Digital61 Secure Cloud Gateway

Secure Cloud Gateway, a modern SIG

A cloud native alternative to the legacy secure internet gateway. IRAP assessed components, flexible tenancy and integrated monitoring, aligned to the Protective Security Policy Framework and built for the risk based decisions agencies now make for themselves.

Modern SIG. Mission-ready. Sovereign.
Trusted across Australian government and enterprise

A selection of the organisations our engineers deliver for.

Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client Digital61 client
01
Capability

What we deliver

Following the change in gateway policy, entities are no longer required to consume an ASD certified gateway. Each non-corporate Commonwealth entity now makes a risk based decision, supported by IRAP assessed solutions. Our Secure Cloud Gateway is built for exactly that model.

Boundary protection and threat prevention Inspection, filtering and threat prevention at the boundary, tuned to your traffic profile rather than to a generic default policy.
Flexible deployment models Multi tenanted, single tenant or service specific deployment, so the tenancy model matches your risk position and your budget.
Granular web and application controls Policy by user, group, application and risk category, with the visibility to justify each decision when someone asks why.
Cloud delivered scalability Capacity that scales with demand instead of a hardware refresh cycle, which removes the usual reason gateway upgrades get deferred.
Integrated monitoring SIEM, SOAR and threat intelligence integrated from day one, so gateway telemetry lands where your analysts are already working.
IRAP assessed components Components assessed and aligned to the Protective Security Policy Framework, with the documentation your accreditation process expects.
02
Clients

Who we work with

The gateway was designed for government requirements, and those same controls answer questions that regulated private sector organisations are now being asked.

Public sector
  • Who. Non-corporate Commonwealth entities, state agencies and government owned corporations making a risk based gateway decision.
  • Compliance. Aligned to the Australian Government Gateway Security Standard, the Protective Security Policy Framework and Zero Trust principles.
  • Sovereignty. One hundred per cent Australian hosted and Australian operated, with AGSVA cleared personnel.
  • Assessment. IRAP assessed components with evidence packaged for your authorising officer rather than assembled after the fact.
  • Transition. Migration paths from legacy gateway arrangements, staged so services stay available throughout.
Private sector
  • Who. Defence industry suppliers, regulated commercial operators and organisations delivering into government supply chains.
  • Drivers. Contractual security obligations, supply chain requirements and customers who want government grade controls evidenced.
  • Cost. Multi tenanted deployment makes government grade boundary protection viable at commercial scale.
  • Risk. Egress inspection, application control and threat prevention that measurably reduce the exposure insurers ask about.
  • Continuity. Operated by Cyber61 with monitoring and response included, rather than handed over as a platform for you to staff.

We do not deliver compliance checklists. The gateway is designed to be operated, monitored and defended, which is a different exercise to being accredited once.

03
Method

How we engage

Gateway engagements are staged deliberately, because availability during transition matters more than speed.

  1. AssessA short paid review of your current gateway arrangement, traffic profile, obligations and the risk position you need to reach.
  2. DesignTenancy model, control set, integration points and a costed design, with the residual risks stated plainly for your authorising officer.
  3. AssureControl mapping to the Gateway Security Standard and the Protective Security Policy Framework, with IRAP evidence assembled as part of the build.
  4. MigrateStaged cutover with parallel running and agreed rollback points, so no service loses connectivity during transition.
  5. OperateOngoing operation, tuning and monitoring integrated with the Managed SOC, with reporting against your obligations.
04
Assurance

Compliance and sovereignty

Sovereignty and compliance are structural here rather than claimed. These are the positions the service is built to hold.

  • FRAMEWORKAustralian Government Gateway Security Standard
  • FRAMEWORKProtective Security Policy Framework
  • ASSESSMENTIRAP assessed components
  • ARCHITECTUREZero Trust architecture
  • SOVEREIGNTYOne hundred per cent Australian hosted
  • PERSONNELAGSVA cleared personnel
  • DELIVERYMulti tenant and single tenant options
  • TOOLINGSIEM, SOAR and threat intelligence integration

The gateway integrates directly with our Managed SOC, incident response and governance practices, which means detection, response and evidence all sit with one accountable Australian team.

05
Recognition and accreditation

Accreditations

Independent assessment, security clearances and industry recognition, held so that our clients do not have to take our word for it.

Accredited and certified
IRAP assessed
Defence Industry Security Program member
ISO certified
Microsoft Security Partner
Recognised and awarded
Technology Partner
CRN Fast50 2024
iTnews Benchmark Awards 2025

Partnering for security, not just compliance

If you are reassessing a legacy gateway arrangement or building a risk based case for a modern alternative, the first step is a short paid review of your current position. You keep the analysis whether or not you proceed.

Digital61 operates a sovereign Secure Cloud Gateway for Australian government and regulated organisations.

See all services