DVULN
Dvuln is an Australian boutique cybersecurity firm offering offensive security services — penetration testing, red teaming, adversary simulation, maturity assessments, and security training — to enterprise and government clients across Australia, with delivery across Sydney, Melbourne, and Brisbane.
- Company typePrivate
- Founded2016
- HeadquartersVictoria Point, Australia
- Headcount11–50
- GTM typeB2B
- OfferingServices
What DVULN does
Dvuln is an Australian information security company founded in 2016, providing specialised offensive security services to enterprise and government clients across Australia. Headquartered in Sydney with offices in Melbourne and Brisbane, the firm operates with a small technical team of approximately seven named professionals led by founder Jamieson O'Reilly. Dvuln's service portfolio spans penetration testing, adversary simulation (red teaming), maturity assessments (encompassing Essential 8, DevSecOps Maturity / DSOVS, PCI DSS, and Secure Design Review), security transformation/DevSecOps consulting, and security training programs. Engagements are delivered on a project or retainer basis with no publicly disclosed pricing and all acquisition flows through a Calendly booking system, indicating a direct enterprise sales motion. There is no SaaS platform, API, or packaged software product — services are delivered manually by the firm's consultants and offensive security specialists.
The company's technical positioning is anchored by documented research publications on its blog, covering areas such as iOS pentesting without jailbreak, Firebase misconfiguration analysis, Active Directory Certificate Services privilege escalation, OWASP API Top 10 testing methodology, and USSD/telecommunications vulnerabilities. Notable client engagements cited in case studies include a security assessment of the NSW Digital Driver Licence system (covered by IT News and SMH) and a comprehensive review of a mobile application used by 2.6 million Australians. All customer acquisition is direct, with no channel partners, reseller network, or self-serve distribution. No institutional investment, private equity backing, or acquisition history has been disclosed, and the firm appears to be independently operated and founder-led.
Revenue is generated exclusively through professional services engagements — project-based assessments and training programs. The website signals an early move toward productization via a client portal (app.dvuln.com), but this is not yet a material revenue stream. The firm operates entirely within Australia, serving a customer base drawn from large enterprises, government agencies (e.g., ServiceNSW), and organisations requiring security workforce training.
DVULN firmographics
Firmographics- Name
- DVULN
- Legal name
- Dvuln
- Website
- https://dvuln.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Dvuln is an Australian boutique cybersecurity firm offering offensive security services — penetration testing, red teaming, adversary simulation, maturity assessments, and security training — to enterprise and government clients across Australia, with delivery across Sydney, Melbourne, and Brisbane.
- Ownership category
- akta.pro rank
DVULN industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Other Computer Related Services (541519), Investigation and Security Services (5616)
- akta.pro primary industry
- Penetration Testing & Red Teaming (BPAKADAE)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Application Security & DevSecOps Services (BPAKAHAJ)
Keywords
Where DVULN is headquartered
LocationHeadquarters
- HQ city
- Victoria Point
- HQ country
- Australia
- HQ region
- Oceania
Offices3 records
Markets served
DVULN business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D
Revenue model
- Security Assessment Services: Professional services revenue generated through penetration testing, adversary simulation, maturity assessments, and security transformation engagements. Services are offered as project-based engagements or retainer arrangements for ongoing security testing needs.
- Security Training Programs: Training revenue from offensive security training, security awareness training, secure coding workshops, and secure design education programs delivered to enterprise clients.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels5 records
DVULN product offering
Product offeringCore offering
DVULN provides offensive cybersecurity services to enterprise and government clients in Australia. Its core offerings include penetration testing of web, mobile (iOS/Android), API, cloud, and telecom systems; adversary simulation and red team engagements; DevSecOps and security transformation consulting; cybersecurity maturity assessments (Essential 8, DSOVS, PCI DSS, Secure Design Review); and offensive security, awareness, and secure coding training delivered as project-based engagements or retainers.
Product overview
DVULN is an information security company offering a portfolio of offensive and defensive cybersecurity services delivered as individual engagements rather than a unified software product. The core offerings are Pentesting, Adversary Simulation (red teaming), DevSecOps/Security Transformation, Training, and Maturity Assessment. The Maturity Assessment service encompasses sub-services including Essential 8, DevSecOps Maturity (DSOVS), PCI Assessment, and Secure Design Review. The company also publishes technical blog posts and case studies documenting its security research findings. There is no SaaS platform, API, or packaged software product.
Differentiator
Problem solved
Functional benefit
Products and services
- Pentesting Offensive security service involving simulated cyberattacks to identify and exploit vulnerabilities in applications, networks, and infrastructure, delivered to enterprise and government clients.
- Adversary Simulation Red team engagements and simulated advanced persistent threat (APT) operations that mimic real-world attackers to test organisational defences for enterprise and government buyers.
- DevSecOps / Security Transformation Consulting service covering security integration into development pipelines, cloud hardening, secure-by-design implementation, and broader organisational security culture transformation.
- Training Security workforce education covering offensive security training, security awareness, secure coding workshops, and secure design education programs delivered to enterprise clients.
- Maturity Assessment Cybersecurity posture evaluation services including Essential 8 maturity assessment, DevSecOps Maturity (DSOVS), PCI assessment, and Secure Design Review for enterprise and government buyers.
Quantifiable outcome
- Identified critical vulnerabilities in NSW Digital Driver Licence system used by 3.9 million people
- +2 more outcomes
Companies that use DVULN
Customer profileNamed customers2 records
Segments3 records
Ideal customer profiles3 records
DVULN technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature5 records
DVULN partnerships and signals
Strategic signalScale indicators2 records
Recent moves6 records
Expansion highlights6 records
DVULN competitors and assessment
Company assessmentDirect peers
- Sekuro: Australian cybersecurity consultancy providing offensive security, managed security services, and security advisory to enterprise and government clients. Closely comparable in size, geography, and service portfolio to Dvuln, often competing for the same mid-market and government engagements.
- Securus Global: Australian cybersecurity firm specializing in penetration testing, red teaming, and security advisory for enterprise and government. Closely comparable as a domestic boutique competitor with overlapping service offerings and target buyer segments in the Australian market.
- CyberCX: Australia's largest pure-play cybersecurity services firm, offering penetration testing, red teaming, DevSecOps, and security advisory across enterprise and government. Directly comparable as a domestic competitor serving the same Australian buyer base with overlapping offensive security and maturity assessment capabilities.
Broad incumbents
- NCC Group: UK-headquartered global cybersecurity consulting firm with strong penetration testing, red team, and security advisory practices and an APAC presence. Comparable on core offensive security service lines, but at significantly larger scale with broader geographic reach.
- Trustwave: Global cybersecurity services and MDR provider with a significant Australian presence, offering penetration testing, red teaming, and managed security services as part of a broader MSSP portfolio. Comparable on offensive security services but operates at much larger scale with a more comprehensive productized offering.
- KPMG Australia (Cyber): Big 4 advisory practice in Australia providing cybersecurity consulting, penetration testing, and security transformation as part of a broader risk advisory portfolio. Comparable on pentesting and security advisory service lines but embedded within a much larger enterprise consulting business.
Emerging players
- Synack: Tech-enabled penetration testing and vulnerability management platform serving enterprise and government buyers with a vetted researcher pool. Comparable on pentesting service delivery to enterprise clients but competes via a SaaS-mediated model rather than pure consulting.
- Cobalt: Pentesting-as-a-service platform providing on-demand access to vetted security testers through a tech-enabled delivery model. Directly competes with Dvuln's core pentesting offering, particularly for technology buyers preferring structured, software-mediated engagements over traditional consulting.
- HackerOne: Global bug bounty and penetration testing platform that competes with boutique offensive security firms for enterprise vulnerability discovery budgets. Comparable customer base and threat-finding use cases, but delivered through a crowdsourced platform model rather than named consultants.
- Bugcrowd: Crowdsourced cybersecurity platform connecting customers to a vetted researcher community for penetration testing and bug bounty engagements. Competes for the same enterprise testing budget as Dvuln but via a platformized, on-demand model rather than boutique consulting engagements.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks5 records
Key highlights6 records
Customer concentration
DVULN social profiles
Digital presenceDVULN financial estimates
Financial estimateRevenue estimate
Valuation estimate
DVULN leadership team
Management profileNumber of profiles
Profiles7 records
DVULN funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
DVULN M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about DVULN
What does DVULN do?
DVULN provides offensive cybersecurity services to enterprise and government clients in Australia. Its core offerings include penetration testing of web, mobile (iOS/Android), API, cloud, and telecom systems; adversary simulation and red team engagements; DevSecOps and security transformation consulting; cybersecurity maturity assessments (Essential 8, DSOVS, PCI DSS, Secure Design Review); and offensive security, awareness, and secure coding training delivered as project-based engagements or retainers.
Is DVULN a public or private company?
DVULN is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was DVULN founded?
DVULN was founded in 2016. It employs 11 to 50 people.
Where is DVULN based?
DVULN is headquartered in Victoria Point, Australia, in the Oceania region.
How does DVULN make money?
Two revenue lines are on record. Security Assessment Services are the primary driver. The others are security Training Programs.
Who are DVULN's main competitors?
Direct peers on record are Sekuro, Securus Global and CyberCX. Broad incumbents are NCC Group, Trustwave and KPMG Australia (Cyber). Emerging players are Synack, Cobalt, HackerOne and Bugcrowd.
Does DVULN have an API?
No public API is recorded for DVULN.
What industry is DVULN in?
DVULN's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKADAE, Penetration Testing & Red Teaming, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 541519.