Services Strategy, Transformation & Design Governance, Risk & Compliance Technical Security Assurance Managed Security Service AI Security & Governance ✦ New Case Studies Clients About Us Contact
Get in Touch
Trusted Cybersecurity Solutions, Australia

Securing Your Business
Is Our Business.

Cyber security risks are ubiquitous, so should your defences be.

Crysp Consulting is Australia's trusted cybersecurity partner. We help organisations build resilient security postures through expert strategy, governance, technical assurance, managed services and AI security, delivered by practitioners, not generalists.

0
Projects Completed
0
Applications & Networks Tested
0
Funding Secured Through Cyber Strategy
0
Board & ARC Presentations
0
Business Risks Remediated

Business Challenges We Solve

Every organisation faces different pressures. We address the ones that keep security leaders up at night.

Skills Shortage

24/7/365 service backed by SLAs means full security coverage without the overhead of building an in-house team from scratch.

Scaling Up

Modern AI-led technology combined with expert-led service scales with your business, without the hiring lag or training overhead.

Cyber Attacks

A realistic roadmap and security strategy provides an IT framework that's future-proof against increasingly sophisticated threats.

Time & Resource Constraints

AI-led technology and expert service lets your team focus on core business priorities while we handle security operations.

Lack of Expertise

Enhance your security and compliance operations without the hassle of hiring, training, and retaining specialist staff.

Insider Threats

Superior visibility into your complete enterprise infrastructure, detecting internal risks and external attacks before they escalate.

Our Service Pillars

Five comprehensive practice areas covering every dimension of your organisation's cybersecurity needs.

Security Strategy, Transformation & Design

We architect robust security solutions that align with your business objectives in today's rapidly evolving digital environments, from boardroom strategy to hands-on implementation.

  • Cyber Strategy, Roadmap & Target Operating ModelView details →
  • IDAM Strategy and SolutionsView details →
  • Cyber Security Program ManagementView details →
  • Enterprise Security Architecture & DesignView details →
Discuss Your Strategy

Strategy & Design

We start by understanding your business context, goals, risk appetite, regulatory obligations, and technology landscape, before building a tailored security programme.


The outcome is a prioritised, actionable roadmap your leadership team can present to the board and your technical team can execute against, with clear milestones and ownership.


Get Started

Governance, Risk & Compliance

We help organisations manage risks, uphold compliance standards, and establish robust governance structures that satisfy regulators, auditors, and the board, without creating bureaucratic overhead.

  • Framework Based Assessment / Audit (NIST, ISO 27001, Essential Eight)View details →
  • Information Security Management Systems (ISMS)View details →
  • Threat & Risk AssessmentView details →
  • Virtual CISO as a ServiceView details →
  • Cyber Awareness and TrainingView details →
Talk to a GRC Expert

Governance, Risk & Compliance

Our Virtual CISO service gives you access to senior security leadership on a fractional basis, strategic oversight, board reporting, and regulatory navigation without the full-time cost.


We work to ISO 27001, NIST CSF, Essential Eight, VPDSF, SOC 2, and sector-specific frameworks, giving your programme credibility and rigour with regulators and auditors.


Get Started

Technical Security Assurance

A comprehensive service crafted to fortify your organisation's defences, identify vulnerabilities, and ensure the resilience of your digital infrastructure against real-world adversaries.

  • Penetration Testing (Network, Web App, API, Cloud, OT/SCADA)View details →
  • Breach and Attack SimulationView details →
  • Source Code ReviewView details →
  • Cloud Configuration ReviewView details →
  • Social EngineeringView details →
Request a Pen Test

Technical Assurance

Our testers hold OSCP, CEH, CREST, and GIAC certifications, not just tooling operators. You get manual testing depth alongside automated scanning efficiency.


Deliverables are risk-rated and written for two audiences: technical remediation guidance for your engineers, and executive summaries your board can act on immediately.


Get Started

Managed Security Service

Comprehensive protection and peace of mind against evolving cyber threats, with proactive defence mechanisms and a team monitoring your environment around the clock.

  • GRC and AssessmentsView details →
  • Cyber Awareness and TrainingView details →
  • Critical Incident Response Planning & SimulationView details →
  • Security Operations Centre & SIEMView details →
  • Threat IntelligenceView details →
Explore Managed Services

Managed Security

Our SOC operates 24/7/365 with defined SLAs, giving you full security operations coverage without the overhead of standing up an internal team.


Threat intelligence feeds, SIEM correlation, and tested incident response playbooks mean you're not just monitored, you're protected with a proven response capability.


Get Started
New Practice Area

AI Security & Governance

AI adoption is accelerating across every industry, but so is the attack surface it creates. Crysp helps organisations harness AI with confidence by identifying and managing the security and safety risks that come with it, before regulators and adversaries find them first.

  • AI Risk Assessment & Threat ModellingView details →
  • AI Security & Safety Policy DevelopmentView details →
  • Shadow AI Discovery & InventoryView details →
  • LLM & Generative AI Security TestingView details →
  • AI Governance Framework (NIST AI RMF, AUS AI Ethics)View details →
Speak to an AI Security Expert

Why AI Security Now?

Organisations are deploying AI tools faster than their governance frameworks can keep pace. Shadow AI, prompt injection, data poisoning, and model inversion are real attack vectors, and most security teams are unprepared for them.


We align your AI programme to the NIST AI Risk Management Framework and Australia's Voluntary AI Safety Standard, giving you a defensible position with regulators and your board.


Covers: LLMs · Generative AI · AI-augmented applications · Third-party AI integrations · Agentic AI systems


Get Started

What Sets Us Apart

We don't just deliver reports, we deliver outcomes. Here's how we approach every engagement.

01

No Cookie-Cutters

We develop a tailored process for every client. Security is not one-size-fits-all, and neither is your strategy.

02

Pragmatic Approach

We deliver beyond the initial requirement to serve the underlying need, practical, actionable outcomes over theoretical compliance.

03

Industry-Leading Expertise

Real-world experience across financial services, critical infrastructure, government, healthcare, and utilities sectors.

04

Fast Response

Short lead times with tangible impact. We move at the pace your business requires, not the pace of a big-four billing cycle.

05

Adaptable Scheduling

Agile programme scheduling for flexibility, we align to your constraints, not the other way around.

06

Focus on Value

Top-tier delivery at competitive pricing. Senior-led engagements without the premium overhead of larger firms.

Our Certifications
CISSP CISM CISA CEH OSCP GIAC CREST ISO 27001 CISSP CISM CISA CEH OSCP GIAC CREST ISO 27001

Case Studies by Sector

A snapshot of how we've helped organisations across Australia and globally build resilient, mature security programmes.

Strategy & Maturity

Multi-Year Cyber Security Uplift: Large Regional Health Service

The Challenge

A major regional health service provider with nearly 10,000 employees, spanning acute care, aged care, mental health, and community services, faced a fragmented security posture with no cohesive strategy. Multiple audits had exposed critical gaps across governance, processes, and technology controls, yet no multi-year investment case had been built to address them.

How We Helped
  • Developed a multi-year cyber security strategy and roadmap with a supporting business case to secure significant capital investment
  • Conducted enterprise risk assessments across critical infrastructure and applications as part of Essential Eight and NIST maturity exercises
  • Designed and delivered a cyber security awareness and training refresh programme across clinical and non-clinical staff
  • Developed the full ISMS programme including security policies, standards, and a Third-Party Assessment Framework covering patient data access
  • Conducted penetration testing across infrastructure, web applications, and clinical systems, including networked medical devices
100+
Apps Assessed
~10K
Employees
E8 + NIST
Frameworks
Incident Response & Compliance

ISMS Build & Incident Response Readiness: Regional Health Network

The Challenge

A regional health network providing hospital, aged care, dental, and community services had not conducted a formal security assessment despite a heightened threat environment targeting healthcare providers. The organisation needed to understand its risk exposure and meet its Victorian Protective Data Security Framework (VPDSF) obligations.

How We Helped
  • Conducted VPDSF compliance assessment including VPDSS Elements Control Assessment and Security Profile Risk Assessment (SRPA)
  • Built the organisation's Information Asset Register from the ground up
  • Designed and delivered cyber incident response planning and simulation exercises to test and mature the response capability
  • Developed a tactical and strategic roadmap addressing immediate risks and long-term capability building
  • Conducted external vulnerability scanning, web application penetration testing, and social engineering exercises
VPDSF
Compliance
~10K
Employees
Full
ISMS Built
Strategy & Program Management

Three-Year Cyber Uplift Programme: Metropolitan Council

The Challenge

A metropolitan council in Victoria, serving over 365,000 residents, had a fragmented approach to cyber security with no cohesive strategy. Budget and effort were being spent reactively on ad hoc initiatives rather than addressing core systemic risks. The leadership team lacked visibility into their security posture and needed a programme they could take to the council for funding approval.

How We Helped
  • Performed a framework-based maturity assessment leveraging the NIST Cybersecurity Framework to establish current state
  • Developed a three-year cyber security strategy comprising 40+ prioritised initiatives, approved by council leadership
  • Built a detailed Programme Management Plan covering scope, resource requirements, dependencies, and budget
  • Delivered high-level architecture, product analysis, scoping studies, and programme plans to launch initiatives
  • Active board and leadership engagement, executives now directly accountable for cyber security outcomes
365K+
Residents Served
40+
Initiatives Delivered
$M+
Platform Savings
Risk Remediation

Risk Backlog Clearance & Platform Rationalisation: Local Council

The Challenge

A local government organisation had accumulated a significant backlog of unresolved cyber risks, many open for over 24 months, along with duplicated and obsolete technology platforms consuming budget with no security benefit. Core and fundamental security problems had gone unaddressed while effort was spent on visible but lower-priority items.

How We Helped
  • Conducted a holistic review to identify core systemic risks across people, process, and technology
  • Decommissioned obsolete and duplicate platforms, delivering significant budget savings reinvested into priority initiatives
  • Resolved 75+ risks that had been open for 24+ months through a structured remediation programme
  • Engaged business leadership and the board directly to drive accountability and secure long-term funding
75+
Risks Resolved
24mo+
Backlog Cleared
NIST
Framework
Managed Security Programme

End-to-End Managed Cyber Programme: Real Estate Investment Manager

The Challenge

A commercial real estate private debt fund manager with over $5 billion in assets under management had no dedicated security team and no formal cyber programme. With growing regulatory obligations and increasing investor scrutiny, the firm needed to establish a credible, ongoing security capability, without the cost of building an internal function.

How We Helped
  • Designed and stood up a managed cyber security programme from scratch, covering people, process, and technology
  • Developed policies and standards with annual review cycles and OVIC SRPA-aligned risk assessments
  • Established ongoing Security Operations Centre (SOC) and SIEM with monthly vulnerability scanning
  • Delivered incident response plans, BCP tabletop exercises, and annual ISO 27001 assessments
  • Delivered ongoing cyber awareness and training programme across the organisation
$5B+
AUM Protected
ISO 27001
Aligned
24/7
SOC Coverage
Technical Assurance & PCI

Red Team & PCI-DSS Assurance: Transport Technology Platform

The Challenge

A US-based financial services company operating integrated transport management systems across Australia, with over 10 million end consumers, needed to demonstrate PCI-DSS compliance and validate the resilience of its environment against realistic attack scenarios.

How We Helped
  • Conducted a full red team assessment of external-facing and internal network environments using MITRE ATT&CK framework
  • Simulated ransomware, malware, phishing, and identity-based attack scenarios to evaluate incident response maturity
  • Penetration tested IT environment, digital systems, web applications, and network communication channels
  • Demonstrated potential vectors for gaining elevated access to critical systems, including PCI-in-scope environments
  • Reconfigured security solutions and monitoring to improve detection and response capability
10M+
Consumers
PCI-DSS
Compliance
MITRE
ATT&CK
OT / SCADA Security

IT/OT Security Assessment & SCADA Hardening: Regional Water Utility

The Challenge

A regional Victorian water utility, serving 100,000+ residents across multiple water supply and wastewater facilities, operated multiple SCADA systems built on outdated technologies with inadequate segmentation between IT and OT networks. The risk of lateral movement from corporate systems into operational technology was significant and unquantified.

How We Helped
  • Conducted penetration testing of the entire Operational Technology (OT) and SCADA systems environment
  • Tested IT environment, digital systems, web applications, and network communications using MITRE ATT&CK and OWASP Top 10
  • Delivered an IEC 62443-aligned IT/OT network segregation strategy, defining Purdue-based OT zones, OT-DMZ pathways, and controlled inter-zone communications
  • Developed a phased SOC transition and budgeting plan covering SIEM/SOC options, OT visibility tooling, licensing, implementation, and uplift cost
  • Defined an integrated IT/OT SOC strategy, including the target operating model, OT NDR/VM integration, staged onboarding, and future monitoring capability uplift
75K+
Residents
28
Facilities
IEC 62443
Standard
Endpoint & Data Protection

Endpoint Protection Strategy & VPDSF Compliance: Metropolitan Water Utility

The Challenge

A Melbourne-based water utility serving 800,000+ business and residential consumers faced compliance obligations under the Victorian Protective Data Security Framework and had no clear strategy for endpoint protection, data loss prevention, or information classification across a complex environment including SCADA workstations.

How We Helped
  • Performed a framework-based maturity assessment leveraging the NIST Cybersecurity Framework to establish current state
  • Developed a three-year cyber security strategy along with a detailed roadmap, required budget and business case
  • Developed comprehensive technology solution requirements for DLP, malware/ransomware protection, device management, and disk encryption
  • Evaluated and shortlisted top 3 solution providers with indicative commercial estimates
  • Delivered an implementation roadmap and technology options paper aligned to VPDSF obligations
800K+
Consumers
VPDSF
Compliance
SCADA
Environment
Strategy & Penetration Testing

National Cyber Security Strategy & Organisation-Wide Pen Test: Regulatory Body

The Challenge

A national Australian organisation responsible for implementing a major professional registration scheme, with 2,000+ staff, 100+ partner organisations, and over 100,000 online consumers, had a fragmented approach to cyber security. Business leadership was not involved in protecting data, core risks had not been addressed, and obsolete platforms were creating hidden exposure.

How We Helped
  • Developed a three-year cyber security strategy comprising 40+ initiatives, covering tactical and strategic requirements
  • Conducted board and leadership workshops to build executive accountability and secure funding for the programme
  • Delivered domain-specific strategies for SASE architecture, Data Protection, IAM, and Privileged Access Management
  • Conducted an organisation-wide penetration test, internal networks, external, web applications, configuration, and cloud assessment
  • Identified 50+ critical vulnerabilities across in-house applications and cloud platforms
50+
Critical Vulns Found
75
Risks Resolved
100K+
Consumers
International Engagement

$30M Transformation Roadmap: Law Enforcement Agency

The Challenge

A major international law enforcement agency with 17,000+ personnel and 5M+ public-facing consumers was unable to harness emerging technologies due to an inconsistent operating model and inadequate visibility into their security posture. Multiple regulatory frameworks applied, including GDPR, NESA, ISO 27001, NIST CSF, and ENISA.

How We Helped
  • Conducted multi-framework compliance assessment across GDPR, ISO 27001, NIST CSF, CSA CCM, and local regulatory standards
  • Delivered cross-departmental workshops spanning IT, Legal, Operations, Physical Security, Logistics, and Procurement
  • Defined a Cyber Security Strategy and Governance framework, the strategy unveiled a $30M, 4-year transformation roadmap
  • Developed 50+ policies, standards, and procedures as part of the governance artefact library
  • Uncovered 50+ risks in workshops, all recorded in a new enterprise risk register
$30M
Transformation Value
17K+
Personnel
50+
Policies Written

What Our Clients Say

Trusted by security leaders across banking, e-commerce, healthcare, government, and enterprise technology.

"

Their onboarding process was quick and the project was delivered on time. The team demonstrated exceptional skills and professionalism throughout the engagement.

AR
Amith Raj
Global Cyber Security Manager
"

Working with Crysp has been an exceptional experience. Their expertise in undertaking cyber security assessments is second to none, thorough, professional, and genuinely insightful.

CD
Chinmay Dhawale
Senior Penetration Testing Lead
"

Crysp identified numerous critical issues and multiple business logic flaws in our e-commerce portal that had gone undetected. Their findings were detailed, actionable, and clearly prioritised.

SS
Sudhir Sukrutharaj
Head of Fraud
"

Their ability to promptly align resources to accommodate ad hoc pen test requests was impressive. The team provided exceptional support and clear explanation of every finding throughout the process.

KH
Khaled Hawas
Chief Information Officer

The People Behind Crysp

Founded in 2015, Crysp was built on a single conviction: every organisation deserves access to senior cybersecurity expertise, practical, independent, and outcomes-focused.

Dhiresh Salian
Dhiresh Salian
Co-Founder & Director
B.E MBA Strategy INSEAD

With 28+ years spanning IT and cybersecurity across EMEA, APAC, and the Americas, Dhiresh leads Crysp's strategic initiatives, business development, and senior client engagements. He brings the rare ability to translate complex security risk into board-level language that drives investment and accountability.

Formerly: Accenture · Microsoft · Motorola · Mashreq Bank

Andy Viswanath
Andy Viswanath
Co-Founder & Director
MS-IS Wireless Security Griffith Uni

Andy brings 20+ years of deep cybersecurity and risk management expertise, with a track record of building and scaling security practices across the Asia-Pacific region. He leads practice growth, stakeholder management, and engagement delivery, ensuring every client gets senior oversight from start to finish.

Formerly: Deloitte · Moore Stephens · Accenture

Brett Thomas
Brett Thomas
Senior Business Development Manager
15+ Years ANZ Markets

Brett leads client acquisition and partnership growth across Australia and New Zealand, bringing 15+ years of cybersecurity sales leadership. He helps organisations navigate the market, match the right services to their needs, and build long-term advisory relationships grounded in trust and measurable outcomes.

Formerly: Symantec · CyberCx · Firemon

Client Centricity

Accountability & Commitment

Integrity & Honesty

Passionate & Self-Critical

Let's Secure
Your Business.

Whether you need a rapid assessment or a long-term security partner, our team responds within one business day.

Email
contact@cryspconsulting.com
Headquarters
Level 6, HWT Tower
40 City Road, Southbank VIC 3006
Response Time
Within 1 Business Day

Global Offices

Melbourne Singapore Mumbai Dubai San Francisco

Australian Made.
Globally Delivered.

Local cybersecurity expertise supporting clients across Australia, Asia, the Middle East and North America — with the depth to operate wherever your business does.

⬤ Melbourne HQ Singapore Mumbai Dubai San Francisco
Crysp global office locations