Industries

Regulated, distributed, or simply out of patience

Eighteen industries, and we are not a single-vertical specialist in any of them. What our clients share is an obligation they cannot delegate — to a regulator, an insurer, a client's risk team, or the people whose records they hold.

The full list

Where our clients actually come from

Ordered roughly by how often we are asked. Four of them carry a longer write-up further down the page — the rest we are happy to talk through on a call.

Professional services

Legal, accounting, financial advice and consulting. Client confidentiality is the product, and trust accounts make you a standing target for payment redirection fraud.

In depth

Health & allied health

General practice, dental, specialist clinics, physiotherapy and psychology. Health records are sensitive information under the Privacy Act, and clinical systems cannot be offline mid-session.

In depth

Aged care & disability

Residential aged care, home care and NDIS providers. A rostered casual workforce on shared devices, holding some of the most sensitive personal records anyone keeps.

Construction & trades

Builders, subcontractors and project managers. Devices get commissioned on sites with no signal, and drawings and variations end up moving through personal accounts.

In depth

Engineering & architecture

CAD, BIM and Revit files large enough to punish a thin link and defeat a naive backup schedule. Intellectual property that can walk out with a departing engineer.

Government & councils

Local government and agencies carrying Essential Eight obligations, procurement rules and public-record retention that has to be implemented in the systems, not just written into a policy.

In depth

Not-for-profit & community

Charities, peak bodies and member organisations. Volunteer turnover, grant-funded systems that arrive with no operating budget, and non-profit licensing most have never claimed.

In depth

Education & training

Independent schools, RTOs and early learning. Student data, BYO devices, and a network shared with people who are actively trying to get around it.

Financial services

Brokers, planners, funds and insurance. Client money moves on emailed instruction, which makes business email compromise your single largest exposure by a wide margin.

Manufacturing & industrial

The IT and OT boundary. Production systems running operating systems that cannot simply be patched, and downtime measured in lost output per hour.

Transport, logistics & warehousing

Rugged scanners, fleet telematics and warehouse management. Devices spend days out of coverage and still have to come back compliant and enrolled.

Wholesale & distribution

ERP and EDI links running into your trading partners, where an outage stops other people's businesses too, and pricing data is worth stealing.

Retail & hospitality

Multi-site point of sale, high seasonal staff turnover, card data obligations, and at least one venue where the server lives under the counter.

Real estate & property

Agencies, strata and property management. Trust accounts, fast staff turnover, and settlement payment redirection fraud that targets this sector specifically.

Mining, energy & resources

Remote sites on satellite links, contractor identities that have to be granted and revoked quickly, and critical infrastructure obligations where they apply.

Agriculture & agribusiness

Rural connectivity, a seasonal workforce that arrives and leaves in waves, and increasingly connected equipment that nobody has put on an asset register.

Media, marketing & creative

Very large files, freelancers who need access for six weeks and then must lose it, and client assets held under contractual confidentiality.

Sport, clubs & recreation

Licensed and gaming venues with member databases, regulator obligations, and technology decisions made by a volunteer committee.

Not listed? Most of what we do is sector-neutral. Tell us what you are obliged to protect and who asks you to prove it, and we will give you an honest answer about fit.

In depth · 01

Professional services

Legal, accounting, financial advice, architecture and consulting. Client confidentiality is the product, and an hour of downtime is an hour nobody can bill.

Two colleagues working together at a laptop
Dual monitors, document management, and a matter that closes today.

What we see most

  • Practice management and document management systems with no tested restore path.
  • Trust account and payment processes exposed to business email compromise.
  • Partners with local administrator rights and MFA exemptions dating back years.
  • Client due-diligence questionnaires answered differently by different people.

What we do about it

  • Payment verification controls and impersonation protection tuned to partner names.
  • Restore testing on the practice management database, quarterly, with a measured RTO.
  • Privileged access separated, with a managed elevation path that does not slow anyone down.
  • A single maintained due-diligence response pack, so a tender takes hours instead of a fortnight.
In depth · 02

Health & allied health

General practice, dental, specialist clinics, physiotherapy and psychology. You hold health records, which the Privacy Act treats as sensitive information — and clinical systems that cannot be offline during a session.

Clinic staff working at a reception desk
Reception, practice software, and a waiting room that does not wait.

What we see most

  • Shared clinical logins, because individual accounts were slower at the front desk.
  • Practice software on a server that has not been patched since the vendor last visited.
  • No documented breach assessment procedure, despite mandatory notification obligations.
  • Backups running, restores never attempted.

What we do about it

  • Individual identities with fast sign-in, so security and reception speed stop competing.
  • Vendor-coordinated patching for clinical systems, with agreed windows outside sessions.
  • A written NDB breach assessment procedure, tested in an annual tabletop exercise.
  • Restore testing on clinical data with an RTO the practice has actually agreed to.
In depth · 03

Construction & field services

Builders, trades, logistics, utilities and field maintenance. Your workforce is distributed by definition, often on shared or rugged devices, connecting from sites with no fixed infrastructure.

A site supervisor in hi-vis using a rugged tablet on a construction site
Site office, rugged tablet, and connectivity that comes and goes.

What we see most

  • Devices that never enrolled because they were commissioned on a site with no signal.
  • Shared tablets where sign-out does not clear the previous person's session.
  • Project files on personal cloud accounts, because the sanctioned path was too slow.
  • An asset register that lost touch with reality three refresh cycles ago.

What we do about it

  • Staged provisioning before dispatch and enrolment profiles that tolerate long offline periods.
  • Shared device mode, so sign-out genuinely ends the session.
  • Mobile access to project data that is faster than the workaround, which is the only way it wins.
  • A reconciled asset register, with device location and assignment kept current.
In depth · 04

Government & not-for-profit

Local councils, agencies, community services, peak bodies and charities. Procurement rules, public accountability, constrained budgets, and genuine assurance requirements — usually all at once.

Parliament House, Canberra, with the flag flying against a clear sky
Public accountability, and a budget that has to survive a council meeting.

What we see most

  • Essential Eight obligations without the budget or headcount to reach the target level.
  • Grant-funded systems with no ongoing operational funding attached.
  • Volunteer and casual access that is granted quickly and revoked slowly.
  • Records management obligations met on paper and not in the systems.

What we do about it

  • A maturity uplift plan sequenced to fit funding cycles, with the cost of each level stated.
  • Non-profit licensing applied where you qualify — many organisations never claim it.
  • Automated joiner, mover and leaver processes so revocation is not a manual memory test.
  • Retention and disposition policy implemented in Microsoft 365, not just written down.
  • Security cleared personnel available where an engagement requires them.
Common ground

What every one of these sectors has in common

Different regulators, different systems, the same four failures. We look for these first regardless of what industry you are in.

  • Identity is the front door, and it is usually the least defended thing in the environment.
  • Backups exist; restores are theoretical. The gap between those two is where a bad week becomes a bad year.
  • Nobody owns patching for the third-party applications that are not Windows and not Microsoft 365.
  • The asset register and reality diverged at some point nobody can identify, and everything downstream inherits the error.

Not in one of these four

Most of what we do is sector-neutral. Tell us what you are obliged to protect and who asks you to prove it, and we will tell you honestly whether we are the right fit.