CyberPulse’s cover photo
CyberPulse

CyberPulse

Computer and Network Security

Sydney, New South Wales 883 followers

Your Trusted CyberSecurity Advisors

About us

CyberPulse partners with organisations to operationalise security across the full threat lifecycle, from governance and compliance through to detection, response, and continuous testing. We deliver outcome-based services across Governance, Risk and Compliance (GRC), strategic advisory, 24x7 Managed Detection and Response (MDR), incident response, security validation, threat hunting, penetration testing, red/purple teaming, and staff augmentation. Whether the need is proactive uplift or urgent remediation, we help clients embed resilience, maintain compliance, and reduce exposure across hybrid environments. Founded by award-winning CISOs and cyber leaders from some of Australia’s most complex environments, our team brings deep domain experience across ASX 100, critical infrastructure, financial services, digital-native and government organisations. Our delivery model is simple. We don’t track hours. We commit to outcomes. And we don’t consider an engagement complete until the agreed objectives are achieved with full client satisfaction. Security is not static. Neither is your business. CyberPulse helps align your security posture to both risk and strategy, supporting you through the full arc of maturity. What sets us apart: • End-to-end services across advisory, operations and validation • Fixed-price delivery and outcome-backed engagements • Deep experience across compliance frameworks and threat mitigation • Executive-ready reporting, backed by real-world expertise • Full lifecycle support from strategy to staffing We exist to simplify complexity, accelerate readiness, and ensure our clients are always prepared, resilient and secure.

Website
https://cyberpulse.com.au
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Sydney, New South Wales
Type
Privately Held
Founded
2020
Specialties
Cyber Security and Advisory, PCI-DSS, ISO 27001:2013, ASD Essential 8, CISO as a service, Security Strategy, Security Maturity assessment, Security Road Map, Penetration Testing & Vulnerability Assessment, Governance, Risk & Compliance (GRC), Cloud Security, Cloud Security Access Broker (CASB), Security Policies & Procedures, AWS security assessment, Security Architecture, Email security and DMARC, Security Awareness, and Patching and Vulnerability management

Employees at CyberPulse

View 8 employees at CyberPulse

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

See all employees

Locations

Updates

  • The FBI and the US Secret Service published a joint advisory on 6 October 2026 (JCSA-20261006-01) warning that FortiBleed, a credential-compromise campaign against internet-facing Fortinet FortiGate firewalls and SSL VPN gateways, is still active. The advisory cites more than 86,644 compromised devices across 194 countries. This is not a new vulnerability, so a patch does not close it. The operators use leaked and reused passwords, password spraying and offline cracking of legacy SHA-256 password hashes, then create their own admin accounts on the firewall. The advisory says some victims have been locked out of their own devices, and that the access is being passed to ransomware affiliates, including INC/Lynx and Payload. For an Australian mid-market organisation with a FortiGate SSL VPN or admin interface reachable from the internet, the steps are: end all admin and VPN sessions and reset those passwords; require phishing-resistant MFA on remote access and admin accounts; take admin access off the internet; remove admin accounts or API keys nobody recognises; and confirm admin credentials are stored with PBKDF2 (FortiOS 7.2.11 and later). Resources FBI and US Secret Service joint advisory JCSA-20261006-01 (6 October 2026): https://lnkd.in/eUE_MHSX Book a 30-minute call: https://lnkd.in/eWXjkgnB #cybersecurity #Fortinet #FortiGate #Australia

    • No alternative text description for this image
  • Security awareness gets bought as a product. The evidence says it only works as a staffed programme. The SANS 2025 Security Awareness Report, its tenth edition, drew on responses from more than 2,700 security awareness practitioners across more than 70 countries. Its finding on resourcing is the one worth taking into a budget conversation. A minimum of 2.8 full-time equivalents is needed to shift user behaviour at scale, and four or more FTEs sustained over five to ten years is what it takes to embed a security culture. Most Australian mid-market organisations run this on a fraction of one person, usually somebody in IT with awareness training appended to an already full role. That is enough to complete the annual module and produce a compliance report. It is not enough to change behaviour, which is what the budget was meant to buy. The same report puts social engineering back at the top of the human risk list, with phishing, vishing and smishing now accelerated by deepfake and voice cloning tooling. So the question for the next budget round is not which platform to license. It is who owns this, how much of their week it gets, and which behaviour you expect to be different in a year. Resources Full guide: https://lnkd.in/eFc_CDmW Book a 30-minute call: https://lnkd.in/eMKw4FNX #CyberSecurity #SecurityAwareness #HumanRisk #AustralianBusiness

    • No alternative text description for this image
  • Congratulations to Ebix Australia on achieving ISO/IEC 27001 certification. Most organisations do not fail certification on technology. They fail on scope, evidence and ownership. Ebix got those right, and the result speaks for itself. CyberPulse was proud to support the team.

    Hip hip hooray!!! I am delighted to share that Ebix Australia has successfully achieved ISO/IEC 27001 certification, the internationally recognised standard for Information Security Management Systems (ISMS). It was a monumental collective effort, and we did it!! While the process may have been long and arduous, along the way, we significantly improved our security posture and practices. This achievement reflects our ongoing commitment to protecting sensitive information, managing security risks, and maintaining the highest standards of data security for our customers, partners, and employees. Achieving ISO 27001 certification demonstrates that our people, processes, and technology are aligned to globally recognised best practices for information security. I want to thank all the employees at Ebix Australia for their support, dedication, and hard work in reaching this important milestone, and I look forward to continually strengthening our security posture together. While it may be a cliché, security is a continuous journey rather than a destination. We remain fully committed to delivering the highest standards of trust and protection to our customers and stakeholders. I also want to thank our internal auditor, Dinesh, who helped us along the way, and the leadership of both Philip and Phil Paterson, as well as the tireless efforts of the capable team. Swee Yeo, Omkar, and Tania, you deserve a special mention. Lastly, to our compliance platform partners Vanta thank you for all your support and a wonderful platform that makes collecting evidence at a single location very easy.

  • View organization page for CyberPulse

    883 followers

    🎉 🎉 🎉 Congratulations to the Sydney Roosters, 2026 NRL and NRLW Premiers! Two grand finals at Accor Stadium on the same day. Two titles! NRL: the Roosters came from 12–0 down to beat the Newcastle Knights 19–18, with a Daly Cherry-Evans field goal the difference. NRLW: a 30–6 win over the Brisbane Broncos, built on a 26–0 half-time lead, the largest in NRLW grand final history. A third NRLW premiership for the club, with Brydie Parker scoring a hat-trick. Proud to work with the Tricolours. #NRL #NRLW #NRLGrandFinal #SydneyRoosters #EastsToWin #CyberPulse

  • Citrix published security bulletin CTX697174 on 3 October 2026 for CVE-2026-88779, a memory overflow in NetScaler ADC and NetScaler Gateway that an unauthenticated attacker can trigger over the network to cause a denial of service (CVSS v4.0 8.7). Citrix says it has observed targeted attacks on unmitigated deployments, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 4 October. The flaw only applies where NetScaler is configured as a SAML service provider or SAML identity provider. Check the configuration for "add authentication samlAction" or "add authentication samlIdPProfile". What this means for an Australian mid-market organisation: patching NetScaler for the late-September zero-days does not cover this one. The builds released then (14.1-73.37 and 13.1-64.23) sit below the new fixed versions, so Citrix is asking customers to upgrade again. Where SAML on NetScaler sits in front of remote access or single sign-on, a crash stops staff logging in through it. The action: upgrade to 14.1-73.41 or 13.1-64.28 (FIPS builds: 14.1-73.41 FIPS or 13.1-37.282), then review the appliance for unexplained crashes or restarts. Citrix updates the NetScaler services it manages in the cloud itself. Resources Citrix security bulletin CTX697174 (3 October 2026): https://lnkd.in/gD7EDZRE Book a 30-minute call: https://lnkd.in/ercMd3uM #cybersecurity #Citrix #NetScaler #Australia

    • No alternative text description for this image
  • Microsoft Threat Intelligence reported on 3 October 2026 that a cluster of compromised websites is running a ClickFix campaign with a new delivery step. The sites quietly pre-load a script into the visitor's browser cache, disguised as a PNG image. A fake verification prompt then asks the user to open the Windows Run dialog, paste and press Enter. That short command searches the browser's cache folder, finds the hidden file by its exact size, saves it as a VBScript file and runs it. Later stages go after browser and device credentials and add a scheduled task to persist. Because the payload is already on the device, nothing is downloaded at the moment of infection. Microsoft advises defenders to hunt beyond download events alone. What this means for an Australian mid-market organisation: any staff member who lands on one of these sites is a target, and the credentials saved in a work browser usually open email and business applications. The action: tell staff that a genuine CAPTCHA never asks them to paste a command into Run, Terminal or PowerShell. On managed Windows devices, enable PowerShell script-block logging, review application control for script hosts, and check Run dialog history and new scheduled tasks. Resources Microsoft Threat Intelligence (3 October 2026): https://lnkd.in/eMazu2G6 Book a 30-minute call: https://lnkd.in/ektRGNBJ #cybersecurity #ClickFix #phishing #Australia

    • No alternative text description for this image
  • By the time a breach becomes public, the credentials involved have usually been traded for months. That is the shape of credential theft. An employee signs up to an external platform with their work email, that platform is breached, and the login lands in a bulk collection that is sold and resold across criminal marketplaces. Ransomware crews feed the same supply through double extortion, publishing exfiltrated data on leak sites when a ransom goes unpaid. None of it raises an alert inside your organisation, because nothing has happened inside your organisation yet. What makes those credentials valuable is that they are real and the accounts still work. Credential stuffing against your tenant looks like a legitimate sign-in right up until it is not. Two practical moves. Get a baseline. A point-in-time check against known breach data tells you which of your domains and staff already appear in circulation. It is a snapshot rather than monitoring, but it is a real number to work from. Then close what those credentials open. Phishing-resistant multi-factor authentication on every account that matters, and a process that resets an exposed login when it surfaces rather than at the next audit. Continuous monitoring is what turns this from an annual surprise into an alert someone can act on the same week. Resources Full guide: https://lnkd.in/eWjXMVmU Book a 30-minute call: https://lnkd.in/eMKw4FNX #CyberSecurity #ThreatIntelligence #IdentitySecurity #AustralianBusiness

    • No alternative text description for this image
  • Fortinet disclosed a critical flaw in FortiMail on 1 October 2026 and says it has been exploited in the wild. CISA added it to its Known Exploited Vulnerabilities catalogue the same day. CVE-2026-104286 (CVSS 9.8) is a path traversal flaw that lets an unauthenticated attacker write arbitrary files on the appliance using crafted HTTP or HTTPS requests. Affected versions: FortiMail 7.2.0 to 7.2.9, 7.4.0 to 7.4.8, 7.6.0 to 7.6.6 and 8.0.0 to 8.0.1. As at 3 October, Fortinet lists the fixed releases (7.4.9, 7.6.7 and 8.0.2) as upcoming. Branch 7.2 gets no fix; Fortinet's advice is to move to 7.4 or later. Until a fix ships, the workaround is the control. What this means for an Australian mid-market organisation: an email gateway faces the internet by design and handles every inbound message. A compromised gateway sits on your mail flow, not on one laptop. Fortinet's published indicators include an archive account added with a remote destination at an external IP address. The action: turn off the IBE service, or restrict the FortiMail webmail interface to trusted networks. Then check the appliance against Fortinet's indicators of compromise, and patch when the fixed release ships. Resources Fortinet PSIRT advisory FG-IR-26-175 (1 October 2026): https://lnkd.in/eBTduFxs Book a 30-minute call: https://lnkd.in/ecgxgypC #cybersecurity #Fortinet #Australia

    • No alternative text description for this image
  • The 90-day password reset survives in more Australian security policies than almost any other control, and the standard it came from withdrew the advice. NIST Special Publication 800-63B removed mandatory periodic password changes. The reasoning is not that rotation is harmless. It is that forcing it every quarter produces Spring2026, then Summer2026, or the same password reused on a system that does not check. NIST now recommends changing a password when there is evidence of compromise, and not on a calendar. The rest of the current guidance follows the same logic. Length and uniqueness beat arbitrary complexity rules. A long passphrase is stronger and easier to remember than a short password with a symbol bolted on the end. Screen new passwords against known breached and common password lists, so a password already in circulation cannot be set in the first place. Retire knowledge-based questions. A mother's maiden name is not a secret, it is a search. If your policy still mandates a 90-day reset and one symbol, it is enforcing guidance the standards body behind it has since withdrawn. Updating the policy costs nothing and removes a recurring source of weak passwords. Then pair it with phishing-resistant multi-factor authentication, because password quality alone was never going to carry the account. Resources Full guide: https://lnkd.in/ejA5rN-w Book a 30-minute call: https://lnkd.in/eMKw4FNX #CyberSecurity #IdentitySecurity #NIST #AustralianBusiness

    • No alternative text description for this image
  • Most privileged access rollouts do not fail on the technology. They fail on the accounts nobody remembers creating. Service accounts, scheduled tasks and application identities hold standing administrative rights, have no named owner, and sit outside every access review. Rotate one of those credentials without knowing what depends on it and something in production stops working, which is how a privileged access programme earns a reputation for breaking things in its first month. The Verizon 2025 Data Breach Investigations Report found credential abuse was the single leading way breaches began, at 22% of cases. Privileged credentials are that same problem with the most damage attached. Four things worth settling before you shortlist a platform. Discover every privileged account, human and non-human, and map what each service account actually depends on. Rank them by the damage a compromise would do, so the rollout runs in priority order instead of all at once. Name an owner for the platform, the approval path and the access reviews. A tool with no operator quietly falls into disuse. Secure executive sponsorship, because privileged users are senior, busy, and will route around anything slower than the old way. Privileged access management is also the most direct route to the Essential Eight mitigation "restrict administrative privileges". Start with discovery, not procurement. Resources Full guide: https://lnkd.in/eZCrPHBZ Free Essential Eight self-assessment: https://lnkd.in/eKHJdbhv Book a 30-minute call: https://lnkd.in/eMKw4FNX #CyberSecurity #PrivilegedAccess #EssentialEight #AustralianBusiness

    • No alternative text description for this image

Similar pages

Browse jobs