Financial Services·Superannuation·Government·Health·Education·Data Centre Providers·Care Services·Critical Infrastructure Operators·Growing Businesses
What we do · Cyber security
Cyber. Handled with proof, not promises.

Cyber security

Understand, manage, and reduce cyber risk across strategy, controls, and the integration of advanced protections. Threat-informed, principal-led, and built so meeting the rules follows from real resilience, not the other way round.

The cyber moment

Cyber has moved from IT problem to board accountability.

Essential Eight. SOCI. APRA CPS 234. Directors' duties. The bar is rising, and the cost of falling short is getting more tangible, in fines, in class actions, and in executive tenure. The organisations responding well aren't chasing a tick in the box. They're building the strength that makes the tick a by-product.

Lumaris designs cyber programs sized to your risk and built to operate. Threat-informed, not vendor-led. Essential Eight, ISO 27001, SOCI, and APRA as evidence layers, with resilience as the real target.

Passing the audit doesn't mean surviving the breach. Surviving the breach doesn't mean passing the audit.
The cyber portfolio

Four capabilities. One integrated cyber practice.

Each capability stands alone. Together they take an organisation from reactive position today to resilient cyber capability, with controls sized to risk and designed to operate.

— 01

Strategy & Advisory

From cyber ambition to practical strategy. Roadmaps, operating plans, policy frameworks, standards, technology advice, and readiness scoring.

— 02

Security & Compliance

Cyber risk understood, managed, and evidenced. Risk assessment, advice on the rules, threat modelling, privacy and breach response, audit-ready documentation.

— 03

Systems Integration

Security built into the stack. Architecture, network, endpoint, data, application, and identity, designed to operate as one.

— 04

Operations & Enablement

Cyber as a sustained capability. Project delivery, change management, monitoring, knowledge management, testing, and quality across the program.

The rules we work to

The cyber rules we work to.

We work to the major Australian and international cyber rules. The Essential Eight is the cyber baseline. ISO 27001 is the international standard for managing information security. The rules for banks, government, breach reporting, critical infrastructure, and directors' duties add their own layers on top. See the glossary for what each one covers and when it bites.
Outcomes, not deliverables

Outcomes you can take to a board.

Every engagement closes with artefacts a board or auditor can read on its own.

  • Essential Eight readiness baseline with prioritised uplift roadmap
  • Cyber risk register sized to a current threat model, with controls mapped
  • Security management pack aligned to ISO 27001, designed to operate, not just to certify
  • Zero-trust foundation: identity, separation, and verification by default
  • Critical infrastructure readiness position with sign-off evidence
  • Incident response runbooks, tested against realistic scenarios
  • Threat-led adversarial assessment findings with prioritised fixes
  • Board-ready closing brief and 90-day roadmap
Three ways to engage

Three ways to engage. Sized to where you are today.

— 01Start with a question

A focused 4–6 week review

Cyber readiness baseline, security review, or focused scope on the rules. Fixed scope, price, end date.

  • Best when you know something needs to happen but aren't yet certain what
  • Board-ready closing brief
  • Prioritised fix-list and roadmap
  • Defined scope, fixed fee
— 02Start with a programme

A defined 8–16 week implementation

Essential Eight uplift. Zero-trust foundations. Critical infrastructure fixes. Incident response readiness.

  • Best when the answer is clear and the work is to make it real
  • Reference architecture and runbooks
  • Identity, separation, and monitoring
  • Hand-over with continued support
— 03Start with advice

A principal advisor on retainer

Senior counsel for boards and executives working through cyber risk, vendor selection, and the rules. Monthly, fortnightly, or to your cadence.

  • Best when you need a trusted hand over time
  • Board-ready risk briefings
  • Independent vendor and platform reviews
  • CISO advisory, fractional
Packaged cyber engagements

Ten ways we scope the work.

Standardised forms our cyber work takes. Each is scoped and sized to deliver measurable outcomes, designed as a complete engagement in its own right and a natural step into deeper work.

01

Cyber Risk & Maturity Baseline

A board-ready answer to "where does our cyber stand, really?"

4–6 wks
02

Essential Eight Uplift Programme

From self-assessed to defensibly assessed, at the readiness level your risk demands.

8–16 wks
03

SOCI / CIRMP Compliance Assessment

Know exactly where you stand against the critical infrastructure rules.

6–10 wks
04

Zero Trust Network Foundation

Replace "inside is safe" with controls that verify every time.

8–14 wks
05

Incident Response Readiness

Be ready before the incident, not during it.

6–10 wks
06

ISO 27001 Certification Readiness

A security management program that's certifiable, designed to operate, not just to pass.

12–20 wks
07

Privacy & NDB Readiness

A privacy position that holds up to scrutiny, or a breach.

6–10 wks
08

Threat-Led Adversarial Assessment

Find out how your defences fail before someone makes you find out.

4–8 wks
09

Secure Cloud Foundation

Cloud done with cyber inside, not bolted on.

8–14 wks
10

Strategic Adviser on Retainer

A principal at your side, sized to your cadence.

Rolling

Every packaged engagement is fixed-fee on a scoping call. Talk to us about your context and we will price it specifically.

The other four offerings

One framework. Five places to start.

Talk to us about your cyber programme.

Tell us about your environment and we will be in touch within one business day.

Rise with confidence.