CyberPulse’s cover photo
CyberPulse

CyberPulse

Computer and Network Security

Sydney, New South Wales 845 followers

Your Trusted CyberSecurity Advisors

About us

CyberPulse partners with organisations to operationalise security across the full threat lifecycle, from governance and compliance through to detection, response, and continuous testing. We deliver outcome-based services across Governance, Risk and Compliance (GRC), strategic advisory, 24x7 Managed Detection and Response (MDR), incident response, security validation, threat hunting, penetration testing, red/purple teaming, and staff augmentation. Whether the need is proactive uplift or urgent remediation, we help clients embed resilience, maintain compliance, and reduce exposure across hybrid environments. Founded by award-winning CISOs and cyber leaders from some of Australia’s most complex environments, our team brings deep domain experience across ASX 100, critical infrastructure, financial services, digital-native and government organisations. Our delivery model is simple. We don’t track hours. We commit to outcomes. And we don’t consider an engagement complete until the agreed objectives are achieved with full client satisfaction. Security is not static. Neither is your business. CyberPulse helps align your security posture to both risk and strategy, supporting you through the full arc of maturity. What sets us apart: • End-to-end services across advisory, operations and validation • Fixed-price delivery and outcome-backed engagements • Deep experience across compliance frameworks and threat mitigation • Executive-ready reporting, backed by real-world expertise • Full lifecycle support from strategy to staffing We exist to simplify complexity, accelerate readiness, and ensure our clients are always prepared, resilient and secure.

Website
https://cyberpulse.com.au
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Sydney, New South Wales
Type
Privately Held
Founded
2020
Specialties
Cyber Security and Advisory, PCI-DSS, ISO 27001:2013, ASD Essential 8, CISO as a service, Security Strategy, Security Maturity assessment, Security Road Map, Penetration Testing & Vulnerability Assessment, Governance, Risk & Compliance (GRC), Cloud Security, Cloud Security Access Broker (CASB), Security Policies & Procedures, AWS security assessment, Security Architecture, Email security and DMARC, Security Awareness, and Patching and Vulnerability management

Locations

Employees at CyberPulse

Updates

  • Many Australian organisations are covered by the Security of Critical Infrastructure Act and do not realise it, because the definition of critical infrastructure is broader than most people assume. The SOCI Act now spans eleven sectors, including energy, healthcare, food and grocery, data storage and processing, and financial services. If your organisation owns or operates an asset in a covered sector, obligations may apply. In plain terms, the Act can require you to: - Register the assets you own or operate. - Report cyber incidents to the Australian Signals Directorate within set timeframes. - Maintain a risk management programme covering cyber, physical, personnel, and supply-chain hazards. The first step is not a control. It is a determination: does the Act apply to us, and if so, for which assets and which obligations? Many organisations skip that question and either over-invest or, more often, miss a duty they did not know they had. Our guide to the Security of Critical Infrastructure Act is linked below. Talk to us if you are unsure whether your organisation is captured. Resources Full guide: https://lnkd.in/gZgzmtGB Free framework decision guide: https://lnkd.in/eXcBHjrM Book a 30-minute call: https://lnkd.in/eMKw4FNX #SOCI #CriticalInfrastructure #Compliance

    • No alternative text description for this image
  • CyberPulse reposted this

    Security has always been a priority at Meshed. Achieving ISO 27001:2022 was an important milestone, but it's only one part of our ongoing commitment to protecting the data our customers trust us with every day. We value our partnership with CyberPulse and their expertise in supporting our security journey—from ISO certification to annual penetration testing and ongoing security improvements. It's been a rewarding journey together, and we look forward to continuing to strengthen our security programme in the years ahead. #ISO27001 #CyberSecurity #EdTech #InformationSecurity #Compliance

    View organization page for CyberPulse

    845 followers

    Thank you to Pramesh Khadka and the MESHED Group team for allowing us to share their story.   Meshed builds student management and admissions software used by more than 40% of Australia's private higher education sector. Their platforms cover the full student lifecycle, from admissions and enrolments through to compliance, finance, reporting and graduation, alongside reporting obligations under TEQSA, ASQA, TCSI and PRISMS.   As Meshed grew and moved into new institution types, enterprise clients and university partners started asking for documented assurance that student data was protected to a recognised standard. Meshed was clear from the outset that certification had to reflect real security capability rather than serve as a sales artefact.   CyberPulse delivered the ISO 27001:2022 programme end to end: gap assessment, ISMS design, process improvement and coordination of the certification audit. Meshed certified with no major nonconformities.   That work has continued. Meshed now runs an annual penetration testing programme across their web applications, APIs and infrastructure, rescoped each year to reflect platform changes, and we support their surveillance audits and internal review cycles.   A long standing partnership we value, and a team that treats security as a capability rather than a document.   Read the full case study in the comments.   #ISO27001 #EdTech #CyberSecurity #PenetrationTesting

  • Health-ISAC published an advisory on 24 July 2026 warning of an increase in successful ShinyHunters attacks against healthcare and medical technology organisations. There is no software exploit in this one. The attackers ring the service desk, impersonate a staff member, and talk an agent into resetting a password or re-enrolling multi-factor authentication. That hands them a single sign-on account. From there they work through whatever is connected to it: Microsoft 365, SharePoint, Salesforce, Slack, Atlassian, Dropbox. Data is copied out, then the extortion demand follows. Australian readers will recognise the pattern. The same group used the same voice phishing method against Qantas in 2025. Two things follow for anyone running a lean IT function. Your identity provider is now a Tier 0 asset and should be governed like a domain controller. And your helpdesk reset procedure is a security control, whether or not anyone has ever written it down as one. The fix is unglamorous. No password or MFA reset completed on the same call. Out-of-band verification of the person asking. Phishing-resistant MFA on privileged and executive accounts. Alerting on new OAuth grants and bulk downloads. Resources Health-ISAC advisory: https://lnkd.in/dQPuVxS4 Book a 30-minute call: https://lnkd.in/eMKw4FNX #cybersecurity #healthcare #identitysecurity #Australia

    • No alternative text description for this image
  • Ask a board where their biggest cyber risk sits and most point inward, at their own systems. Increasingly, it sits with their suppliers. Modern organisations run on a web of third parties: software vendors, managed service providers, payroll, cloud platforms. Each one is a door into your data and operations, and you inherit the weakest link. The Australian Signals Directorate has repeatedly flagged supply-chain and managed-service-provider compromise as a live threat to Australian organisations (ASD Annual Cyber Threat Report 2023-24). In assessments we see the same pattern: careful control of internal systems, and very little assurance over the vendors holding the same data. Contracts are signed, then never revisited. A workable third-party risk programme does not need to be heavy: - Know who your critical suppliers are and what data they touch. - Ask for evidence, not promises: certifications, recent testing, breach notification terms. - Tier vendors by impact, and spend your attention where a failure would actually hurt. You cannot outsource the risk, even when you outsource the service. Our guide to supply-chain risk management is linked below. Resources Full guide: https://lnkd.in/ebCxfp2z Free vendor risk toolkit: https://lnkd.in/e-RcvnYM Book a 30-minute call: https://lnkd.in/eMKw4FNX #ThirdPartyRisk #SupplyChainSecurity #CyberRisk

    • No alternative text description for this image
  • Thank you to Pramesh Khadka and the MESHED Group team for allowing us to share their story.   Meshed builds student management and admissions software used by more than 40% of Australia's private higher education sector. Their platforms cover the full student lifecycle, from admissions and enrolments through to compliance, finance, reporting and graduation, alongside reporting obligations under TEQSA, ASQA, TCSI and PRISMS.   As Meshed grew and moved into new institution types, enterprise clients and university partners started asking for documented assurance that student data was protected to a recognised standard. Meshed was clear from the outset that certification had to reflect real security capability rather than serve as a sales artefact.   CyberPulse delivered the ISO 27001:2022 programme end to end: gap assessment, ISMS design, process improvement and coordination of the certification audit. Meshed certified with no major nonconformities.   That work has continued. Meshed now runs an annual penetration testing programme across their web applications, APIs and infrastructure, rescoped each year to reflect platform changes, and we support their surveillance audits and internal review cycles.   A long standing partnership we value, and a team that treats security as a capability rather than a document.   Read the full case study in the comments.   #ISO27001 #EdTech #CyberSecurity #PenetrationTesting

  • A medium-severity vulnerability from February is now confirmed as exploited in the wild. That combination is worth a look. CISA added CVE-2025-68686 to its Known Exploited Vulnerabilities catalog on 27 July 2026. The flaw is in Fortinet FortiOS. It lets a remote, unauthenticated attacker bypass the patch Fortinet built to stop a symbolic link persistence trick used in earlier FortiGate compromises. Fortinet published advisory FG-IR-25-934 on 10 February 2026 and rates it medium severity. Devices without SSL-VPN enabled are not affected. This is a persistence problem, not an initial-access one. Exploitation requires the device to have been compromised already at filesystem level. So if a FortiGate was breached at some point and then patched, the patch may not have removed the attacker's foothold. A medium score from February is also exactly the finding that gets deferred in a busy patch queue. A severity number is not a risk assessment. The ACSC issued a critical alert on 18 June 2026 about credential exposure affecting Fortinet firewalls and VPN gateways, so these devices are under real pressure here. Affected versions span the 6.4, 7.0, 7.2, 7.4 and 7.6 branches. Fixes are 7.6.2 or above and 7.4.7 or above, and 7.2, 7.0 and 6.4 need a migration. If you run FortiGate SSL-VPN, upgrade, then look for signs of prior compromise. Resources Fortinet advisory: https://lnkd.in/gJEJ4CzX Book a 30-minute call: https://lnkd.in/eMKw4FNX #cybersecurity #fortinet #vulnerabilitymanagement #Australia

    • No alternative text description for this image
  • Your staff have learned to be suspicious of email. Attackers know it, so a growing share of social engineering has moved to the phone. Vishing, or voice phishing, is a call that impersonates someone your team trusts: the IT helpdesk, a supplier, a senior executive, sometimes the bank. The goal is the same as any phishing attempt, to get a credential, a payment, or a one-time code, but a live human voice applies pressure that an email cannot. The tactics that work are familiar once you name them: - Urgency: a problem that must be fixed in the next five minutes. - Authority: a caller who sounds senior and expects compliance. - A plausible pretext: a real project, a real invoice, a real name lifted from your website or LinkedIn. The defence is process, not instinct. Verify any request for payment or credentials through a separate, known channel. Give finance and helpdesk teams explicit permission to slow down and call back. Our guide to identifying and defending against voice scams is linked below. Talk to us about awareness training that covers the phone, not just the inbox. Resources Full guide: https://lnkd.in/eSRMB8h5 Book a 30-minute call: https://lnkd.in/eMKw4FNX #CyberSecurity #SocialEngineering #Vishing

    • No alternative text description for this image
  • "Should we get ISO 27001 or SOC 2?" is one of the most common questions we hear. It usually starts from a false assumption: that one is simply the better certificate. They are not ranked. They answer different questions, for different audiences. ISO/IEC 27001 is an international management-system standard. It proves you run an information security programme on purpose, with governance and continuous improvement behind it. It travels well internationally and suits organisations that want a durable framework. SOC 2 is an attestation report, produced by an auditor, describing how your controls operate against the Trust Services Criteria. North American buyers and SaaS procurement teams often ask for it by name. So the real question is not which is better. It is: who is asking, what will they accept, and where are you selling? A UK or EU enterprise deal points one way. A US SaaS contract often points the other. Plenty of Australian organisations end up needing both, and the work overlaps more than people expect. Our comparison of the two, and how to choose, is linked below. Resources Full guide: https://lnkd.in/enC83JB9 Free framework decision guide: https://lnkd.in/eXcBHjrM Book a 30-minute call: https://lnkd.in/eMKw4FNX #ISO27001 #SOC2 #Compliance

    • No alternative text description for this image

Similar pages

Browse jobs