CI-ISAC Australia
CI-ISAC Australia is a not-for-profit cyber threat intelligence sharing network that aggregates, enriches, and redistributes MITRE ATT&CK-mapped threat intelligence to 110+ member organisations across all 11 of Australia's SOCI Act critical infrastructure sectors, funded through tiered annual membership fees and government grants.
- Company typePrivate
- Founded2022
- HeadquartersMaroochydore, Australia
- Headcount11–50
- GTM typeB2B
- OfferingServices
What CI-ISAC Australia does
CI-ISAC Australia Ltd is a Queensland-incorporated, not-for-profit public company limited by guarantee (ABN 55 664 445 907) that operates Australia's only sovereign cyber threat intelligence sharing network built exclusively for critical infrastructure. Founded in 2022 by David Sandell (ex-NAB Threat Intelligence) and Scott Flower (ex-FS-ISAC Global Intelligence Officer, ex-ASIO), the organisation serves owners and operators across all 11 critical infrastructure sectors defined under Australia's Security of Critical Infrastructure (SOCI) Act, including energy, healthcare, financial services, communications, government, transport, higher education, data storage, food and grocery, space technology, and water and sewerage.
The platform aggregates member-contributed threat sightings, Australian honeypot intelligence, and global threat feeds, then enriches and redistributes them as MITRE ATT&CK-mapped advisories, vulnerability feeds, and real-time situational awareness dashboards via a secure member portal. Core products include Managed Threat Intelligence, the Threat Sharing Platform, the Member Portal, Analyst On Demand, and Trusted Communities (national, sector-specific, and analyst-only forums). The Health Cyber Sharing Network (HCSN) is a dedicated, A$6.4M Department of Home Affairs-funded (2025-2027) healthcare vertical programme operationalised with 60+ member organisations spanning 600+ facilities.
CI-ISAC monetises exclusively through an eight-tier annual membership fee model, ranging from A$1,500 (Tier 8, sub-A$10M revenue) to A$45,000 interim / A$75,000 target 2027 (Tier 1, >A$5B revenue), with 15-30% discounts for NFP and public health entities. All tiers receive the same core services under an inclusive collective-defence design. Distribution is direct, sales-led, and domestic-only, supported by a Member Value Briefing motion, industry event presence, and strategic partnerships with Health ISAC, Cloudflare (Project Secure Health), Google (Priority Flagger Program), and sector partners. The organisation is positioning for regulatory tailwinds via the 2026 SOCI Act Review (Slay Review), which recommends mandatory CTI sharing and bi-directional government-industry exchange.
CI-ISAC Australia firmographics
Firmographics- Name
- CI-ISAC Australia
- Legal name
- CI-ISAC Australia Ltd
- Website
- https://ci-isac.org.au
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CI-ISAC Australia is a not-for-profit cyber threat intelligence sharing network that aggregates, enriches, and redistributes MITRE ATT&CK-mapped threat intelligence to 110+ member organisations across all 11 of Australia's SOCI Act critical infrastructure sectors, funded through tiered annual membership fees and government grants.
- Ownership category
- akta.pro rank
CI-ISAC Australia industry classification
Industry- Product category
- Cyber Threat Intelligence Sharing
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Membership Organizations (8600), Services-Business Services, Nec (7389)
- akta.pro primary industry
- Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC)
- akta.pro secondary industries
- OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN), Control System Cybersecurity for OT (ICS Security, Monitoring, Hardening) (IMAGABAL)
Keywords
Where CI-ISAC Australia is headquartered
LocationHeadquarters
- HQ city
- Maroochydore
- HQ country
- Australia
- HQ region
- Oceania
Offices1 record
Markets served
CI-ISAC Australia business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Infrastructure, Operations, Marketing or Sales
Revenue model
- Membership Fees: CI-ISAC operates on a not-for-profit membership fee model. Membership fees are the primary revenue stream and are tiered by organisation size (revenue or funds under management). Fees range from A$1,500/year (Tier 8, smallest) to A$45,000/year interim (A$75,000 target 2027) for Tier 1. NFP and Public Health entities receive 15-30% discounts. All tiers receive the same core services — a hallmark of the inclusive, collective-defence model.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Tier 1: Revenue >$5B / FUM >$150B — $45,000 (2026) / $75,000 (2027) |
| Subscription | Annual | Tier 2: Revenue $1B–$5B / FUM $50B–$150B — $35,000 (2026) / $50,000 (2027) |
| Subscription | Annual | Tier 3: Revenue $500M–$1B / FUM $25B–$50B — $27,500 (2026) / $35,000 (2027) |
| Subscription | Annual | Tier 4: Revenue $250M–$500M / FUM $10B–$25B — $20,000 (2026) / $25,000 (2027) |
| Subscription | Annual | Tier 5: Revenue $100M–$250M / FUM $5B–$10B — $15,000 (2026) / $18,000 (2027) |
| Subscription | Annual | Tier 6: Revenue $50M–$100M / FUM $2B–$5B — $10,000 (2026) / $12,500 (2027) |
| Subscription | Annual | Tier 7: Revenue $10M–$50M / FUM $500M–$2B — $5,000 (2026) / $7,500 (2027) |
| Subscription | Annual | Tier 8: Revenue <$10M / FUM <$500M — $1,500 (2026) / $2,500 (2027) |
| Freemium | Multi-year contract | HCSN Pilot — Complementary 6-month trial for eligible health organisations |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels8 records
CI-ISAC Australia product offering
Product offeringCore offering
CI-ISAC Australia operates a sovereign, not-for-profit cyber threat intelligence sharing network for critical infrastructure operators across all 11 Australian SOCI Act sectors. Members contribute real-world threat sightings that CI-ISAC enriches with data from Australian honeypots and global sources, then shares back as actionable, MITRE ATT&CK-mapped advisories, vulnerability feeds, and real-time situational awareness via a secure member portal. All membership tiers receive the same core services, with specialized initiatives including the Health Cyber Sharing Network (HCSN) and Project Secure Health.
Product overview
CI-ISAC Australia operates as a not-for-profit cyber threat intelligence network offering a unified platform for critical infrastructure operators. The core offering combines Managed Threat Intelligence services (including Threat Briefs and Advisories, a Threat Sharing Platform, Member Portal, and Analyst On Demand) with Trusted Communities through sector-specific and cross-sector forums. All membership tiers receive access to the same core services. The organisation also operates specialized initiatives including the Health Cyber Sharing Network (HCSN) for healthcare sector participants and Project Secure Health for GP clinics, with upcoming capabilities in cyber exercising, attack surface monitoring, and leaked credential monitoring.
Differentiator
Problem solved
Functional benefit
Products and services
- Managed Threat Intelligence Provides members with ongoing expert analysis of cybersecurity threats, including threat briefs, advisories, vulnerability dashboards, and real-time threat data sharing through a secure member portal, for critical infrastructure operators across all 11 SOCI Act sectors.
- Threat Sharing Platform A secure platform for real-time sharing of threat data, indicators of compromise (IOCs), and vulnerability assessments across the CI-ISAC membership network, enabling member contributions and enriched intelligence distribution.
- Member Portal A feature-rich web portal providing access to threat and vulnerability advisories, dashboards, and supporting member resources for all membership tiers of CI-ISAC Australia.
- Analyst On Demand (AOD) Direct support from CI-ISAC Australia's experienced cyber analysts for threat hunting, incident response, and tailored analysis services (subject to fair use policy), available to all members.
- National Threat Sharing Forums Regular forums where members share observations, insights, and best practices with peers across all 11 critical infrastructure sectors in Australia.
- Industry Sector Sharing Forums Sector-specific forums (Legal, Government, Energy, Healthcare, etc.) for peer sharing of threat intelligence and best practices within individual critical infrastructure sectors.
- Analyst Collaboration Forums Technical collaboration sessions where cyber and threat intelligence analysts discuss security challenges, lessons learned, and gain insights from across the CI-ISAC membership.
- Health Cyber Sharing Network (HCSN) A dedicated healthcare cybersecurity intelligence sharing community funded by the Department of Home Affairs, providing early access to threat intelligence, collaborative defensive strategies, and sector-specific security insights for hospitals, pathology providers, digital health infrastructure, aged care, and medical supply chain organisations.
- Project Secure Health A collaboration with Cloudflare providing free cybersecurity resources (DDoS protection, web application firewall, zero-trust access) for Australian GP clinics to protect against cyber threats, targeting over 1,000 GP clinics.
- Threat Briefs and Advisories Regular updates on emerging threats, vulnerabilities, and attack campaigns targeting critical infrastructure, delivered as actionable MITRE ATT&CK-mapped advisories to members.
Quantifiable outcome
- Over 110 teams have joined CI-ISAC
- +4 more outcomes
Companies that use CI-ISAC Australia
Customer profileNamed customers5 records
Segments13 records
Ideal customer profiles3 records
CI-ISAC Australia technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability3 records
Feature8 records
CI-ISAC Australia partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered core and minor.
- CloudflarecoreCloudflare partnered with CI-ISAC Australia in June 2024 to provide free cybersecurity tools to Australian GP clinics via Project Secure Health. Cloudflare supplies security technology (DDoS protection, web application firewall, zero-trust access) while CI-ISAC provides the intelligence sharing framework and HCSN programme coordination. Over 1,000 GP clinics targeted for free protection.
- Health ISACcoreMOU signed in March 2024 between CI-ISAC Australia and Health ISAC for international health sector cyber threat intelligence collaboration. This partnership enables cross-border intelligence sharing specific to the healthcare sector, leveraging Health ISAC's global network with CI-ISAC's Australian sovereign capabilities.
- UNSW (University of New South Wales)minorPartner organisation contributing to the Academic R&D Engagement Group within CI-ISAC's governance structure. UNSW brings academic research capabilities to address complex problems faced by critical infrastructure entities.
- Pentagram AdvisoryminorPentagram Advisory hosts the 'Maximising Cyber Resilience: Unlocking the Benefits of CI-ISAC Membership' course, providing education and training services that support member onboarding and maximise the value of CI-ISAC membership.
- Australian Women in Security Network (AWSN)minorAWSN is a partner organisation supporting diversity and inclusion in cybersecurity. Helaine Leggat, CI-ISAC Non-Executive Director, is former Co-chair of AWSN, creating an organic connection between the two organisations.
- Australasian Institute of Digital Health (AIPIO)minorAIPIO is a partner organisation bringing digital health expertise to support the Health Cyber Sharing Network initiative and broader healthcare sector engagement.
- Australasian Health Ethics Research (AHECS)minorAHECS contributes ethics and research expertise relevant to healthcare sector data sharing, privacy, and governance considerations within the Health Cyber Sharing Network.
- PACF (Pacific Forum)minorPacific Forum is a partner organisation providing regional perspective on critical infrastructure protection across the Pacific region, supporting CI-ISAC's international engagement and intelligence sharing.
- CybermindzminorCybermindz is a partner organisation contributing cybersecurity expertise to support the collective defence mission, particularly for resource-constrained CI operators.
- Social Cyber InstituteminorSocial Cyber Institute is a partner organisation focused on the human and social dimensions of cybersecurity. Helaine Leggat is a Distinguished Fellow of the Social Cyber Institute.
- Australian Department of Home AffairscoreThe Department of Home Affairs commissioned and funded the Health Cyber Sharing Network Pilot with A$6.4M for 2025-2027. This positions CI-ISAC as a key delivery partner for government cyber resilience policy in the healthcare sector, validating the model and creating a template for mandatory CTI sharing implementation under the SOCI Act reform.
Scale indicators8 records
Recent moves8 records
Expansion highlights7 records
CI-ISAC Australia competitors and assessment
Company assessmentDirect peers
- OT-ISAC: Operational Technology Information Sharing and Analysis Center. Direct peer as a sector-based ISAC focused on operational technology / industrial control systems, overlapping with several of CI-ISAC's SOCI Act sectors (energy, water, transport).
- FS-ISAC: Financial Services Information Sharing and Analysis Center. The global model for sector ISACs; co-founder Scott Flower was previously its Global Intelligence Officer for Asia Pacific. Directly comparable membership-based CTI sharing model, but focused on the financial services vertical.
- Health-ISAC: Health Information Sharing and Analysis Center. CI-ISAC's international health-sector intelligence partner via the 2024 MOU. Same model (membership-based CTI sharing for a critical infrastructure sector), but globally scoped rather than Australia-only.
- AUSCERT: Australia's first Computer Emergency Response Team, based at the University of Queensland. Provides incident response, threat intelligence, and security advisories to Australian organisations - direct functional peer within the same national market.
Emerging players
- Cyber Threat Alliance: Non-profit industry consortium enabling automated CTI sharing across member cybersecurity vendors. Comparable collective-defence mission and member-funded model, but vendor-membership rather than critical-infrastructure operator-membership.
- FIRST (Forum of Incident Response and Security Teams): Global association of incident response and security teams, including CERTs and ISACs. Comparable peer-to-peer threat sharing orientation across public and private sectors; broader scope but less operationally integrated than CI-ISAC's platform model.
Broad incumbents
- Australian Cyber Security Centre (ACSC): Australian government's lead agency for cyber security, part of ASD. The dominant national incumbent for cyber threat sharing and coordination; a potential competitor if government builds competing CI capability, but also a likely partner for bidirectional exchange under SOCI reform.
- JCDC (Joint Cyber Defense Collaborative): US CISA-led collaborative combining government and private-sector cyber defenders for joint threat response. The closest international analogue of CI-ISAC's intended industry-led, government-partnered model - larger scale but government-initiated rather than industry-initiated.
Regional players
- NCSC UK (National Cyber Security Centre): UK's national cyber authority providing threat intelligence, advisories, and CNI programmes such as the Cyber Security Information Sharing Partnership (CiSP). Same sovereign-CNI-protection thesis as CI-ISAC but government-operated in the UK rather than industry-led.
Peers
Market position
Strengths5 records
Weaknesses5 records
Competitive moat7 records
Key risks6 records
Key highlights7 records
Customer concentration
CI-ISAC Australia social profiles
Digital presenceCI-ISAC Australia compliance and trust
Trust signalCompliance5 records
CI-ISAC Australia financial estimates
Financial estimateRevenue estimate
Valuation estimate
CI-ISAC Australia leadership team
Management profileNumber of profiles
Profiles11 records
CI-ISAC Australia subsidiaries and ownership
Company hierarchySubsidiaries1 record
CI-ISAC Australia funding detail
Funding detailFunding overview
Funding rounds1 record
Investors1 record
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CI-ISAC Australia M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CI-ISAC Australia
What does CI-ISAC Australia do?
CI-ISAC Australia operates a sovereign, not-for-profit cyber threat intelligence sharing network for critical infrastructure operators across all 11 Australian SOCI Act sectors. Members contribute real-world threat sightings that CI-ISAC enriches with data from Australian honeypots and global sources, then shares back as actionable, MITRE ATT&CK-mapped advisories, vulnerability feeds, and real-time situational awareness via a secure member portal. All membership tiers receive the same core services, with specialized initiatives including the Health Cyber Sharing Network (HCSN) and Project Secure Health.
Is CI-ISAC Australia a public or private company?
CI-ISAC Australia is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was CI-ISAC Australia founded?
CI-ISAC Australia was founded in 2022. It employs 11 to 50 people.
Where is CI-ISAC Australia based?
CI-ISAC Australia is headquartered in Maroochydore, Australia, in the Oceania region.
How does CI-ISAC Australia make money?
One revenue line is on record: membership Fees.
Who are CI-ISAC Australia's main competitors?
Direct peers on record are OT-ISAC, FS-ISAC, Health-ISAC and AUSCERT. Emerging players are Cyber Threat Alliance and FIRST (Forum of Incident Response and Security Teams). Broad incumbents are Australian Cyber Security Centre (ACSC) and JCDC (Joint Cyber Defense Collaborative). NCSC UK (National Cyber Security Centre) is listed as a regional player. AISA (Australian Information Security Association) is listed as a peer.
Does CI-ISAC Australia have an API?
No public API is recorded for CI-ISAC Australia.
What industry is CI-ISAC Australia in?
CI-ISAC Australia's product category is Cyber Threat Intelligence Sharing. Its primary akta.pro industry code is HDADAJAC, Critical Infrastructure Protection (CIP) & NERC-CIP Compliance, with a secondary code of BPAKAHAN, OT/ICS & Critical Infrastructure Cybersecurity Services. Its NAICS code is 54151 and its SIC code is 8600.