned to your environment, playbooks and escalation paths agreed and tested before go live.
  4. OperateContinuous monitoring, hunting and response, with the backlog of posture improvements visible to both sides rather than held privately.
  5. ProveRegular reporting and evidence packs that satisfy an assessor, an insurer or a board without a scramble in the week they ask.
04
Services

Security services

Cyber61 runs four connected services. Most clients start with one and add the others as the obligations widen.

05
Assurance

Standards and assurance

Public sector clients need the evidence to get accredited. Private sector clients increasingly need the same evidence for insurers, customers and boards. We operate to one standard and produce the artefacts once.

  • FRAMEWORKACSC Essential Eight
  • FRAMEWORKInformation Security Manual
  • FRAMEWORKProtective Security Policy Framework
  • CERTIFICATIONISO/IEC 27001 certified
  • ASSESSMENTIRAP assessed
  • MEMBERSHIPDefence Industry Security Program
  • SOVEREIGNTYAustralian data sovereignty
  • PERSONNELSecurity cleared personnel
  • DELIVERYOnshore delivery and support

Our heritage is Federal Government and critical national infrastructure. That is why the same operating model holds up when a commercial client is asked, at short notice, to show a regulator or a customer how their environment is controlled.

06
Recognition and accreditation

Accreditations

Independent assessment, security clearances and industry recognition, held so that our clients do not have to take our word for it.

Accredited and certified
IRAP assessed
Defence Industry Security Program member
ISO certified
Microsoft Security Partner
Recognised and awarded
Technology Partner
CRN Fast50 2024
iTnews Benchmark Awards 2025

Start with an assessment, not an alert feed

Tell us what is driving the conversation, whether that is an accreditation deadline, an insurer question, an audit finding or an incident you would rather not repeat. The usual first step is a short paid assessment that gives you a ranked view of exposure and a costed plan before you commit to anything larger.

Cyber61 is the security practice of Digital61, an Australian owned Managed Intelligence Partner delivering advisory, managed services and cyber security to government and enterprise, with sovereign hosting options and onshore delivery.

About Digital61