Insicon
Insicon Cyber is an Australia/New Zealand cybersecurity advisory and managed services firm founded in 2013, providing CISOaaS, board advisory, Essential Eight, and ISO certification plus 24/7 SOC/MDR services to mid-market and enterprise clients.
- Company typePrivate
- Founded2013
- HeadquartersNorth Sydney, Australia
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Insicon does
Insicon Cyber (operating as Insicon Pty Ltd) is an Australian-headquartered cybersecurity advisory and managed services firm founded in 2013, with a regional headquarters in Wellington, New Zealand. The company combines strategic board-level advisory with 24/7 managed security operations, offering CISO as a Service (CISOaaS), Board Cyber Advisory, Essential Eight assessments, ISO 27001/42001/9001/14001/45001 certification support, Managed Detection and Response (MDR), Managed SIEM, Managed Compliance, Managed Autonomous Red Teaming, and tabletop/cyber simulation exercises. Service delivery targets mid-market and enterprise customers in aged care, online retail and SaaS, financial services, professional services, and critical infrastructure verticals across Australia and New Zealand.
The technology stack is multi-vendor rather than proprietary, integrating SentinelOne, Microsoft, Okta, Trend Micro, Cloudflare, Google Cloud, F5, Cribl, Horizon3.ai, Rubrik, KnowBe4, and OneLogin into an adaptive Security Operations Centre (aSOC) that combines managed SIEM, MDR, and continuous compliance evidence collection. Co-founders Matt Miller (CEO) and Greg Bunt personally serve as practising Fractional CISOs and lead board-level engagements, which the firm positions against the junior-consultant delivery model common in larger MSSPs. The company holds its own ISO 27001:2022 certification and has earned industry recognition including the 2025 Benchmark Security Awards (Retail Security Partner of the Year) and 2026 Australian Cyber Awards finalist placements for Cyber Consulting Business of the Year (SME) and CISO of the Year.
The business model is a mix of recurring subscription-style retainers and project-based professional services. Disclosed indicative pricing includes $8,000-$15,000/month for virtual CISO engagements, $2,500-$3,500/day for fractional CISO engagements (typically 2-3 days per week), and approximately $6,500-$15,000 per simulation exercise, with most other scopes quoted on consultation. Distribution is entirely direct through website enquiries, a dedicated sales phone line, and board-level advisory-led conversations, with no reseller or channel partner model. The firm is privately held, founder-controlled, and has not disclosed external funding or revenue.
Insicon firmographics
Firmographics- Name
- Insicon
- Legal name
- Insicon Pty Ltd
- Website
- https://insicon.com.au
- Company type
- Private
- Founded year
- 2013
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Insicon Cyber is an Australia/New Zealand cybersecurity advisory and managed services firm founded in 2013, providing CISOaaS, board advisory, Essential Eight, and ISO certification plus 24/7 SOC/MDR services to mid-market and enterprise clients.
- Ownership category
- akta.pro rank
Insicon industry classification
Industry- Product category
- Cybersecurity Advisory and Managed Security Services
- NAICS
- Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Integrated Systems Design (7373)
- akta.pro primary industry
- OT/ICS & Critical Infrastructure Cybersecurity Services (BPAKAHAN)
- akta.pro secondary industry
- Security Awareness, Training & Compliance Attestation (HDADAIAJ)
Keywords
Where Insicon is headquartered
LocationHeadquarters
- HQ city
- North Sydney
- HQ country
- Australia
- HQ region
- Oceania
Offices2 records
Markets served
Insicon business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Managed Security Services: Ongoing managed security services including SOC operations, MDR, Managed SIEM, and Managed Compliance. These are recurring retainer engagements providing continuous monitoring and operational delivery, complementing advisory services with 24/7 security operations capability.
- CISO as a Service (CISOaaS): Virtual CISO (vCISO) delivered at $8,000-$15,000 per month for 10-20 hours/month of executive guidance, retainer-based. Fractional CISO delivered at $2,500-$3,500 per day, on-site 2-3 days per week, project-based or ongoing. Both models include access to the full specialist team. Monthly retainer pricing provides budget certainty.
- ISO 27001 Compliance and Certification Advisory: Advisory services guiding organisations through ISO 27001 compliance and certification journey. Includes gap assessment, ISMS design, implementation support, and liaison with external auditors. Ongoing managed compliance support post-certification for surveillance audit preparation and continuous improvement.
- Tabletop and Cyber Simulation Exercises: Tabletop simulation exercises at ~$6,500 ex GST for a half-day on-site session. Cyber simulation (BCP test) at ~$15,000 ex GST for a full-day on-site session including tailored findings report and presentation to leadership.
- Essential Eight Assessment and Advisory: Essential Eight maturity assessments and ongoing managed compliance services for organisations pursuing or maintaining Essential Eight maturity levels aligned with ASD framework. Includes assessment, roadmap development, maturity uplift advisory, and managed compliance with annual reassessment.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Virtual CISO (vCISO) - Remote strategic leadership |
| Unit Pricing | Multi-year contract | Fractional CISO - On-site integrated leadership |
| Unit Pricing | Pay-as-you-go | Tabletop Simulation - Half-day on-site |
| Unit Pricing | Pay-as-you-go | Cyber Simulation (BCP Test) - Full day on-site |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels5 records
Insicon product offering
Product offeringCore offering
Insicon Cyber is a trans-Tasman cybersecurity advisory and managed services firm that delivers strategic cyber governance advice (Fractional/Virtual CISO, board advisory, risk assessments) alongside 24/7 operational security services (adaptive SOC, MDR, Managed SIEM, Managed Compliance). It supports organisations in achieving and maintaining Essential Eight, ISO 27001, ISO 42001, ISO 9001, ISO 14001 and ISO 45001 certifications, and delivers tabletop and full cyber simulation exercises to test incident response.
Product overview
Insicon Cyber is a managed cybersecurity services provider offering an integrated suite of advisory and operational security services across Australia and New Zealand. The core offering combines strategic advisory services (CISOaaS, Board Cyber Advisory, Risk Assessment, Compliance) with 24/7 managed security operations (SOC, MDR, SIEM, Managed Compliance). Key service modules include Essential Eight assessment and maturity uplift, ISO 27001/42001/9001 certification support, tabletop exercises, and technology acquisition advisory. Services are delivered through an Adaptive SOC with continuous monitoring, and the Managed Compliance platform provides ongoing evidence collection and compliance monitoring. The company positions itself as bridging boardroom strategy with operational execution through a combination of fractional CISO leadership and managed security services.
Differentiator
Problem solved
Functional benefit
Brands
- Insicon Cyber: The primary operating brand for cybersecurity advisory and managed services, covering managed security services, SOC, MDR, SIEM, compliance services (ISO 27001, ISO 42001, Essential Eight), CISO as a Service, Board Cyber Advisory, and tabletop/cyber simulation exercises.
Products and services
- Managed Security Services
Quantifiable outcome
- 15-25% cyber insurance premium reductions for CISOaaS clients
- +2 more outcomes
Companies that use Insicon
Customer profileNamed customers4 records
Segments6 records
Ideal customer profiles5 records
Insicon technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration14 records
Insicon partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core.
- SentinelOnecoreSentinelOne is listed as a technology partner providing endpoint detection and response (EDR) capabilities integrated into Insicon Cyber's managed security services ecosystem.
- MicrosoftcoreMicrosoft is listed as a technology partner providing security and productivity platform integration across Insicon Cyber's managed security services and security operations.
- OktacoreOkta is listed as a technology partner providing identity and access management integration for Insicon Cyber's security solutions.
- Google CloudcoreGoogle Cloud is listed as a technology partner providing cloud infrastructure and security capabilities. Insicon Cyber is identified as a Google Cloud Partner.
- RubrikcoreRubrik is listed as a technology partner providing data protection and ransomware recovery capabilities integrated into Insicon Cyber's managed security services.
- GCC (Global Compliance Certification)coreGCC is listed as a technology partner and accredited certification body providing ISO 27001 certification services. Insicon Cyber coordinates certification audits with GCC for clients achieving ISO 27001 certification.
- Citation CertificationcoreCitation Certification operates across Australia providing ISO certification services. Insicon Cyber has an established partnership with Citation as a preferred certification body for ISO 27001:2022 certification journeys.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Insicon competitors and assessment
Company assessmentBroad incumbents
- Trustwave: Global MSSP and MDR provider with ANZ presence, offering managed detection, response, and compliance services at greater scale — competes with Insicon's SOC/MDR layer and is often the alternative on enterprise RFPs.
- CrowdStrike Services: Global endpoint security and MDR provider with incident response and advisory services — competes with Insicon's MDR and SOC layers, especially where customers already standardise on the CrowdStrike platform.
- Palo Alto Networks Unit 42: Managed detection, response, and consulting arm of Palo Alto Networks — competes with Insicon on incident response, advisory, and managed security, particularly for customers already on Palo Alto technology.
- Arctic Wolf: Global MDR/MSSP vendor operating a Security Operations subscription model — competes with Insicon's aSOC and MDR offerings, particularly for mid-market ANZ customers seeking outsourced SOC.
- Deloitte Cyber (Australia): Big Four cybersecurity advisory and managed services practice in ANZ serving ASX-listed, financial services, and critical infrastructure clients — competes with Insicon on enterprise CISO advisory and large-scale managed engagements.
Direct peers
- Sekuro: Australia-based cybersecurity and digital resiliency advisory firm offering managed security, governance, risk, and ISO 27001 advisory — closely overlapping Insicon's CISOaaS and ISO certification service lines.
- Loop Secure: ANZ cybersecurity advisory and managed services firm providing board advisory, SOC, MDR, and Essential Eight maturity services — a near-direct comparable to Insicon's integrated advisory + operations model.
- Tesserent (Thales): ANZ-headquartered cybersecurity advisory and managed services provider (acquired by Thales) offering CISO advisory, SOC, MDR, and compliance services directly competing with Insicon across regulated sectors.
- CyberCX: Largest Australia- and New Zealand-focused cybersecurity services firm, offering managed security, advisory, and compliance services across similar verticals (financial services, critical infrastructure, government). Closest direct competitor to Insicon in the ANZ MSSP/advisory market, but at materially greater scale.
Emerging players
- Avertro: ANZ-headquartered cybersecurity governance, risk and compliance (GRC) software and advisory firm focused on ISO 27001, Essential Eight and board-level cyber reporting — competing with Insicon on the GRC/compliance layer.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Insicon social profiles
Digital presenceInsicon compliance and trust
Trust signalCompliance5 records
Insicon financial estimates
Financial estimateRevenue estimate
Valuation estimate
Insicon leadership team
Management profileNumber of profiles
Profiles2 records
Insicon funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Insicon M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Insicon
What does Insicon do?
Insicon Cyber is a trans-Tasman cybersecurity advisory and managed services firm that delivers strategic cyber governance advice (Fractional/Virtual CISO, board advisory, risk assessments) alongside 24/7 operational security services (adaptive SOC, MDR, Managed SIEM, Managed Compliance). It supports organisations in achieving and maintaining Essential Eight, ISO 27001, ISO 42001, ISO 9001, ISO 14001 and ISO 45001 certifications, and delivers tabletop and full cyber simulation exercises to test incident response.
Is Insicon a public or private company?
Insicon is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Insicon founded?
Insicon was founded in 2013. It employs 11 to 50 people.
Where is Insicon based?
Insicon is headquartered in North Sydney, Australia, in the Oceania region.
How does Insicon make money?
Five revenue lines are on record. Managed Security Services are the primary driver. The others are CISO as a Service (CISOaaS), ISO 27001 Compliance and Certification Advisory, tabletop and Cyber Simulation Exercises and essential Eight Assessment and Advisory.
Who are Insicon's main competitors?
Broad incumbents on record are Trustwave, CrowdStrike Services, Palo Alto Networks Unit 42, Arctic Wolf and Deloitte Cyber (Australia). Direct peers are Sekuro, Loop Secure, Tesserent (Thales) and CyberCX. Avertro is listed as an emerging player.
Does Insicon have an API?
No public API is recorded for Insicon.
What industry is Insicon in?
Insicon's product category is Cybersecurity Advisory and Managed Security Services. Its primary akta.pro industry code is BPAKAHAN, OT/ICS & Critical Infrastructure Cybersecurity Services, with a secondary code of HDADAIAJ, Security Awareness, Training & Compliance Attestation. Its NAICS code is 5415 and its SIC code is 7373.