Phronesis Security
Phronesis Security is an Australian cybersecurity consulting firm delivering penetration testing, security architecture, GRC, security awareness, and vCISO services to government agencies, critical infrastructure providers, and mid-market enterprises across Australia.
- Company typePrivate
- Founded2021
- HeadquartersMelbourne, Australia
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Phronesis Security does
Phronesis Security is an Australian cybersecurity consulting firm headquartered in Melbourne, founded in 2021. The company delivers five core consulting service lines: Governance, Risk and Compliance (GRC); Penetration Testing and Red Teaming; Security Architecture; Security Awareness and Education; and Strategy and Management, including a virtual Chief Information Security Officer (vCISO) offering. Engagements span threat and risk assessments, ISO 27001, NIST CSF, IRAP and ISM, SOC 2 reporting, PCI-DSS support, and red-team simulations across internal, external, cloud, web application, IoT, and AI environments. The firm applies established frameworks (TOGAF, COBIT, SABSA, OSA, CMMI, MITRE ATT&CK, OWASP Top 10) rather than proprietary technology, differentiating through a tailored security architecture methodology and CREST-certified penetration testing.
The firm's primary customer base comprises Australian federal and state government agencies, critical infrastructure providers, and values-aligned mid-market and enterprise organisations. Named engagements include the Australian Department of Defence, the Australian Cyber Security Centre (ACSC), NSW Government agencies, an Australian critical infrastructure provider with approximately AUD$400 million annual turnover, and a health and community services non-profit. Marketing relies on thought leadership, media commentary, certifications, and awards (AISA, AWSA, Telstra Business Awards, Technology Scale-Up Awards) rather than paid acquisition.
Phronesis operates on a professional services revenue model with quote-based pricing, project-based engagements, and multi-year retainer arrangements. The firm holds CREST certification and is Australia's first B Corp certified cyber security company, with a 2025 recertification score of 116.3 and a structural commitment to donate 10% of profits to high-impact charities. The company was acquired by Bastion in December 2025 in an undisclosed-value deal.
Phronesis Security firmographics
Firmographics- Name
- Phronesis Security
- Legal name
- Phronesis Security Pty Ltd
- Website
- https://phronesissecurity.com
- Company type
- Private
- Founded year
- 2021
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- Phronesis Security is an Australian cybersecurity consulting firm delivering penetration testing, security architecture, GRC, security awareness, and vCISO services to government agencies, critical infrastructure providers, and mid-market enterprises across Australia.
- Ownership category
- akta.pro rank
Phronesis Security industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Investigation and Security Services (5616)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Penetration Testing, Red Team & Ethical Hacking (EDAOAIAH)
Keywords
Where Phronesis Security is headquartered
LocationHeadquarters
- HQ city
- Melbourne
- HQ country
- Australia
- HQ region
- Oceania
Offices1 record
Markets served
Phronesis Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Marketing or Sales, Operations, Others
Revenue model
- Cybersecurity Consulting Services: Professional services revenue generated through consulting engagements including vCISO services, penetration testing, security architecture, GRC programs, and security awareness training. Services are delivered to government agencies, critical infrastructure providers, and enterprises.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom consulting engagements |
Go-to-market motion2 records
Distribution channels1 record
Marketing channels3 records
Phronesis Security product offering
Product offeringCore offering
Phronesis Security is a cybersecurity consulting firm delivering penetration testing and red teaming, security architecture, governance risk and compliance (GRC), security awareness training, and strategy and management services including virtual CISO offerings. Services are delivered to government agencies, critical infrastructure providers, and enterprises across Australia.
Product overview
Phronesis Security is a cybersecurity consulting firm, not a software product company. The company offers five core consulting service lines: Penetration Testing and Red Teaming (simulating cyberattacks to identify vulnerabilities across internal, external, cloud, web application, IoT, and AI environments), Security Architecture (enterprise security architecture, security solutions, assessments, and engineering), Governance Risk and Compliance (risk mitigation and compliance programs including ISO 27001, NIST CSF, and IRAP), Security Awareness and Education (workforce cyber security training), and Strategy and Management (virtual CISO services and security advisory). These services are delivered by an award-winning team with world-class qualifications and are designed to make cyber security a business enabler rather than an obstacle.
Differentiator
Problem solved
Functional benefit
Products and services
- Penetration Testing and Red Teaming Simulates cyberattacks to identify vulnerabilities and test defenses using the same tools, tactics, and techniques as adversaries. Covers internal, external, cloud, web application, IoT, and AI penetration testing. CREST certified.
- Security Architecture Develops principles, methods, tools, and frameworks to protect organizational assets from threats. Includes enterprise security architecture, security solutions architecture, security architecture assessment, configuration assessment, security engineering, and security operations, combining TOGAF, COBIT, SABSA, OSA, and CMMI frameworks.
- Governance, Risk and Compliance Cost-effective solutions for mitigating risks and achieving compliance goals. Includes threat and risk assessments, ISO 27001 compliance programs, NIST CSF maturity assessments, IRAP and ISM assessments, SOC 2 reporting, and PCI-DSS SAQ support.
- Security Awareness and Education Highly modular and impactful campaigns to empower and educate workforces about cyber security, including training tailored to specific user groups based on policy, internal processes, and business risk exposure.
- Strategy and Management Virtual CISO (vCISO), pragmatic security strategies and programs, and advisory on-demand. Includes security management and reporting, on-demand advisory, organization-wide threat modelling, security strategy definition, security maturity roadmapping, and budget analysis and planning.
Quantifiable outcome
- 14-point improvement in B Corp score (102.2 to 116.3) in 2025 recertification
- +2 more outcomes
Companies that use Phronesis Security
Customer profileNamed customers6 records
Segments3 records
Ideal customer profiles3 records
Phronesis Security technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability1 record
Feature2 records
Phronesis Security partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- BastionacquisitionPhronesis Security was acquired by Bastion in December 2025. This is an undisclosed-value acquisition focused on expanding digital security capabilities. Bastion is an Australian cybersecurity firm acquiring Phronesis to strengthen its service offerings.
Scale indicators5 records
Recent moves6 records
Expansion highlights5 records
Phronesis Security competitors and assessment
Company assessmentBroad incumbents
- CyberCX: Australia and New Zealand's largest dedicated cybersecurity services firm, offering consulting, advisory, managed detection/response, and penetration testing across all sectors including government and critical infrastructure. Directly comparable service portfolio to Phronesis, with significantly greater scale.
- Bastion: Australian-owned digital, cyber, and technology consultancy that acquired Phronesis Security in December 2025. Operates an overlapping cybersecurity consulting and advisory practice, and is now the parent platform for Phronesis's service lines.
- Deloitte Australia (Cyber): Big 4 firm with a substantial Australian cyber risk advisory practice spanning GRC, technical security testing, and vCISO. Competes for the same government and enterprise mandates as Phronesis, with much greater scale.
- KPMG Australia (Cyber): Big 4 advisory practice with a large Australian cyber security consulting arm covering GRC, penetration testing, and security strategy for government and enterprise. Overlaps with Phronesis on consulting services but operates as part of a wider advisory portfolio.
Direct peers
- Content Security: Australian cybersecurity consultancy providing penetration testing, GRC, security architecture, and managed security services. Comparable Australian mid-market peer in the consulting space.
- Ionize: Boutique Australian cybersecurity consultancy delivering security architecture, penetration testing, GRC, and vCISO services. Directly comparable in service lines and SMB positioning.
- Shearwater Solutions: Australian cybersecurity consultancy offering penetration testing, security advisory, GRC, and security architecture services to government and enterprise clients. Closely comparable in size, service mix, and target verticals.
- Insomnia Security: Trans-Tasman cybersecurity consultancy (NZ and Australia) providing penetration testing, red team, security advisory, and managed security services. Comparable niche specialist in the Australia/NZ consulting market.
- CQR Consulting: Australian cybersecurity consultancy specializing in penetration testing, red team, and security advisory services. Comparable niche boutique competitor in the Australian pentesting market.
- Loop Secure: Australian cybersecurity consultancy offering security advisory, GRC, penetration testing, and vCISO services to government and enterprise. Directly comparable in service mix and target market.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Phronesis Security social profiles
Digital presencePhronesis Security compliance and trust
Trust signalCompliance12 records
Phronesis Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
Phronesis Security leadership team
Management profileNumber of profiles
Profiles5 records
Phronesis Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Phronesis Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Phronesis Security
What does Phronesis Security do?
Phronesis Security is a cybersecurity consulting firm delivering penetration testing and red teaming, security architecture, governance risk and compliance (GRC), security awareness training, and strategy and management services including virtual CISO offerings. Services are delivered to government agencies, critical infrastructure providers, and enterprises across Australia.
Is Phronesis Security a public or private company?
Phronesis Security is a private company. It is classified as corporate owned and is currently acquired.
When was Phronesis Security founded?
Phronesis Security was founded in 2021. It employs 11 to 50 people.
Where is Phronesis Security based?
Phronesis Security is headquartered in Melbourne, Australia, in the Oceania region.
How does Phronesis Security make money?
One revenue line is on record: cybersecurity Consulting Services.
Who are Phronesis Security's main competitors?
Broad incumbents on record are CyberCX, Bastion, Deloitte Australia (Cyber) and KPMG Australia (Cyber). Direct peers are Content Security, Ionize, Shearwater Solutions, Insomnia Security, CQR Consulting and Loop Secure.
Does Phronesis Security have an API?
No public API is recorded for Phronesis Security.
What industry is Phronesis Security in?
Phronesis Security's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is EDAOAIAH, Penetration Testing, Red Team & Ethical Hacking. Its NAICS code is 5616 and its SIC code is 7370.