IPSec
IPSec is an Australian managed security services provider offering 24x7 onshore SOC monitoring, managed EDR/SIEM, vulnerability management, penetration testing, and Essential Eight compliance consulting to government, enterprise, and mid-market organisations across Australia.
- Company typePrivate
- Founded2009
- HeadquartersNotting Hill, Australia
- Headcount11–50
- GTM typeB2B
- OfferingServices
What IPSec does
IPSec Pty Ltd is an Australian managed security services provider (MSSP) founded in 2009 and headquartered in Cremorne, Victoria, with regional offices in Sydney and Brisbane. The company operates a manned 24x7 onshore Security Operations Centre and serves 140+ organisations protecting more than 200,000 endpoints, with a stated cumulative track record of 1,350+ cybersecurity projects. Customers span Australian government (federal, state, and local councils), enterprise (Honda Australia, Quest Apartment Hotels), mid-market, and regulated sectors including healthcare and financial services. The company holds ISO/IEC 27001:2022 certification and is CREST accredited for penetration testing.
The company's core offering is organised around three pillars: Managed Security Services (IPSec Protect - managed EDR/XDR powered by SentinelOne; IPSec Guard - managed SIEM/SOC built on Microsoft Sentinel; IPSec Detect - risk-based vulnerability management; IPSec Insight - brand and dark web monitoring), Penetration Testing and Red Team services (IPSec Impact, plus specialised web, mobile, wireless, and physical security testing), and Security Consulting (Essential Eight assessments, GRC, security awareness training). Technology integrations include Microsoft, SentinelOne, Fortinet, Check Point, Exabeam, Recorded Future, One Identity, and Tenable. AI/ML capability is applied through third-party platforms - SentinelOne's behavioural AI engine and Microsoft Sentinel's machine learning-based log analytics - rather than via proprietary models.
IPSec's business model combines recurring subscription revenue from managed security services (SOC monitoring, SIEM, MDR, vulnerability management, dark web monitoring on annual contracts) with project-based revenue from penetration testing engagements and consulting. Pricing is quote-based with no public tiers; the company offers complimentary consultations as a funnel entry point and conducts go-to-market through direct enterprise sales, website contact forms, phone outreach, and content marketing targeting Australian cybersecurity buyers. The firm is privately held with no disclosed external funding, parent company, or institutional investors.
IPSec firmographics
Firmographics- Name
- IPSec
- Legal name
- IPSec Pty Ltd
- Website
- https://ipsec.com.au
- Company type
- Private
- Founded year
- 2009
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- IPSec is an Australian managed security services provider offering 24x7 onshore SOC monitoring, managed EDR/SIEM, vulnerability management, penetration testing, and Essential Eight compliance consulting to government, enterprise, and mid-market organisations across Australia.
- Ownership category
- akta.pro rank
IPSec industry classification
Industry- Product category
- Managed Cybersecurity Services
- NAICS
- Computer Facilities Management Services (541513), Security Systems Services (56162)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Management Services (8741)
- akta.pro primary industry
- Security Operations Center (SOC) as a Service (BPAEADAB)
- akta.pro secondary industries
- Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG), Application Security & DevSecOps Services (BPAKAHAJ)
Keywords
Where IPSec is headquartered
LocationHeadquarters
- HQ city
- Notting Hill
- HQ country
- Australia
- HQ region
- Oceania
Offices3 records
Markets served
IPSec business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Managed Security Services: Recurring subscription-based managed security services including SOC monitoring, SIEM management, MDR, vulnerability management, and dark web monitoring. Services operate on 24x7x365 model with monthly or annual billing.
- Professional Security Services: One-time and project-based penetration testing services (red team, purple team, web application, mobile, wireless, physical security), security consulting, and security awareness training.
- Security Consulting: Governance, Risk & Compliance consulting including Essential Eight assessments, ISMA assessments, incident response planning, policy development, and third-party security governance services.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free EOFY Consultation - Complimentary 30-minute session with Technical Consulting Manager |
| Subscription | Annual | Managed Security Services - Subscription-based pricing |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels4 records
IPSec product offering
Product offeringCore offering
IPSec is an Australian managed security services provider delivering 24x7x365 cybersecurity services through four managed service modules (IPSec Protect endpoint detection and response, IPSec Guard SIEM/SOC monitoring, IPSec Detect vulnerability management, and IPSec Insight dark web monitoring), supported by an offensive security service line (IPSec Impact) for CREST-accredited penetration testing and red team engagements, and a consulting practice covering Essential Eight assessments, GRC, and security awareness training. Services are delivered by onshore Australian cybersecurity engineers operating from a manned 24x7 Security Operations Center in Australia.
Product overview
IPSec is an Australian managed security services provider (MSSP) offering an integrated portfolio of cybersecurity solutions organized into three main pillars: Managed Security Services (Protect, Guard, Detect, Insight), Penetration Testing/Red Team Services (via IPSec Impact), and Security Consulting (Essential Eight, Security Awareness Training, GRC). The managed security services operate as distinct but complementary modules - Protect provides endpoint detection and response, Guard delivers SIEM/SOC capabilities, Detect manages vulnerability scanning, and Insight monitors brand/dark web threats. These services are powered by technology partnerships with SentinelOne and Microsoft Sentinel, integrating AI-driven behavioural analysis and automated response capabilities.
Differentiator
Problem solved
Functional benefit
Brands
- IPSec Detect: Vulnerability management program enabling organisations to prioritise and protect against vulnerabilities across cloud, on-premises, and infrastructure environments.
- IPSec Guard
- IPSec Insight
- IPSec Protect
- IPSec Impact
Products and services
- IPSec Protect Managed Endpoint Detection and Response (EDR/XDR) service leveraging SentinelOne technology with human-powered cybersecurity expertise to detect and respond to ransomware and phishing attacks across central, cloud, and remote endpoints. Features include behavioural AI engine analysis, instant roll-back capabilities, and MITRE ATT&CK Framework integration for organisations requiring 24x7 endpoint protection without in-house SOC resources.
- IPSec Guard Managed SIEM/SOC service built on Microsoft Sentinel providing 24x7x365 surveillance, proactive threat detection, notification, and remediation across devices, endpoints, applications, cloud platforms, and networks. Processes 1.8 trillion logs annually using big data and machine learning capabilities with automated playbooks for orchestration and threat response.
- IPSec Detect Vulnerability management program that provides prioritised, risk-based alerts and 24x7x365 protection across cloud, on-premises, and hybrid infrastructure environments. Prioritises vulnerabilities based on organisational risk rather than generic CVSS scores.
- IPSec Insight Brand intelligence and dark web monitoring service that detects unauthorized brand use, credential leaks, and emerging cyber threats through continuous monitoring of surface web, deep web, and dark web sources. Includes custom watchlists for domains, IPs, logos, brands, and key personnel with SOC ITSM integration and automated incident ticketing.
- IPSec Impact Threat intelligence-based penetration testing and offensive security service that simulates real-world attacks using advanced techniques aligned with CREST accreditation standards. Encompasses red team, purple team, and threat emulation exercises for organisations seeking to test their cyber resilience against real-world threat actor tactics, techniques, and procedures.
- Attack Surface Discovery Service that scans and identifies all internet-facing assets including shadow IT, unauthorised assets, and misconfigurations to provide visibility into organisational digital footprint for security testing engagements.
- Internal Penetration Testing Simulates attacks from within the network, mimicking malicious insiders, supply chain attacks, or perimeter breaches to identify vulnerabilities in internal systems and processes for organisations seeking internal network security validation.
- Internet Facing Infrastructure Testing Identifies vulnerabilities in external infrastructure including servers, firewalls, network devices, and cloud configurations using OSSTMM methodology for organisations needing external infrastructure security validation.
- Web Application Penetration Testing Identifies vulnerabilities in web applications using OWASP Testing Methodology, covering frontend, backend, APIs, and data storage security assessment for organisations operating customer-facing or internal web applications.
- Mobile Application Penetration Testing Security assessment for iOS, Android, and hybrid mobile applications using OWASP Mobile Application Testing Guide methodology for organisations deploying mobile applications to customers or staff.
- Wireless Penetration Testing Evaluates wireless network security including encryption protocols, configurations, user access controls, and tests for rogue access points, AITM attacks, and brute force attacks for organisations operating wireless infrastructure.
- Red Team Engagement Advanced offensive security testing simulating APTs and targeted attacks, testing networks, applications, cloud infrastructure, physical security, and social engineering for organisations needing advanced threat simulation.
- Purple Team Engagement Collaborative testing combining Red Team attack simulation with Blue Team detection, using MITRE ATT&CK Framework to improve organisational detection and response capabilities for security teams seeking to validate and improve their defences.
- Physical Security Testing Evaluates physical security controls including access control systems, surveillance, perimeter defences, and tests employee awareness through social engineering for organisations needing physical security validation.
- Phishing Awareness Campaign Simulated phishing campaigns that test employee awareness, measuring click rates and providing reporting on user interactions with phishing emails for organisations seeking to assess and improve human security posture.
- ACSC Essential Eight Assessment Assessment evaluating organisational implementation of the Australian Cyber Security Centre's Essential Eight mitigation strategies, providing gap analysis and prioritised recommendations for Australian organisations seeking Essential Eight compliance.
- Security Awareness Training Employee education program covering phishing identification, password hygiene, safe internet use, data protection, and social engineering awareness delivered in-person or virtually for organisations seeking to improve staff security culture.
- Governance, Risk & Compliance Consulting Consulting services including security threat and risk management, Information Security Maturity Assessment, incident response planning, security policies development, and third-party security governance for organisations needing GRC advisory support.
- Azure/Microsoft 365 Security Configuration Review Review of Azure and M365 cloud security configurations to identify issues and ensure organisational information security objectives are maintained for organisations operating Microsoft cloud platforms.
Quantifiable outcome
- 75% reduction in customer cyber risk profile and likelihood of damaging attack
- +3 more outcomes
Companies that use IPSec
Customer profileNamed customers6 records
Segments6 records
Ideal customer profiles4 records
IPSec technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration9 records
AI capability6 records
Feature5 records
IPSec partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and supporting.
- MicrosoftcoreTechnology partnership for cloud security solutions. IPSec's Guard on Microsoft Sentinel service is a managed SIEM solution built on the Microsoft Sentinel platform, providing 24x7 monitoring with expert human analysis.
- SentinelOnecoreStrategic partnership for endpoint detection and response. SentinelOne powers IPSec Protect - Managed EDR service with features including roll-back capabilities and behavioural AI engine.
- FortinetsupportingTechnology partner providing network security solutions integrated into IPSec's managed security services offerings.
- Check PointsupportingTechnology partner for cybersecurity solutions integrated into IPSec's managed security ecosystem.
- ExabeamsupportingTechnology partner for security analytics and SIEM capabilities enhancing IPSec's threat detection services.
- Recorded FuturesupportingThreat intelligence partner providing real-time threat intelligence feeds integrated into IPSec's security monitoring and detection services.
- OneIdentitysupportingTechnology partner for identity and access management solutions integrated into IPSec's security offerings.
- TenablesupportingTenable research cited regarding vulnerability management statistics. IPSec leverages Tenable's research on CVSS strategies, noting that organisations using CVSS 7+ strategy waste 76% of remediation time.
Scale indicators9 records
Recent moves6 records
Expansion highlights4 records
IPSec competitors and assessment
Company assessmentBroad incumbents
- Secureworks: Global MSSP offering managed detection, vulnerability management, and consulting. Has an Australian presence and competes for enterprise SOC and compliance work alongside IPSec.
- Arctic Wolf: Global MDR/SOC-as-a-service vendor operating across the US, EMEA, and APAC including Australia. Competes head-to-head with IPSec's Guard SIEM/SOC and Protect EDR managed services for mid-market and enterprise customers.
- Trustwave: Global cybersecurity firm providing managed detection, MDR, pen testing, and consulting with operations in Australia. Competes with IPSec across both managed services and offensive security.
Direct peers
- Loop Secure: Australian cybersecurity consultancy and MSSP delivering managed detection, vulnerability management, and pen testing. Comparable size and service mix to IPSec, focused on the same Australian mid-market and enterprise buyers.
- Sekuro: Australian MSSP offering managed security, offensive security, and GRC consulting to mid-market and enterprise. Closely mirrors IPSec's portfolio and target verticals in Australia.
- Pure Security: Australian penetration testing and offensive security firm offering CREST-accredited testing. Closely comparable to IPSec's IPSec Impact offensive security practice.
- Tesserent (Thales Cyber & Digital): Australian-headquartered MSSP and cyber consulting firm, now part of Thales, providing managed detection, SOC, and compliance services to government and enterprise. Overlaps IPSec's GRC, SOC, and pen testing offerings.
- CyberCX: Australia's largest independent cybersecurity services firm offering managed SOC, penetration testing, and consulting. Directly competes with IPSec across enterprise and government accounts but at materially greater scale.
- HackLabs: ANZ-based CREST-accredited penetration testing and red team firm. Overlaps with IPSec's IPSec Impact service line across government and enterprise pen testing engagements.
Regional players
- Insomnia Security: Specialist offensive security consultancy headquartered in New Zealand with Australia presence. Comparable pen testing, red team, and assurance services though primarily ANZ-focused.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
IPSec compliance and trust
Trust signalCompliance2 records
IPSec financial estimates
Financial estimateRevenue estimate
Valuation estimate
IPSec leadership team
Management profileNumber of profiles
IPSec funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
IPSec M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about IPSec
What does IPSec do?
IPSec is an Australian managed security services provider delivering 24x7x365 cybersecurity services through four managed service modules (IPSec Protect endpoint detection and response, IPSec Guard SIEM/SOC monitoring, IPSec Detect vulnerability management, and IPSec Insight dark web monitoring), supported by an offensive security service line (IPSec Impact) for CREST-accredited penetration testing and red team engagements, and a consulting practice covering Essential Eight assessments, GRC, and security awareness training. Services are delivered by onshore Australian cybersecurity engineers operating from a manned 24x7 Security Operations Center in Australia.
Is IPSec a public or private company?
IPSec is a private company. It is classified as unknown and is currently operating.
When was IPSec founded?
IPSec was founded in 2009. It employs 11 to 50 people.
Where is IPSec based?
IPSec is headquartered in Notting Hill, Australia, in the Oceania region.
How does IPSec make money?
Three revenue lines are on record. Managed Security Services are the primary driver. The others are professional Security Services and security Consulting.
Who are IPSec's main competitors?
Broad incumbents on record are Secureworks, Arctic Wolf and Trustwave. Direct peers are Loop Secure, Sekuro, Pure Security, Tesserent (Thales Cyber & Digital), CyberCX and HackLabs. Insomnia Security is listed as a regional player.
Does IPSec have an API?
No public API is recorded for IPSec.
What industry is IPSec in?
IPSec's product category is Managed Cybersecurity Services. Its primary akta.pro industry code is BPAEADAB, Security Operations Center (SOC) as a Service, with a secondary code of BPAEADAG, Network Security Managed Services (Firewall/IDS/IPS/SASE). Its NAICS code is 541513 and its SIC code is 7373.