Who We Are

Internationally certified cybersecurity team, built for Australian business.

Our team is trained and certified to international standards — operating under CREST, OWASP, and NIST methodologies — delivering world-class SOC and penetration testing capabilities to Australian businesses at competitive pricing.

We are transparent: our delivery team operates internationally, while our engagement, scoping, and client-facing work is managed from Sydney. This model lets us offer enterprise-grade security at costs that make sense for SMEs.

How we work — specific, not vague

Every engagement follows documented, repeatable methodology aligned to global standards. No black boxes.

Penetration Testing
  • Testing methodology: OWASP Testing Guide & PTES
  • Findings mapped to: MITRE ATT&CK framework
  • Scoring: CVSS v3.1 + OWASP Risk Rating
  • Typical engagement: 1-4 weeks depending on scope
  • Includes: free retest after remediation
View Pentest details →
SOC / Managed Security
  • Coverage: 24/7/365 analyst monitoring
  • SLA — Detection: within 15 minutes of alert generation
  • SLA — Response: within 30 minutes for critical severity
  • Platform: Enterprise SIEM + SOAR included
  • Reporting: monthly executive dashboards
View SOC details →
Compromise Assessment
  • Approach: Hypothesis-driven threat hunting + DFIR
  • Scope: AD, endpoints, network, cloud, identity
  • Typical timeline: 5-10 business days
  • Deliverable: Executive summary + IOC report
  • Includes: remediation guidance & re-validation
View CA details →

What we comply with — and what we're working toward

We believe transparency about current certifications and roadmap builds more trust than vague claims.

Australian Privacy Act 1988

We comply with the Australian Privacy Principles (APPs) in all handling of client data. Client data is stored encrypted at rest, and access is restricted to named engagement personnel only.

ACSC Essential Eight Alignment

All services are designed to help clients meet and mature against the ACSC Essential Eight mitigation strategies — the baseline for Australian government and critical infrastructure entities.

ISO 27001 — In Progress

We are currently implementing an ISO 27001-aligned ISMS. Target certification: [Q3 2025 — update when confirmed]. Our internal security practices already align to the standard.

CREST Accreditation — In Progress

CREST membership application is underway. Our pentesters already hold CREST-recognised individual certifications (OSCP, OSCP, CRTP). Target: [update when confirmed].

Professional Indemnity Insurance

Professional indemnity and public liability insurance coverage: [Policy details — to be added when bound]. Certificate of currency available on request for due diligence.

Items in grey are in progress. We will update this page as certifications are obtained. Transparency is part of our commitment.

See our work before you commit

We'd rather show you than tell you. Download a sample report or read a recent engagement summary.

Sample Pentest Report

Download a redacted penetration test report to see our scoring, structure, and remediation guidance quality.

Coming Soon

Anonymous Case Study

Read how we helped a mid-size Australian [industry] organisation identify and remediate critical vulnerabilities — without disruption.

Coming Soon

Client Testimonials

Hear directly from clients about their experience working with Cyber Harbour. Real feedback, not edited quotes.

Coming Soon

Don't see what you need? Book a call and we'll walk you through our capabilities live.

What Guides Us

Integrity

We operate with complete transparency — about our pricing, our methodology, and what we can and can't do.

Excellence

Every finding has a working proof-of-concept. Every engagement has a senior lead. No juniors unsupervised.

Vigilance

We maintain constant awareness of the evolving threat landscape — and share what we learn through our articles.

Partnership

We're not a vendor — we're your security team extension. Our success is measured by your reduced risk.

Book a free 30-minute consultation

Speak directly with our founder. No sales pitch — just an honest conversation about your current security posture and where the gaps are.

Schedule a Call