# CyberOps > CyberOps (CyberOps Pty Ltd, ABN 47 614 137 932) is an Australian-owned, independent cybersecurity firm headquartered at Lot Fourteen, Adelaide, South Australia. CyberOps provides defence-grade cybersecurity engineering, governance, and advisory services to the Australian Defence Force, government at federal, state and local levels, and industry sectors including critical infrastructure, healthcare, finance, and space systems. CyberOps does not provide services to personal or consumer clients. CyberOps is a DISP member with NV1 and NV2 cleared personnel, ISO/IEC 27001:2022 certified, and ASD Essential Eight Maturity Level 2 aligned. The firm is among the first in Australia to offer CMMC 2.0 assessment and readiness through a US C3PAO partnership. CyberOps has delivered more than 500 projects for more than 250 organisations and founded the Australian Space Cyber Forum. ## Services - [Vulnerability Management Program (VMP)](/services#vmp): The CyberOps Vulnerability Management Program (VMP) replaces the usual annual security assessments with continuous visibility into vulnerabilities for ongoing remediation. By partnering with your internal IT team, we deploy enterprise tools to provide the asset visibility and risk-informed intelligence needed to effectively prioritise remediation and strengthen your security posture throughout your ICT environment. 3 engagement tiers: **Strategic Oversight** (Quarterly): For organisations with internal teams running day-to-day operations; **PRO-Active Management** (Monthly): Full-service program management from CyberOps specialists; **Custom-Tailored** (As-required): Expert augmentation for specific tasks or mature teams. - [Compliance Management Program (CMP)](/services#cmp): CyberOps' Compliance Management Program (CMP) gives you a single, structured way to understand where you stand against ISO 27001, Essential Eight, SOC 2, CMMC 2.0 and other key frameworks. We combine automated monitoring, tailored workflows and expert guidance so you can see gaps quickly, act with confidence, and demonstrate assurance to customers, regulators and leadership. Frameworks: ISO 27001:2022, CMMC 2.0, NIST CSF, SACSF, Australian ISM, DISP, Essential Eight, SOC 2. - [Secure AI](/services#secure-ai): We bring the same defence-grade rigour we apply to classified networks and critical infrastructure to AI and large language model integration, including sovereign and classified deployments. We research, build, and operate AI capabilities in-house, and have delivered AI architecture advisory to Australian Defence including Space Command. Frameworks: Australian Government AI Safety Standard, ISO/IEC 42001, NIST AI RMF, Australian ISM. - [Hardware Security Testing](/services#hardware-testing): Structured, standards-based hardware testing helps teams deploy embedded systems securely across defence, government, and critical infrastructure without derailing production timelines. Services include compliance and risk assessment aligned with defence, commercial, and international benchmarks, and certified hardware disposal through data sanitation and physical destruction. Testing standards: MITRE EMB3D, IMDA IoT CyberSecurity, ETSI EN 303 645. ## Capabilities CyberOps delivers across six core capability pillars: - **Defence-grade Cyber**: Offensive testing by cleared engineers uncovers exploitable risk, validates controls, and prioritises remediation with evidence. - **Governance, Risk and Compliance**: ISO 27001-certified ISMS, Essential Eight alignment, DISP guidance - pragmatic governance turning requirements into operating reality, daily. - **Threat Adversary Simulations**: Adversary emulation and red-teaming sharpen defences; we design, execute, and debrief realistic, mission-relevant attacks safely. - **Secure-by-design Engineering**: Architecture hardened from inception; patterns, review and acceptance-focused assurance deliver maintainable, accredited systems for operations. - **Pioneers in Australian Space Cyber**: Founded Australian Space Cyber Forum, advancing sovereign collaboration; SpaceIQ delivered passive RF data to UDL. - **An Extension of your Team**: Fractional vCISO, embedded specialists, or deliverables-based projects - engagement models that flex around mission outcomes and constraints. Additional capabilities: classified network design and accreditation, Authority to Operate (ATO) documentation, JORN Design Authority contribution, cyber range design and delivery, incident response, and supply chain security advisory. ## Target Clients CyberOps serves organisations, not individuals. Engagements are with: - **Australian Defence Force**: ADF, RAAF, ASD, DSTG, and the Department of Defence. Services include classified network design and accreditation, ATO documentation, supply chain security, JORN design authority support, and hardware testing. - **Federal Government**: Air traffic control security assessments, GNSS procurement advisory, IoT sensor network security. - **State and Local Government**: Over thirty security assessments across SA and interstate; fractional cyber-as-a-service; SACSF compliance; cyber range design; GRC uplift advisory. - **US Government Supply Chain**: CMMC 2.0 assessment and readiness for organisations entering the US Defence supply chain. - **Critical Infrastructure**: Energy, transport, space systems, and manufacturing. - **Healthcare**: SACSF compliance, aged-care and emergency services security, laboratory security, hardware and software testing. - **Finance**: Security assessments for insurers, fund managers, and lenders; PCI accreditation guidance. - **Education**: Sensitive network design for universities; security advisory for schools and contract research organisations (CROs). ## Credentials and Frameworks - ISO/IEC 27001:2022: certified and operated ISMS - ASD Essential Eight: Maturity Level 2 aligned - DISP (Defence Industry Security Program): member; NV1 and NV2 cleared personnel - CMMC 2.0: assessment and readiness via US C3PAO partnership - Australian ISM (Information Security Manual) - NIST Cybersecurity Framework (CSF) - SOC 2 - SACSF (South Australian Cyber Security Framework) - NATO Locked Shields: cyber wargames environment design - Space ISAC: member ## Key Statistics - > 250 Happy Customers - > 500 Delivered Projects - > 1,000 Hours of Community Engagement - > 30 Partners, Panels and Professionals - > 50,000 Vulnerabilities Discovered - ~25% Year-on-Year Growth - > 100 Publications ## Leadership - **Dr Daniel Floreani**, CEO. Daniel is a consultant with over 30 years in communication networks, covering R&D, systems engineering, enterprise architecture and business development in local and global leadership roles. He specialises in Defence, Satellite, Cyber Security, and public sector ICT, securely connecting devices to the internet. He translates complexity, blending strategy, technical depth, business acumen and political insight. Daniel is leading CyberOps to become an agile, AI aware, cybersecurity services organisation to support its customers on their security journey. - **Jennifer Lee**, BD Manager. Jennifer is a cyber security leader with extensive experience delivering complex programs across Australian government and commercial sectors. Specialising in project delivery, stakeholder engagement and cyber GRC, she works with organisations to embed security into strategic decision-making and business operations. A CISA and CISM certified professional, Jennifer provides trusted protective security and assurance expertise that strengthens resilience, executive commitment and security culture. - **Jim Labilles**, Cyber Program Manager. Jim is certified ISO 27001:2022 Lead Auditor, ASD's Essential 8 Assessor, and a Microsoft Security Engineer, specialising in Cloud Secure Architecture, NIST, FedRAMP, and the Australian ISM. A former Principal Design Engineer with a BSc in Electronics and Communications Engineering, he has over 20 years delivering secure, standards-driven solutions across government, academia and industry. - **Stefan Norman**, Engineering Principal. Stefan is a senior cybersecurity consultant and telecommunications engineer with experience in the design, uplift and accreditation of network environments. He has demonstrated expertise in secure network architecture, infrastructure design, and system hardening, contributing to resilient and compliant capabilities across both standalone and integrated environments. - **Paula Oliver**, GRC Principal. Paula Oliver is a Governance, Risk & Compliance Consultant with senior leadership experience in South Australia's Government. She established AustCyber's SA Node, operated Security Risk & Assurance for DPC, led cyber industry growth at DSD and served as interim CEO of Aus3C. She developed SA's first Cyber Industry Capability Matrix, co-designed the state cybersecurity strategy, and orchestrated hackathons and diversity initiatives. A CISM, she champions inclusive ecosystems. - **Brett Burford**, Consultant - Cyber & Space. Brett is a seasoned IT and high-tech leader specialising in advanced technology integration, cyber security, deep AI projects and space systems. Solutions oriented, he has launched startups, designed national networks, and delivers end to end platforms, RF/SDA solutions and rapid AI deployments. His work spans space cyber ranges and RF jamming simulation environments. With two Master's degrees, he turns complexity into fast, deployable outcomes globally. - **Marcus Phan**, Security Analyst. Marcus is a cyber security professional at CyberOps, specialising in vulnerability assessment across web applications, Active Directory and cloud environments. He pinpoints weaknesses from front-end interfaces to complex architectures and designs remediation paths. Now leading workstreams, he applies standards-aligned defence practices to deliver measurable risk reduction and resilience for enterprise clients across APAC. - **Jesse Sherlock**, Security Analyst. Jesse Sherlock is a Cyber Security Analyst specialising in web application testing, internal network assessments and physical penetration exercises. He applies social engineering techniques and structured methodologies to uncover vulnerabilities. As volunteer IT Specialist for the Wild Webcap citizen science project, he ensures secure data collection. Committed to continuous self-improvement, he pursues ongoing certifications and specialised training, supporting CyberOps' security engagements. - **Peter McQuade**, GRC Consultant. Peter is a cybersecurity professional with experience in Governance, Risk and Compliance within technology-focused environments. He has conducted Data Protection Impact Assessments (DPIAs), performed security risk assessments, and supported audit and compliance activities for regulated systems processing sensitive data. - **Helen Abbott**, HR Manager. Helen is an experienced HR professional with a strong background in people operations, organisational development, and workforce planning. She leads recruitment, onboarding, and employee engagement initiatives, ensuring CyberOps attracts and retains high-performing talent. Helen is passionate about building a positive workplace culture and supporting teams through structured policies, compliance, and best-practice HR governance. ## Strategic Partners PacketWorks, CSP Global, Accenture, Shoal, School of Information Operations (SOIO), Australian Cyber Security Centre (ACSC), Boeing. ## Engagement CyberOps engages organisations through fractional vCISO leadership, embedded specialist placement, deliverables-based projects, or ongoing consulting retainers. - Website: [cyberops.com.au](https://cyberops.com.au) - Phone: 1300 100 377 - Sales: sales@cyberops.com.au - Address: Level 2, SpaceLab Building, Lot Fourteen, Frome Rd, Adelaide SA 5000 ## Pages - [Home](/): Overview of capabilities, differentiators, and engagement model. - [Capabilities](/capabilities): Six capability pillars and sector-specific exemplars (Defence, Government, Corporate). - [Services](/services): VMP, CMP, Secure AI, and Hardware Security Testing service detail. - [About Us](/about-us): Company background, values, team profiles, and approach. - [Insights](/news): Technical articles and industry commentary. - [Engage](/engage): Contact and engagement enquiry. - [Privacy Policy](/privacy-policy): Data handling practices (website users only; not applicable to client engagements).