3 Lights
3 Lights is a Brisbane-based GRC and cyber security advisory firm that delivers consulting, vCISO, managed GRC (GRC Evolve), and a Human Risk Management platform to mid-market and enterprise clients across Australia.
- Company typePrivate
- Founded2021
- HeadquartersBrisbane, Australia
- Headcount1–10
- GTM typeB2B
- OfferingServices
What 3 Lights does
3 Lights is a Brisbane-based, privately held GRC (governance, risk, and compliance) and cyber security advisory firm operating as 3 Lights PTY LTD. Founded circa 2021-2022 with a team of 1-10 employees, the company targets mid-market and enterprise organizations in Australia that require structured compliance, risk management, and security advisory support, including services delivered to boards and C-suite executives. Its portfolio spans project-based consulting (GRC advisory, vCISO services, Risk Management, Essential Eight Posture Assessment), recurring managed services (GRC Evolve), and subscription software (Human Risk Management platform), with a free Human Risk Report used as a self-serve lead generation tool.
The underlying technology stack combines human advisory services with a third-party GRC platform and a proprietary Human Risk Management platform that delivers security awareness training, simulated phishing, dark web monitoring, policy management, and a company-wide human risk score derived from aggregated training and simulation data. The firm also resells Pentera's automated security validation technology as part of its solutions portfolio. No proprietary AI models, patents, or in-house AI research are disclosed; AI capabilities are described at the feature level (predictive analytics on risk scoring, anomaly detection on dark web exposure) and appear to rely on third-party platforms.
3 Lights generates revenue through professional services engagements, recurring managed service contracts (GRC Evolve), and subscription access to the HRM platform, all priced on a quote-based, multi-year basis with no publicly disclosed rates. Go-to-market is primarily sales-led enterprise field sales supported by content marketing, email newsletters, and active participation in Australian cyber security events (BrisSEC, AusCERT, CyberCon). No funding rounds, parent company, or institutional investors are disclosed, and the firm operates exclusively within the Australian domestic market.
3 Lights firmographics
Firmographics- Name
- 3 Lights
- Legal name
- 3 Lights PTY LTD
- Website
- https://3lights.com.au
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- 3 Lights is a Brisbane-based GRC and cyber security advisory firm that delivers consulting, vCISO, managed GRC (GRC Evolve), and a Human Risk Management platform to mid-market and enterprise clients across Australia.
- Ownership category
- akta.pro rank
3 Lights industry classification
Industry- Product category
- Cybersecurity and GRC Advisory Services
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Platforms (BPAEAPAA)
- akta.pro secondary industries
- Governance, Risk & Compliance (GRC) Managed Services (BPAEADAJ), Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH), Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF)
Keywords
Where 3 Lights is headquartered
LocationHeadquarters
- HQ city
- Brisbane
- HQ country
- Australia
- HQ region
- Oceania
Offices1 record
Markets served
3 Lights business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Marketing or Sales, Technology or R&D, Operations
Revenue model
- vCISO Services: Virtual Chief Information Security Officer services providing security governance, ISMS program management, board cyber advisory, and security program assessment. Typically delivered as consulting engagements.
- GRC Consulting Services: Advisory services for governance, risk, and compliance including assessments, policy development, and strategic roadmap development.
- GRC Evolve Managed Service: Managed GRC service combining human expertise with AI technologies and GRC platform, providing ongoing compliance and risk management with monthly reporting and dashboards.
- Human Risk Management Platform: Subscription-based access to HRM platform including security awareness training, phishing simulations, dark web monitoring, and risk analytics.
- Essential Eight Posture Assessment: One-time assessment service providing baseline analysis of Essential Eight controls and implementation roadmap.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Quote-based professional services |
Go-to-market motion2 records
Distribution channels2 records
Marketing channels4 records
3 Lights product offering
Product offeringCore offering
3 Lights is a niche GRC+Security advisory firm that provides governance, risk, and compliance consulting along with cybersecurity services. It delivers vCISO engagements, enterprise risk management, managed GRC services (GRC Evolve), and operates a Human Risk Management platform with security awareness training, phishing simulation, and dark web monitoring for organisations seeking to reduce cyber and compliance risk.
Product overview
3 Lights is a niche GRC+Security advisory provider offering a portfolio of consulting services and technology solutions. Their core offerings include GRC advisory services, vCISO services, and Risk Management, complemented by managed services like GRC Evolve. They also offer technology platforms including the Human Risk Management (HRM) platform for security awareness and phishing simulation, Human Risk Report for risk assessment, Pentera for security validation, and Essential Eight Posture Assessment for cybersecurity compliance. The company combines human expertise with AI-powered GRC platform technology.
Differentiator
Problem solved
Functional benefit
Brands
- GRC Evolve: A new managed GRC service that integrates governance, risk management, and compliance into a cohesive service framework designed to evolve business practices in GRC and cybersecurity.
- Human Risk Management (HRM)
Products and services
- GRC Advisory Advisory service helping clients understand, implement, and meet governance, risk, and compliance requirements to reduce risk exposure and satisfy stakeholder requirements.
- GRC Evolve Managed GRC service that integrates governance, risk management, and compliance into a cohesive service framework, leveraging AI technologies and a world-class GRC platform with monthly reporting and dashboards.
- vCISO Virtual Chief Information Security Officer service providing ISMS program management, security governance, board cyber advisory, security awareness training, and security program improvement for organisations without a full-time CISO.
- Risk Management Enterprise risk management services including cyber/threat risk assessments, risk management policy development, business continuity planning, operational risk, commercial risk impact modelling, and risk treatment planning.
- Human Risk Management (HRM) Platform Subscription-based platform for calculating, reducing, and monitoring human cyber risk through security awareness training, simulated phishing campaigns, dark web monitoring, policy management, in-depth risk analytics, and human risk scoring.
- Human Risk Report (HRR) Free one-page report service that scans domains for dangerous lookalikes, searches the dark web for stolen credentials, simulates targeted phishing attacks, and provides an organisational human risk score with a step-by-step remediation plan.
- Essential Eight Posture Assessment Cybersecurity assessment service helping businesses implement the Australian Cyber Security Centre's Essential Eight mitigation strategies, providing visibility, gap analysis, and a roadmap for improvement.
- Pentera Security Validation Automated security validation solution allowing organisations to test the integrity of cybersecurity layers, including ransomware readiness, to uncover true, current security exposures.
- Strategic Planning Advisory Business strategy development services including ICT strategy, digital transformation, go-to-market design, corporate governance, business model design, and market forces assessments.
- Operations Advisory Operational management advisory covering financial management, business operations, leadership, HR, vendor management, bid/tender management, quality control, and business process optimisation.
Quantifiable outcome
- The ACSC Essential Eight can help mitigate up to 85% of possible data breaches
- +2 more outcomes
Companies that use 3 Lights
Customer profileSegments3 records
Ideal customer profiles3 records
3 Lights technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature4 records
3 Lights partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- PenterasupportingPentera is described as the category leader for Automated Security Validation. 3 Lights offers Pentera as part of their security solutions portfolio, providing clients with ransomware readiness testing and security exposure validation capabilities.
Scale indicators2 records
Recent moves5 records
Expansion highlights5 records
3 Lights competitors and assessment
Company assessmentDirect peers
- Vanta: Vanta is a leading automated compliance and GRC platform serving mid-market and enterprise customers with continuous monitoring across SOC 2, ISO 27001, HIPAA and similar frameworks. It competes directly with 3 Lights' GRC Evolve managed-service and GRC advisory offering by productising much of the same workflow.
- Drata: Drata is an automated compliance and GRC platform targeting fast-growing tech and SaaS companies across frameworks such as SOC 2, ISO 27001 and Essential Eight-style controls. It overlaps directly with 3 Lights' GRC platform and human risk compliance work for mid-market buyers.
- Secureframe: Secureframe is a compliance automation platform that combines technology with managed services for SOC 2, ISO 27001, HIPAA and PCI. Its product-plus-services model closely mirrors 3 Lights' GRC Evolve positioning for mid-market and enterprise buyers.
- Sekuro: Sekuro is an Australia-based cyber security and GRC advisory and managed-services provider. As a fellow Australian boutique serving enterprise and mid-market clients with advisory, vCISO-style and managed security offerings, it is one of the closest direct competitive analogues to 3 Lights.
Broad incumbents
- Trustwave: Trustwave is a global cybersecurity incumbent offering managed detection and response, GRC consulting and security advisory across many regions. It competes with 3 Lights for mid-market GRC and vCISO budgets but at significantly greater scale and geographic reach.
- Optiv: Optiv is a large North-American cyber advisory and solutions integrator offering GRC, vCISO and managed security services to enterprise clients. It is comparable as a broad incumbent providing overlapping GRC advisory services to large buyers.
- Arctic Wolf: Arctic Wolf is a global managed detection and response and security operations incumbent that increasingly bundles GRC and vCISO-style services for mid-market customers. It competes with 3 Lights at the broader managed-security-plus-advisory layer rather than at the GRC-niche layer.
- CyberCX: CyberCX is one of Australia's largest dedicated cyber security service providers, offering GRC advisory, managed security and consulting across the country. It competes with 3 Lights for enterprise Australian GRC and vCISO engagements but at far greater scale and brand recognition.
- KPMG Australia (Cyber & GRC practice): KPMG's Australian cyber and GRC advisory practice serves ASX-listed and large enterprise clients on governance, risk, compliance and cyber assurance. It competes with 3 Lights on enterprise GRC engagements and board-level cyber advisory, but with much larger delivery teams.
Emerging players
- Tugboat Logic (OneTrust): Tugboat Logic, now part of OneTrust, is a GRC and security compliance automation platform aimed at mid-market companies. It overlaps with 3 Lights' GRC advisory and platform offering for buyers seeking lighter-weight, technology-led compliance programs.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
3 Lights social profiles
Digital presence3 Lights financial estimates
Financial estimateRevenue estimate
Valuation estimate
3 Lights leadership team
Management profileNumber of profiles
3 Lights funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
3 Lights M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about 3 Lights
What does 3 Lights do?
3 Lights is a niche GRC+Security advisory firm that provides governance, risk, and compliance consulting along with cybersecurity services. It delivers vCISO engagements, enterprise risk management, managed GRC services (GRC Evolve), and operates a Human Risk Management platform with security awareness training, phishing simulation, and dark web monitoring for organisations seeking to reduce cyber and compliance risk.
Is 3 Lights a public or private company?
3 Lights is a private company. It is classified as unknown and is currently operating.
When was 3 Lights founded?
3 Lights was founded in 2021. It employs 1 to 10 people.
Where is 3 Lights based?
3 Lights is headquartered in Brisbane, Australia, in the Oceania region.
How does 3 Lights make money?
Five revenue lines are on record. vCISO Services are the primary driver. The others are GRC Consulting Services, GRC Evolve Managed Service, human Risk Management Platform and essential Eight Posture Assessment.
Who are 3 Lights's main competitors?
Direct peers on record are Vanta, Drata, Secureframe and Sekuro. Broad incumbents are Trustwave, Optiv, Arctic Wolf, CyberCX and KPMG Australia (Cyber & GRC practice). Tugboat Logic (OneTrust) is listed as an emerging player.
Does 3 Lights have an API?
No public API is recorded for 3 Lights.
What industry is 3 Lights in?
3 Lights's product category is Cybersecurity and GRC Advisory Services. Its primary akta.pro industry code is BPAEAPAA, Governance, Risk & Compliance (GRC) Platforms, with a secondary code of BPAEADAJ, Governance, Risk & Compliance (GRC) Managed Services.