ABOUT INSICON Cyber
Finalists in the Australian Cyber Awards 2026
Winner of the 2025 Benchmark Tech Partner Security Awards
Retail Security Partner for 2025
We’re proud to announce that Insicon Cyber has won the 2025 Techpartner.news Security Benchmark Awards in the Retail Sector category.
The Benchmark Security Awards powered by iTnews and techpartner.news is a conference and awards program celebrating leadership in cyber security from a cross section of Australian business, including end users and tech partners.
About Insicon Cyber
Founded in 2013, Insicon Cyber is a trusted, leading cybersecurity advisory and managed services firm serving mid-market organisations across Australia and New Zealand. We work with boards, executives, and security teams in regulated sectors including financial services, aged care, healthcare, and government.
We are ISO 27001 certified, hold Australian Government Protective Security Policy Framework clearances at Baseline and Negative Vetting 1 levels, and operate as a NSW Government SCM0020 prequalified ICT services provider. Our technology partnerships with Google Cloud, Stellar Cyber, SentinelOne, TrendAI, F5, and KnowBe4 underpin our managed security capabilities.
We operate from North Sydney with full Australian data sovereignty and 24/7 trans-Tasman coverage across Australia and New Zealand.
Why We Exist
When Matt Miller and Greg Bunt co-founded Insicon Cyber in 2013, they identified a problem that remains just as relevant today. Enterprise-grade cybersecurity leadership, the kind that connects boardroom strategy with operational security, was accessible only to the largest organisations. Mid-market organisations in regulated sectors were left to navigate an increasingly complex and high-stakes threat landscape without the resources, expertise, or guidance available to their larger counterparts.
That imbalance was not acceptable. And it was not inevitable.
The founding vision of Insicon Cyber was to democratise cybersecurity. To make the quality of cyber leadership, strategic advisory, compliance management, and security operations that large enterprises take for granted accessible to every organisation, regardless of size. To ensure that a financial services firm with 200 employees, an aged care provider managing sensitive client data, or a healthcare organisation navigating regulatory change could access the same depth of expertise and operational capability as organisations ten times their size.
That vision has shaped every decision we have made since. It shapes how we structure our services, how we price our engagements, and how we build our team. It is why we lead with advisory before technology. It is why we integrate strategy and operations into a single practice rather than selling point solutions. And it is why our clients are mid-market organisations in regulated sectors, not the large enterprises that already have the resources to protect themselves.
Cybersecurity should not be a privilege. We are here to make sure it is not.
What We Do
Our practice spans five interconnected capability areas: board and executive advisory, fractional CISO leadership, AI security and governance, managed security operations, and managed compliance. These are not separate products sold by separate teams. They are integrated capabilities delivered by a single specialist practice that understands your organisation, your sector, and your regulatory environment.
The result is a cyber programme where boardroom governance connects directly with security operations. Where compliance programmes reflect real-world threat intelligence. Where strategy translates into execution rather than sitting in a document that no one acts on.
Board Cyber Advisory
Boards and executives carry personal liability for cyber risk. Most lack the independent, unbiased guidance needed to translate that risk into confident governance decisions. Our Board Cyber Advisory service provides exactly that.
We help leadership teams understand their cyber risk exposure, meet regulatory obligations under APRA CPS 230/234, the Privacy Act, NZISM, and the SOCI Act, and make informed decisions on risk appetite, security investment, and incident response posture. The outcome is a board that leads on cyber rather than reacts to it.
We also conduct a Cyber Security Risk Assessment as an entry point for many engagements, providing a structured analysis of the threats, vulnerabilities, and gaps specific to your organisation, with a clear remediation blueprint prioritised by your risk appetite and regulatory obligations.
CISO-as-a-Service
Mid-market organisations need experienced cyber leadership. Most cannot justify the cost or commitment of a full-time CISO hire. Our CISO-as-a-Service provides fractional Chief Information Security Officer expertise, immediately available and operationally grounded.
Our fractional CISOs lead strategic risk management, security programme development, board-level reporting, vendor oversight, regulatory engagement, and incident response leadership. Organisations get the depth and experience of a seasoned CISO without the overhead of a permanent role, and without the gaps that come from leaving the position vacant.
This service is particularly effective when combined with our Board Cyber Advisory and Managed Compliance capabilities, creating a fully integrated leadership and operational security function.
AI Security and Governance
AI adoption is accelerating across financial services, aged care, healthcare, and government. Regulators in Australia and New Zealand are responding. ASIC, APRA, and the NCSC have all signalled that AI governance is a board-level obligation, not a technology consideration. Organisations that cannot demonstrate secure, governed AI systems face growing regulatory and reputational exposure.
Our AI Security and Governance practice helps organisations build trustworthy AI systems through three integrated services. F5-powered AI Assurance tests and validates AI model security before and after deployment. ISO 42001 AI governance framework implementation establishes organisational controls over AI development, deployment, and use. Managed AI compliance ensures systems remain secure and compliant as they evolve and as regulatory expectations tighten.
Secure AI. Governed AI. Compliant AI.
Managed Security Services and Adaptive SOC
Building and maintaining an internal security operations capability is beyond the resource reach of most mid-market organisations. Our Managed Security Services provide enterprise-grade protection without the overhead of building it yourself.
Our Google SecOps-powered Adaptive SOC (aSOC) delivers 24/7 threat detection, monitoring, incident response, and proactive threat hunting across your infrastructure. Powered by Stellar Cyber for extended detection and response, SentinelOne for endpoint protection, and TrendAI Vision One for advanced threat intelligence, our MSSP provides continuous protection with full Australian data sovereignty.
Unlike traditional MSSPs focused purely on alert triage, our aSOC team understands your business context, regulatory environment, and operational constraints. Security events are assessed against your specific risk profile, not generic playbooks.
We also provide Managed Detection and Response (MDR), Managed SIEM, Managed Autonomous Red Teaming, and Managed IT Services.
Managed Compliance
Compliance is not a project with a finish line. It is an ongoing programme that must evolve alongside your business, the threat landscape, and tightening regulatory expectations. Treating it as a one-time engagement creates a false sense of security and leaves organisations exposed as controls become stale.
We deliver compliance as a managed, continuously monitored service. Our Managed Compliance practice covers Essential Eight maturity assessment and hardening, ISO 27001 implementation and continual improvement, ISO 42001 AI governance frameworks, and NZISM compliance for New Zealand organisations. Controls are monitored, maintained, and adjusted as regulations and threats evolve.
Tabletop and Cyber Simulation Exercises
Cyber resilience is built through practice, not policy. A response plan that has never been tested is a plan that will fail when it matters most. Our tabletop exercises and cyber simulations stress-test your incident response capability under realistic conditions, surface gaps in planning and decision making, and prepare boards, executives, and operational teams to respond with confidence under pressure.
We also assist organisations in strengthening business continuity planning by stress-testing relevant scenarios alongside legal, insurance, and operational stakeholders, ensuring your BCP reflects the realities of a cyber incident, not just a theoretical framework.
Why Choose Insicon Cyber
There is no shortage of cybersecurity vendors. What is scarce is a partner that combines genuine strategic advisory expertise with operational security capability, that understands the regulatory environment your organisation operates in, and that is genuinely committed to making enterprise-grade cyber leadership accessible to mid-market organisations. That is what Insicon Cyber offers.
Democratising Cybersecurity for Mid-Market Organisations
Large enterprises have always had access to the best cyber leadership, the most sophisticated security operations, and the deepest compliance expertise. Mid-market organisations in regulated sectors have historically been left to manage with less. We founded Insicon Cyber specifically to change that.
Our services are designed and priced to make enterprise-grade cyber advisory, managed compliance, and 24/7 security operations accessible to organisations that need them but have not previously been able to access them. Cybersecurity should not be a privilege of scale. We are here to make sure it is not.
Integrated Strategy and Operations
Most cybersecurity providers operate in silos. Advisory firms give strategic guidance but do not run security operations. MSSPs monitor and respond but do not engage at board level. Compliance specialists certify frameworks but do not connect them to operational reality.
Insicon Cyber operates as a single integrated practice. Your fractional CISO, your compliance manager, your SOC analyst, and your board advisor all understand your organisation, your sector, and your current risk profile. They coordinate continuously. Strategy informs operations. Operations informs strategy. The result is a cyber programme that actually works rather than one that looks good on paper.
Deep Regulated Sector Expertise
Generic cybersecurity advice rarely translates into effective risk management for organisations operating in regulated environments. The compliance obligations, threat landscapes, and risk profiles of financial services, aged care, healthcare, and government organisations are specific. The advice and operations serving them should be too.
Our team has deep, direct experience in these sectors. We understand APRA CPS 230/234, the Privacy Act, the SOCI Act, NZISM, and Essential Eight not as frameworks to be read but as regulatory environments we navigate with our clients every day. That depth of sector knowledge shapes everything from the advice we give boards to the way we configure and operate our aSOC.
Trans-Tasman Coverage and Australian Data Sovereignty
We operate across Australia and New Zealand as a single integrated practice, not as two separate offerings with a flag planted in each country. Our 24/7 aSOC provides continuous coverage across both jurisdictions. Our advisory and compliance teams understand both regulatory environments. Our clients receive consistent service quality whether they operate in Sydney, Auckland, or across both markets.
All customer data, security logs, and threat intelligence processed through our managed services remain within Australia. For organisations with data sovereignty obligations, regulatory requirements, or board-level commitments to Australian data residency, this is not a minor point. It is a fundamental requirement that we meet as standard.
Accessible Enterprise-Grade Expertise
Through our fractional CISO, managed compliance, and MSSP models, we make the depth of expertise typically reserved for large enterprises available to organisations that do not have the budget or scale for full-time internal teams. You do not need to build a security operations centre to have one. You do not need to hire a full-time CISO to have one. And you do not need to build an internal compliance function to maintain a rigorous, continuously monitored compliance programme.
We provide all of this as a managed service, scaled to your organisation's needs, and committed to outcomes rather than headcount.
Proven, Recognised, and Awarded
We hold ISO 27001 certification as an organisation, operate as a Google Cloud Partner, and hold Australian Government Protective Security Policy Framework clearances at Baseline and Negative Vetting 1 levels. We are a NSW Government SCM0020 prequalified ICT services provider.
We won Retail Cyber Security Partner of the Year at the 2025 Benchmark Security Awards (iTnews/techpartner.news) and are finalists in two categories at the 2026 Australian Cyber Awards: CISO of the Year and Cyber Consulting Business of the Year - SME. These recognitions reflect the quality and consistency of outcomes we deliver for our clients, not marketing claims.
Our Credentials
Insicon Cyber holds ISO 27001 certification and Australian Government Protective Security Policy Framework clearances at Baseline and Negative Vetting 1 levels. We are a NSW Government SCM0020 prequalified ICT services provider and a Google Cloud Partner.
Our team holds individual certifications including CISSP, OSCP, SABSA Chartered Architect, CREST CPSA, Google Cloud Certified, Google SecOps Technical, Generative AI Leader, TrendAI CREM Practitioner, TrendAI SecOps Practitioner, TrendAI Cloud Security Practitioner, ISO 27001 Senior Lead Auditor, ISO 27001 Lead Implementer, ISO 9001 Lead Implementer, BTL2, and Essential Eight practitioner credentials.
Technology partners powering our managed security capabilities include Google Cloud (SecOps), Stellar Cyber, SentinelOne, TrendAI Vision One, F5 (AI Assurance), and KnowBe4.
Winner of Retail Cyber Security Partner of the Year at the 2025 Benchmark Security Awards (iTnews/techpartner.news). Finalists in two categories at the 2026 Australian Cyber Awards: CISO of the Year (Matt Miller) and Cyber Consulting Business of the Year - SME (Insicon Cyber).
Insicon Cyber Founders
Insicon Cyber's founders remain at the heart of our operations, bringing their deep expertise to every client engagement, while our growing team of talented cybersecurity professionals extends our capabilities, ensuring we deliver the perfect balance of seasoned leadership and fresh perspectives to protect your business.
Matt Miller
Co-Founder and CEO
Matt Miller is a seasoned cybersecurity expert and a business-savvy technologist, dedicated to advocating for the critical importance of cybersecurity knowledge in the boardrooms of Australian organisations. With a unique ability to bridge the gap between executive leadership and technical teams, Matt ensures seamless communication across all levels of an organisation. His expertise fosters alignment among diverse teams, functions, and leadership, driving cohesive strategies and solutions.
Drawing from over 25 years of industry experience, Matt also serves as fractional Chief Information Security Officer (CISO) for large-scale enterprises in sectors such as online retail, financial services, and technology. This extensive hands-on experience informs his deep understanding of ICT service management and delivery, risk management, contract negotiation, data and information security, as well as strategic planning. Additionally, Matt is a seasoned ISO 27001 Senior Lead Auditor, further solidifying his credentials in the field.
In 2013, Matt co-founded Insicon Cyber with his business partner, Greg Bunt. Together, they have cultivated a culture of cyber awareness, transforming the way executive leadership and board members perceive cybersecurity. Insicon Cyber's mission is to provide clear, actionable insights that empower organisations to navigate the complex landscape of cyber threats with confidence and clarity.
Greg Bunt
Co-Founder and Director
Greg Bunt is a Co-Founder and Director of Insicon Cyber, a leading cybersecurity advisory firm specialising in governance, risk management, and compliance. With over 25 years of experience in security, risk, and enterprise architecture across Australia and the Asia-Pacific region, Greg is a trusted leader in delivering complex cybersecurity solutions while managing high-performing teams.
Greg’s career has been defined by his passion for solving complex problems and driving meaningful change. He has led large-scale cybersecurity initiatives from start to finish, ensuring they are delivered on time, within budget, and with measurable impact. He has also played a key role in designing cloud migration strategies, embedding security into software development lifecycles, and transitioning businesses away from legacy systems to modern infrastructure. His work is always grounded in global best practices, including ISO 27001, NIST frameworks, and Australia’s Essential Eight.
As an ISO 27001 Senior Lead Implementer, Greg combines his deep technical knowledge with a strategic mindset to help organisations build resilience against cyber threats.
In 2013, Greg co-founded Insicon Cyber with his business partner, Matt Miller. Together, they have cultivated a culture of cyber awareness, transforming the way executive leadership and board members perceive cybersecurity. Insicon's mission is to provide clear, actionable insights that empower organisations to navigate the complex landscape of cyber threats with confidence and clarity.
Insicon Cyber Credentials and Capabilities
Contact Insicon Cyber
Speak to one of our friendly folks