# CyberOps > CyberOps (CyberOps Pty Ltd, ABN 47 614 137 932) is an Australian-owned, independent cybersecurity firm headquartered at Lot Fourteen, Adelaide, South Australia. CyberOps provides defence-grade cybersecurity engineering, governance, and advisory services to the Australian Defence Force, government at federal, state and local levels, and industry sectors including critical infrastructure, healthcare, finance, and space systems. CyberOps does not provide services to personal or consumer clients. CyberOps is a DISP member with NV1 and NV2 cleared personnel, ISO/IEC 27001:2022 certified, and ASD Essential Eight Maturity Level 2 aligned. The firm is among the first in Australia to offer CMMC 2.0 assessment and readiness through a US C3PAO partnership. CyberOps has delivered more than 500 projects for more than 250 organisations and founded the Australian Space Cyber Forum. ## Services ### Vulnerability Management Program (VMP) The CyberOps Vulnerability Management Program (VMP) replaces the usual annual security assessments with continuous visibility into vulnerabilities for ongoing remediation. By partnering with your internal IT team, we deploy enterprise tools to provide the asset visibility and risk-informed intelligence needed to effectively prioritise remediation and strengthen your security posture throughout your ICT environment. **Engagement tiers:** **Strategic Oversight** (Quarterly): For organisations with internal teams running day-to-day operations. - Quarterly vulnerability triage - Quarterly vulnerability prioritisation - Executive risk reporting - Platform health check - Threat intelligence briefing - Strategic review of program KPI **PRO-Active Management** (Monthly): Full-service program management from CyberOps specialists. - Monthly vulnerability triage and remediation prioritisation - Regular platform health, tuning, and optimisation - Executive risk reporting to reduce blind spots - Threat intelligence briefing mapped to your environment - Proactive review of VMP effectiveness and roadmap alignment **Custom-Tailored** (As-required): Expert augmentation for specific tasks or mature teams. - On-demand vulnerability analysis and advisory - Support for complex or high-profile remediation activities - Targeted health checks of your VMP platform and processes - Specialist workshops or training for internal teams - Assistance with board, regulator, or audit reporting - Flexible scope aligned to your existing security program ### Compliance Management Program (CMP) CyberOps' Compliance Management Program (CMP) gives you a single, structured way to understand where you stand against ISO 27001, Essential Eight, SOC 2, CMMC 2.0 and other key frameworks. We combine automated monitoring, tailored workflows and expert guidance so you can see gaps quickly, act with confidence, and demonstrate assurance to customers, regulators and leadership. **Frameworks:** ISO 27001:2022, CMMC 2.0, NIST CSF, SACSF, Australian ISM, DISP, Essential Eight, SOC 2. ### Secure AI We bring the same defence-grade rigour we apply to classified networks and critical infrastructure to AI and large language model integration, including sovereign and classified deployments. We research, build, and operate AI capabilities in-house, and have delivered AI architecture advisory to Australian Defence including Space Command. **Architecture & Integration**: We design AI system architectures applying zero trust, least-privilege access, and data boundary controls across AI pipelines, APIs, and infrastructure, including sovereign and classified environments. - Zero Trust AI Design - LLM & Agentic System Architecture - Agentic System & Tool Integration - RAG Security Patterns - Sovereign Deployment Patterns - Classified & Air-Gap Considerations Our work includes GPS Trust, a sovereign agentic AI platform on MCP for high-assurance operational PNT. **Governance & Risk**: We assess how AI adoption changes your risk profile and map findings to the frameworks you are already accountable to, helping leadership understand exposure and act with confidence. - Australian Government AI Safety Standard - ISO/IEC 42001 - NIST AI RMF - Australian ISM We have developed AI governance frameworks for Australian Defence including Space Command. **Policy & Assurance**: We build the policies, controls, and documented evidence your organisation needs to demonstrate AI governance to customers, regulators, and leadership. - AI Governance Policy Development - Framework Gap Assessment & Roadmap - Board & Executive Risk Reporting - Ongoing Advisory Support ### Hardware Security Testing Structured, standards-based hardware testing helps teams deploy embedded systems securely across defence, government, and critical infrastructure without derailing production timelines. Services include compliance and risk assessment aligned with defence, commercial, and international benchmarks, and certified hardware disposal through data sanitation and physical destruction. **Testing Framework**: We establish structured, standards-based hardware evaluation to ensure functional and secure performance. - MITRE EMB3D - IMDA IoT CyberSecurity - ETSI EN 303 645 **Compliance & Risk Assessment**: Our reviews align with defence, commercial, and international benchmarks to reduce risk. We conduct thorough evaluations of hardware components for compliance ensuring secure deployment across critical infrastructure. **Hardware Disposal**: We provide secure decommissioning of test proponent through certified data sanitation, physical destruction, and environmentally friendly methods. Designed to eliminate data leakage and comply with disposal regulations. ## Capabilities CyberOps delivers engineering-led cybersecurity: secure-by-design architecture, offensive security and adversary emulation, continuous GRC and accreditation (ISO 27001, Essential Eight, ISM), and vCISO leadership. We operate where assurance matters: supporting Defence and government programs while bringing the same rigor to industry. Our focus is practical uplift: controls that work, systems that stand up to threat, and teams that can sustain them. Core Cyber Pillars Architecture & Hardening • Offensive Security • GRC & Accreditation • vCISO • Incident Response • Secure AI CyberOps delivers across six core capability pillars: - **Defence-grade Cyber**: Offensive testing by cleared engineers uncovers exploitable risk, validates controls, and prioritises remediation with evidence. - **Governance, Risk and Compliance**: ISO 27001-certified ISMS, Essential Eight alignment, DISP guidance - pragmatic governance turning requirements into operating reality, daily. - **Threat Adversary Simulations**: Adversary emulation and red-teaming sharpen defences; we design, execute, and debrief realistic, mission-relevant attacks safely. - **Secure-by-design Engineering**: Architecture hardened from inception; patterns, review and acceptance-focused assurance deliver maintainable, accredited systems for operations. - **Pioneers in Australian Space Cyber**: Founded Australian Space Cyber Forum, advancing sovereign collaboration; SpaceIQ delivered passive RF data to UDL. - **An Extension of your Team**: Fractional vCISO, embedded specialists, or deliverables-based projects - engagement models that flex around mission outcomes and constraints. Additional capabilities: classified network design and accreditation, Authority to Operate (ATO) documentation, JORN Design Authority contribution, cyber range design and delivery, incident response, and supply chain security advisory. ## Sector Exemplars ### AUSTRALIAN DEFENCE FORCE CyberOps supports the Department of Defence with end-to-end, mission-ready cyber engineering. We design, deploy, and uplift large, classified networks, hardening architecture and operations for sustained security and availability. Our teams prepare Authority to Operate (ATO) security documentation and evidence guiding programs through assessment with defensible controls. We advance space-cyber capability, delivering ASCA initiatives and Space Domain Awareness (SDA) analysis that translates threat into actionable design decisions. Across the supply chain, we provide security advice that strengthens acquisition, integration, and sustainment. As JORN Design Authority contributors, we apply disciplined systems thinking to complex, long-range radar environments. We also conduct rigorous hardware testing to verify assumptions, reduce risk, and support acceptance. ### CRITICAL INFRASTRUCTURE CyberOps supports commercial and industry sectors across health, finance, academia, and the wider community. In health, we deliver SACSF and regulatory compliance, provide ongoing security services for aged-care, emergency services, and laboratories, and perform hardware and software testing. In finance, we conduct ongoing security assessments for insurers, fund managers, and lenders, and guide PCI accreditation. In academia, we design and build sensitive university networks and provide security and advisory services for schools, universities, and contract research organisations (CROs). We also invest in community events: leading and training Australian teams for NATO Cyber Wargames (Locked Shields), supporting the BSides community cyber event, and running the Australian Space Cyber Forum and workshops. ### AUSTRALIAN GOVERNMENT CyberOps supports government at federal, state, and local levels with pragmatic, mission-aligned security services. At the federal level, we undertake board-level technical assessments of Air Traffic Control systems, provide GNSS procurement security advisory, and assess the security of IoT sensor networks. For state government, we have delivered over thirty past and ongoing security assessments across SA and interstate, offer fractional cyber-as-a-service, support SACSF compliance and reporting, provide DR and BCP training, design and build cyber ranges, and advise on GRC uplift. At the local level, we perform security vulnerability assessments for various local and regional councils and design SCADA and IoT security architectures. Our work strengthens resilience and assurance. ## Target Clients CyberOps serves organisations, not individuals. Engagements are with: - **Australian Defence Force**: ADF, RAAF, ASD, DSTG, and the Department of Defence. Services include classified network design and accreditation, ATO documentation, supply chain security, JORN design authority support, and hardware testing. - **Federal Government**: Air traffic control security assessments, GNSS procurement advisory, IoT sensor network security. - **State and Local Government**: Over thirty security assessments across SA and interstate; fractional cyber-as-a-service; SACSF compliance; cyber range design; GRC uplift advisory. - **US Government Supply Chain**: CMMC 2.0 assessment and readiness for organisations entering the US Defence supply chain. - **Critical Infrastructure**: Energy, transport, space systems, and manufacturing. - **Healthcare**: SACSF compliance, aged-care and emergency services security, laboratory security, hardware and software testing. - **Finance**: Security assessments for insurers, fund managers, and lenders; PCI accreditation guidance. - **Education**: Sensitive network design for universities; security advisory for schools and contract research organisations (CROs). ## Credentials and Frameworks - ISO/IEC 27001:2022: certified and operated ISMS - ASD Essential Eight: Maturity Level 2 aligned - DISP (Defence Industry Security Program): member; NV1 and NV2 cleared personnel - CMMC 2.0: assessment and readiness via US C3PAO partnership - Australian ISM (Information Security Manual) - NIST Cybersecurity Framework (CSF) - SOC 2 - SACSF (South Australian Cyber Security Framework) - NATO Locked Shields: cyber wargames environment design - Space ISAC: member ## Key Statistics - > 250 Happy Customers - > 500 Delivered Projects - > 1,000 Hours of Community Engagement - > 30 Partners, Panels and Professionals - > 50,000 Vulnerabilities Discovered - ~25% Year-on-Year Growth - > 100 Publications ## Leadership ### Dr Daniel Floreani **CEO** Daniel is a consultant with over 30 years in communication networks, covering R&D, systems engineering, enterprise architecture and business development in local and global leadership roles. He specialises in Defence, Satellite, Cyber Security, and public sector ICT, securely connecting devices to the internet. He translates complexity, blending strategy, technical depth, business acumen and political insight. Daniel is leading CyberOps to become an agile, AI aware, cybersecurity services organisation to support its customers on their security journey. ### Jennifer Lee **BD Manager** Jennifer is a cyber security leader with extensive experience delivering complex programs across Australian government and commercial sectors. Specialising in project delivery, stakeholder engagement and cyber GRC, she works with organisations to embed security into strategic decision-making and business operations. A CISA and CISM certified professional, Jennifer provides trusted protective security and assurance expertise that strengthens resilience, executive commitment and security culture. ### Jim Labilles **Cyber Program Manager** Jim is certified ISO 27001:2022 Lead Auditor, ASD's Essential 8 Assessor, and a Microsoft Security Engineer, specialising in Cloud Secure Architecture, NIST, FedRAMP, and the Australian ISM. A former Principal Design Engineer with a BSc in Electronics and Communications Engineering, he has over 20 years delivering secure, standards-driven solutions across government, academia and industry. ### Stefan Norman **Engineering Principal** Stefan is a senior cybersecurity consultant and telecommunications engineer with experience in the design, uplift and accreditation of network environments. He has demonstrated expertise in secure network architecture, infrastructure design, and system hardening, contributing to resilient and compliant capabilities across both standalone and integrated environments. ### Paula Oliver **GRC Principal** Paula Oliver is a Governance, Risk & Compliance Consultant with senior leadership experience in South Australia's Government. She established AustCyber's SA Node, operated Security Risk & Assurance for DPC, led cyber industry growth at DSD and served as interim CEO of Aus3C. She developed SA's first Cyber Industry Capability Matrix, co-designed the state cybersecurity strategy, and orchestrated hackathons and diversity initiatives. A CISM, she champions inclusive ecosystems. ### Brett Burford **Consultant - Cyber & Space** Brett is a seasoned IT and high-tech leader specialising in advanced technology integration, cyber security, deep AI projects and space systems. Solutions oriented, he has launched startups, designed national networks, and delivers end to end platforms, RF/SDA solutions and rapid AI deployments. His work spans space cyber ranges and RF jamming simulation environments. With two Master's degrees, he turns complexity into fast, deployable outcomes globally. ### Marcus Phan **Security Analyst** Marcus is a cyber security professional at CyberOps, specialising in vulnerability assessment across web applications, Active Directory and cloud environments. He pinpoints weaknesses from front-end interfaces to complex architectures and designs remediation paths. Now leading workstreams, he applies standards-aligned defence practices to deliver measurable risk reduction and resilience for enterprise clients across APAC. ### Jesse Sherlock **Security Analyst** Jesse Sherlock is a Cyber Security Analyst specialising in web application testing, internal network assessments and physical penetration exercises. He applies social engineering techniques and structured methodologies to uncover vulnerabilities. As volunteer IT Specialist for the Wild Webcap citizen science project, he ensures secure data collection. Committed to continuous self-improvement, he pursues ongoing certifications and specialised training, supporting CyberOps' security engagements. ### Peter McQuade **GRC Consultant** Peter is a cybersecurity professional with experience in Governance, Risk and Compliance within technology-focused environments. He has conducted Data Protection Impact Assessments (DPIAs), performed security risk assessments, and supported audit and compliance activities for regulated systems processing sensitive data. ### Helen Abbott **HR Manager** Helen is an experienced HR professional with a strong background in people operations, organisational development, and workforce planning. She leads recruitment, onboarding, and employee engagement initiatives, ensuring CyberOps attracts and retains high-performing talent. Helen is passionate about building a positive workplace culture and supporting teams through structured policies, compliance, and best-practice HR governance. ## Strategic Partners PacketWorks, CSP Global, Accenture, Shoal, School of Information Operations (SOIO), Australian Cyber Security Centre (ACSC), Boeing. ## Engagement CyberOps engages organisations through fractional vCISO leadership, embedded specialist placement, deliverables-based projects, or ongoing consulting retainers. - Website: [cyberops.com.au](https://cyberops.com.au) - Phone: 1300 100 377 - Sales: sales@cyberops.com.au - Address: Level 2, SpaceLab Building, Lot Fourteen, Frome Rd, Adelaide SA 5000 ## Pages - [Home](/): Overview of capabilities, differentiators, and engagement model. - [Capabilities](/capabilities): Six capability pillars and sector-specific exemplars (Defence, Government, Corporate). - [Services](/services): VMP, CMP, Secure AI, and Hardware Security Testing service detail. - [About Us](/about-us): Company background, values, team profiles, and approach. - [Insights](/news): Technical articles and industry commentary. - [Engage](/engage): Contact and engagement enquiry. - [Privacy Policy](/privacy-policy): Data handling practices (website users only; not applicable to client engagements).