Independent cyber security engineeringAustralia-wide. Operationally focused.

Confidence.
Built into your
defences.

Practical cyber security for Australian businesses. We harden your systems, close the gaps, and give you the evidence to know it’s working.

Engineer-led. Clear scope. Measurable outcomes.

DESIGNED IN LAYERS.VERIFIED IN PRACTICE. ↗
Microsoft 365   /   Identity & cloudInfrastructure   /   Firewalls & endpointsEssential Eight   /   Governance & evidenceOur approach ↗
10+Years in security
8/8Essential 8 controls
1 dayTypical response
100%Remote-first, AU
FRAMEWORKS WE WORK WITHACSC Essential EightISO 27001NIST CSFMicrosoft 365
What we do

Security that does
the real work.

We deliberately keep the service list short. Everything below is something we deliver repeatably, with artefacts your IT team, MSP, auditor, or insurer can actually use.

Microsoft 365 & Azure Hardening

Conditional Access, secure baselines, identity hygiene, mail hygiene, logging, and privileged access reviews — the controls that actually stop business email compromise.

  • Tenant baseline review and remediation plan
  • Conditional Access design and rollout
  • Defender / Exchange Online Protection uplift
Explore service

Firewall Review & Uplift

Fortigate, pfSense, Palo Alto, or vendor-agnostic review. We rationalise rulesets that have grown for a decade and document what's left.

  • Ruleset simplification and documentation
  • VPN and remote access patterns
  • Segmentation across sites and environments
Explore service

Windows / GPO Baselines

Essential Eight-aligned hardening: OS baselines, application control options, USB and device lockdown, secure config.

Explore service

Vulnerability Assessments

Targeted scanning, triage, and remediation plans your IT team or MSP can actually execute — ranked by real exploitability.

Explore service

Incident Response

Compromise assessment, containment, and cleanup across accounts, endpoints, and email. Focused on rapid, practical recovery.

Explore service

GRC & Policy

Policy development aligned to Essential Eight, ISO 27001, and NIST CSF — including board-level summaries that a non-technical director can act on.

Explore service

Business Continuity & IR Planning

Runbooks, escalation paths, backup validation, and tabletop exercises so the plan works on the day it's needed rather than the day it was written.

Explore service
The DingoSec platform

Your controls.
Your evidence.
One clear view.

Bring your Essential Eight program into focus. Track control status, surface configuration drift, and turn technical findings into a roadmap your team can work through.

  • Continuous control visibility
  • Prioritised findings and remediation
  • Evidence and reporting for your next audit
Explore the platform
DINGOSEC / ESSENTIAL EIGHTPRODUCT PREVIEW ↗
DingoSec Essential Eight platform showing security controls organised by maturity level

Essential Eight controls, organised by maturity level.

How an engagement runs

From first call to verified uplift

No 90-day discovery phase. We aim to have you measurably safer inside the first engagement, with evidence you can hand to an auditor.

Scoping call

30 minutes to understand your environment, obligations, and what's actually keeping you up at night.

Assessment

We review the real configuration — tenant, edge, endpoints — not a questionnaire, and rank findings by exploitability.

Remediation

Changesets your team or MSP can implement, or hands-on delivery by us. Documented as we go.

Verify & hand over

Re-test, evidence pack, and a prioritised backlog for what comes next. Optional ongoing monitoring.

THE HANDOVERBUILT TO BE USED ↗

Clarity you can
put to work.

Every engagement ends with practical deliverables your team can own.

01
Prioritised risk registerKnow what matters and what to fix first.
02
Documented changesetsClear implementation steps for your IT team or MSP.
03
Verification & evidenceRe-tested controls. Findings backed by evidence.
04
Your next-stage roadmapA practical backlog to keep improving.
In their words

What clients say

DingoSec completely overhauled our firewall and M365 security in a matter of weeks. Highly pragmatic and no fluff. They operate exactly as advertised.

— CIO, National Logistics Firm

Their Essential 8 roadmap finally gave our board the clarity we needed. We now have a verifiable security baseline and can prove it to our insurers.

— IT Director, Manufacturing Sector

Who we help

DingoSec focuses on Australian small and mid-sized organisations that need to make meaningful security progress without hiring a full-time internal security team.

Typical clients include manufacturing, food and beverage, logistics, regional councils, and services businesses built around Microsoft 365, Windows endpoints, and a firewall that “works” but hasn't been revisited in years.

Engagements are remote-first across Australia, with on-site work by arrangement where factories, warehouses, or data centres are involved.

Approach & outcomes

Work is prioritised around threats that matter: ransomware, business email compromise, account takeover, and destructive insider activity.

Deliverables are pragmatic: secure baselines, changesets that your IT team or MSP can implement, and clear documentation. We can also deploy automated solutions to continuously track control status for Essential Eight programs.

The goal is to leave you measurably safer with artefacts that stand up to auditors, insurers, and customers — not a slide deck that gathers dust.

Make your next move
a more secure one.

A 30-minute scoping call is usually enough to tell you where the real risk sits and what a sensible first engagement looks like. No obligation, no sales theatre.

Book a consult