StickmanCyber
StickmanCyber is an Australian cybersecurity services firm founded in 2006 that delivers AI-driven Cybersecurity-as-a-Service (CSaaS), managed SOC, and compliance certification (ISO 27001, PCI-DSS, Essential 8, APRA CPS 234) to 200+ mid-to-large enterprises via offices across Australia, India, Nepal, and South Africa.
- Company typePrivate
- Founded2006
- HeadquartersSydney, Australia
- Headcount51–100
- GTM typeB2B
- OfferingServices
What StickmanCyber does
StickmanCyber is an Australian cybersecurity services firm founded in 2006 (legal entity Stickman Consulting Pty Ltd) that sells managed security and compliance services to mid-to-large enterprises, with disclosed coverage of 200+ enterprise customers. The company's core product is Cybersecurity-as-a-Service (CSaaS), an AI-driven managed offering that bundles 24x7 security monitoring, threat detection, incident response, and compliance certification. The underlying SOC is built on Google Security Operations (Chronicle SIEM + SOAR) integrated with CrowdStrike EDR, wrapped by a proprietary delivery framework called WISDOM and a single-point-of-contact engagement model branded as CyberNavigator. The company is also a PCI-DSS Qualified Security Assessor and CREST ANZ Registered entity, and employs NV1-cleared professionals with CISSP, CISA, CRISC, and ISO 27001 Lead Auditor/Implementer certifications.
The company monetizes through three streams: a subscription/recurring CSaaS managed services line, professional services including cybersecurity assessments, penetration testing, virtual CISO, and vendor risk management, and managed security monitoring engagements. Go-to-market is primarily direct enterprise sales with 'Talk to an Expert' engagement and a free trial for SOC-as-a-Service, supplemented by distribution through the Google Cloud Marketplace. The company pursues vertical segmentation with dedicated healthcare and finance cybersecurity practices, and supports compliance with ISO 27001, PCI-DSS, Essential 8, NIST, APRA CPS 234, ISM ASD, and Australian Privacy Principles.
StickmanCyber is founder-led by Ajay Unni, headquartered in Sydney (Macquarie Park, NSW) with operating offices in Melbourne, Brisbane, and Perth, and additional operating presence in India, Nepal, and South Africa. It is privately held with no disclosed external funding, acquisitions, or IPO plans, and operates primarily in the Australian market with limited international distribution outside its offshore delivery centers.
StickmanCyber firmographics
Firmographics- Name
- StickmanCyber
- Legal name
- Stickman Consulting Pty Ltd
- Website
- https://stickmancyber.com
- Company type
- Private
- Founded year
- 2006
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- StickmanCyber is an Australian cybersecurity services firm founded in 2006 that delivers AI-driven Cybersecurity-as-a-Service (CSaaS), managed SOC, and compliance certification (ISO 27001, PCI-DSS, Essential 8, APRA CPS 234) to 200+ mid-to-large enterprises via offices across Australia, India, Nepal, and South Africa.
- Ownership category
- akta.pro rank
StickmanCyber industry classification
Industry- Product category
- Managed Cybersecurity Services
- NAICS
- Computer Systems Design and Related Services (54151), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Managed Detection & Response (MDR) & SOC Services (HDADAGAG)
- akta.pro secondary industries
- Cybersecurity & Identity Consulting (BPAHAEAG), Data Security & Privacy Services (DLP, Encryption, Privacy Ops) (BPAKAHAM)
Keywords
Where StickmanCyber is headquartered
LocationHeadquarters
- HQ city
- Sydney
- HQ country
- Australia
- HQ region
- Oceania
Offices4 records
Markets served
StickmanCyber business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Cybersecurity as a Service (CSaaS): AI-driven fully managed cybersecurity services with 24x7 monitoring, detection, and response capabilities. Includes SOC as a Service, threat intelligence, and incident response.
- Professional Services: Consulting services including cybersecurity assessments, penetration testing, compliance framework implementation (ISO 27001, PCI-DSS, Essential 8, NIST, APRA 234), virtual CISO (vCISO), and vendor risk management.
- Managed Security Monitoring: Continuous security operations center monitoring and threat detection services.
Go-to-market motion1 record
Distribution channels3 records
Marketing channels6 records
StickmanCyber product offering
Product offeringCore offering
StickmanCyber provides AI-driven Cybersecurity as a Service (CSaaS) anchored by a 24x7 managed Security Operations Center delivering continuous threat monitoring, detection, hunting, dark web monitoring and incident response, alongside cybersecurity and cloud security assessments, penetration testing, social engineering prevention, virtual CISO advisory, vendor risk management, and a comprehensive governance, risk and compliance practice covering ISO 27001, PCI-DSS, Essential 8, NIST, APRA CPS 234, ISM and the Australian Privacy Principles. Offerings are delivered to enterprise and mid-market customers, particularly in healthcare, financial services and government sectors, using the proprietary WISDOM methodology and CyberNavigator single-point-of-contact model integrated with Google Security Operations and CrowdStrike.
Product overview
StickmanCyber is a managed cybersecurity services company offering a comprehensive portfolio of security products and services. The core offering is Cybersecurity As-A-Service (CSaaS), an AI-driven platform providing 24x7 managed security services. The CyberNavigator methodology guides clients through Assess, Secure, Comply, Certify, and Uplift phases. Key products include SOC As A Service (combining Google Security Operations SIEM/SOAR with CrowdStrike EDR), Incident Response, Threat Intelligence, Penetration Testing, Social Engineering Prevention, Virtual CISO, and Vendor Risk Management. The company also provides certification services for ISO 27001, PCI-DSS, Essential 8, NIST, APRA CPS 234, ISM, and Australian Privacy Principles. Industry-specific solutions cover healthcare and finance sectors. Operating since 2006, the company serves over 200+ enterprise clients across Australia with offices in Sydney, Melbourne, Brisbane, Perth, India, Nepal, and South Africa.
Differentiator
Problem solved
Functional benefit
Products and services
- Cybersecurity as a Service (CSaaS) Subscription-based managed cybersecurity service delivered through the company's AI-driven CSaaS platform, providing 24x7 security operations, threat monitoring, detection and incident response for mid-market and enterprise customers that need continuous coverage without building an in-house SOC.
- SOC as a Service Outsourced 24x7 Security Operations Center offering continuous monitoring, detection, triage and response of security events on behalf of customers, available as a managed subscription.
- Threat Monitoring, Detection and Response Continuous monitoring, detection and response of cyber threats across customer environments, integrated with the company's SOC and CSaaS platform for enterprise and mid-market customers.
- Incident Response Reactive and proactive incident response services to contain, remediate and recover from cybersecurity incidents, including ransomware and breach scenarios, for enterprise customers.
- Threat Intelligence Curated threat intelligence feeds and analysis providing context on adversary tactics, techniques and procedures relevant to Australian enterprises and regulated industries.
- Dark Web Monitoring Continuous monitoring of the dark web for stolen customer credentials, leaked data and brand abuse, with alerting and remediation guidance.
- Threat Hunting Proactive, hypothesis-driven threat hunting across customer environments to identify adversaries that have evaded automated detection.
- Penetration Testing Offensive security testing of networks, applications, cloud and people to identify exploitable vulnerabilities before attackers can leverage them.
- Cybersecurity Assessment Comprehensive cybersecurity posture assessments of customer environments, identifying gaps across people, process and technology.
- Cloud Security Assessment Security assessment of customer cloud environments (e.g. Google Cloud, AWS, Azure) covering configuration, identity, data protection and workload security.
- Social Engineering Prevention Testing and program support to reduce human cyber risk, including phishing simulations and awareness uplift, typically delivered alongside penetration testing.
- Virtual CISO (vCISO) Fractional Chief Information Security Officer advisory service providing executive-level security strategy, governance and board reporting for organizations that do not have a full-time CISO.
- Vendor Risk Management Third-party and supply-chain risk management service, helping customers assess, monitor and remediate cyber risk across their vendor ecosystem.
- CIS Benchmark Assessment Assessment and remediation guidance against the Center for Internet Security (CIS) Benchmarks for secure configuration of systems and cloud platforms.
- Governance, Risk and Compliance (GRC) GRC services helping organizations design, implement and operate cybersecurity governance, risk management and compliance programs against multiple frameworks.
- ISO 27001 Assessment and Implementation Assessment, gap analysis and implementation support for ISO 27001 information security management systems, leading to certification.
- PCI-DSS Compliance Assessment and remediation services to help organizations achieve and maintain compliance with the Payment Card Industry Data Security Standard.
- Essential 8 Assessment
- NIST Cybersecurity Framework Assessment Assessment and gap analysis against the NIST Cybersecurity Framework, with prioritized recommendations aligned to customer risk profile.
- APRA CPS 234 Assessment Assessment of APRA-regulated entities against CPS 234 Information Security requirements, supporting attestation and remediation.
- ISM (Australian Signals Directorate) Assessment Assessment against the Australian Signals Directorate's Information Security Manual (ISM) for Australian government and critical infrastructure customers.
- Australian Privacy Principles Compliance Privacy compliance services aligned to the Australian Privacy Principles and Notifiable Data Breaches scheme, supporting APP-aligned controls and breach readiness.
- Healthcare Cybersecurity Sector-specific cybersecurity bundle for hospitals, clinics, digital health providers and health insurers, combining managed security, privacy compliance and incident response tailored to healthcare data and clinical operations.
- Finance Cybersecurity Sector-specific cybersecurity bundle for banks, credit unions, insurers and super funds, combining managed security, APRA CPS 234 support, PCI-DSS, threat intelligence and incident response tailored to financial services.
Quantifiable outcome
- Reduces cybersecurity spend by 50%
- +2 more outcomes
Companies that use StickmanCyber
Customer profileNamed customers9 records
Segments4 records
Ideal customer profiles3 records
StickmanCyber technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability3 records
Feature2 records
StickmanCyber partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- Google CloudcoreStickmanCyber partners with Google Cloud to deliver Google Security Operations (SIEM + SOAR) services. This partnership enables the company to offer enterprise-grade SOC as a Service combining Google's Chronicle SIEM platform with StickmanCyber's managed security expertise.
- CrowdStrikecoreStickmanCyber integrates CrowdStrike EDR (Endpoint Detection and Response) as part of their security operations center offering to provide market-leading endpoint protection alongside Google Chronicle SIEM.
- CREST ANZcoreCEO Ajay Unni sits on the board of CREST ANZ, a non-profit organization that provides cybersecurity accreditation for companies, individuals, and corporate entities and promotes best practice information security services.
Scale indicators3 records
Recent moves5 records
Expansion highlights5 records
StickmanCyber competitors and assessment
Company assessmentDirect peers
- CyberCX: Australia's largest independent cybersecurity services firm (PE-backed by BGH Capital) offering SOC, MDR, consulting, and managed security services to enterprise and government clients — the most direct competitor to StickmanCyber's full-stack CSaaS model in the Australian mid-to-large enterprise market.
- Tesserent (now Senticore / CGI): Australian-headquartered cybersecurity services firm (formerly Tesserent, now under CGI following a take-private) that competes head-to-head with StickmanCyber across SOC-as-a-Service, GRC, and certification work for Australian enterprises and government.
- Sekuro: Australian MSSP and cybersecurity consulting firm offering managed security, ISO 27001 advisory, and vCISO services — directly comparable customer base, product mix, and go-to-market motion to StickmanCyber's mid-market enterprise segment.
- Triskele Labs: Australian cybersecurity services firm providing SOC, incident response, penetration testing, and managed security for mid-market and government clients — competes in the same compliance-heavy, regulated-vertical segments that StickmanCyber serves.
- Loop Secure (formerly A1Logic): Australian cybersecurity and managed security services provider serving mid-market and enterprise customers across ANZ with SOC and advisory offerings overlapping with StickmanCyber's CSaaS portfolio.
Emerging players
- Arctic Wolf: US-headquartered MDR/SOC-as-a-service provider rapidly expanding in APAC through channel partners — competes with StickmanCyber on outcome-based managed security for mid-market buyers without a heavy in-region delivery footprint.
Broad incumbents
- CrowdStrike Services: Endpoint security platform whose EDR technology StickmanCyber resells in its SOC; CrowdStrike also offers Falcon Complete MDR and professional services that directly overlap with StickmanCyber's managed detection and incident response offerings.
- Palo Alto Networks Unit 42: Global cybersecurity platform vendor offering MDR, incident response, and managed security consulting through Unit 42 — represents the bundle-and-displace competitive threat to Australian MSSPs from global incumbents.
- Trustwave: Global MSSP offering managed detection, MDR, and consulting services with an established Australian presence — comparable in service breadth (SOC, GRC, pen testing) though at significantly greater scale.
- Mandiant (Google Cloud): Google-owned incident response and managed defense firm — both a vendor-partner adjacent entity (via StickmanCyber's Google Cloud SIEM tie-up) and a competitor for high-end IR and threat intelligence work in Australia.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks6 records
Key highlights6 records
Customer concentration
StickmanCyber social profiles
Digital presenceStickmanCyber compliance and trust
Trust signalCompliance17 records
StickmanCyber financial estimates
Financial estimateRevenue estimate
Valuation estimate
StickmanCyber leadership team
Management profileNumber of profiles
Profiles1 record
StickmanCyber funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
StickmanCyber M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about StickmanCyber
What does StickmanCyber do?
StickmanCyber provides AI-driven Cybersecurity as a Service (CSaaS) anchored by a 24x7 managed Security Operations Center delivering continuous threat monitoring, detection, hunting, dark web monitoring and incident response, alongside cybersecurity and cloud security assessments, penetration testing, social engineering prevention, virtual CISO advisory, vendor risk management, and a comprehensive governance, risk and compliance practice covering ISO 27001, PCI-DSS, Essential 8, NIST, APRA CPS 234, ISM and the Australian Privacy Principles. Offerings are delivered to enterprise and mid-market customers, particularly in healthcare, financial services and government sectors, using the proprietary WISDOM methodology and CyberNavigator single-point-of-contact model integrated with Google Security Operations and CrowdStrike.
Is StickmanCyber a public or private company?
StickmanCyber is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was StickmanCyber founded?
StickmanCyber was founded in 2006. It employs 51 to 100 people.
Where is StickmanCyber based?
StickmanCyber is headquartered in Sydney, Australia, in the Oceania region.
How does StickmanCyber make money?
Three revenue lines are on record. Cybersecurity as a Service (CSaaS) is the primary driver. The others are professional Services and managed Security Monitoring.
Who are StickmanCyber's main competitors?
Direct peers on record are CyberCX, Tesserent (now Senticore / CGI), Sekuro, Triskele Labs and Loop Secure (formerly A1Logic). Arctic Wolf is listed as an emerging player. Broad incumbents are CrowdStrike Services, Palo Alto Networks Unit 42, Trustwave and Mandiant (Google Cloud).
Does StickmanCyber have an API?
No public API is recorded for StickmanCyber.
What industry is StickmanCyber in?
StickmanCyber's product category is Managed Cybersecurity Services. Its primary akta.pro industry code is HDADAGAG, Managed Detection & Response (MDR) & SOC Services, with a secondary code of BPAHAEAG, Cybersecurity & Identity Consulting. Its NAICS code is 54151 and its SIC code is 7370.