Catalyst Cyber
Catalyst Cyber is a Canberra-based cybersecurity consultancy specializing in federal government cyber assurance, advisory, and compliance services, including IRAP, Essential Eight, offensive assurance, and security engineering, delivered by security-cleared personnel and now operating as a subsidiary of Infotrust Ltd.
- Company typePrivate
- Founded-
- HeadquartersCanberra, Australia
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Catalyst Cyber does
Catalyst Cyber is an Australian-owned cybersecurity consultancy headquartered in Canberra, specializing in federal government cyber assurance, advisory, and compliance services. The firm delivers seven core service lines: Governance, Risk and Compliance (GRC); Digital and Data; Offensive Assurance (including AI/LLM security testing, red and purple team engagements, cloud and web application penetration testing); Essential Eight maturity assessments against the ACSC framework; Framework Evaluation and IRAP assessments (covering ISM, NIST, PSPF, ISO 27001); Strategy and Planning (including virtual CISO); and Security Engineering (covering cloud, DevSecOps, SIEM/SOAR integration across AWS, Azure, and GCP). Delivery is anchored by 20 security-cleared personnel with government clearances and IRAP assessor accreditations, providing access to high-barrier federal cyber markets.
The company's revenue model is professional services–based, with engagement-based pricing for consulting, assessments, and advisory work, typical of the specialist cyber consultancy segment. Catalyst Cyber operates a direct enterprise/government field-sales motion, targeting federal government agencies as its primary vertical and Australian private-sector firms as a secondary segment. Following its March 2026 acquisition by ASX-listed Infotrust Ltd for approximately AUD $5 million (comprising AUD $3.5 million cash, AUD $1.5 million in Infotrust shares, plus an uncapped EBIT-linked earn-out), the firm now contributes as a wholly-owned subsidiary within Infotrust's sovereign Australian cyber capability. Expected annual revenue contribution is approximately AUD $1.3 million with underlying EBITDA of approximately AUD $0.3 million, implying a ~23% EBITDA margin at the acquisition baseline.
Catalyst Cyber firmographics
Firmographics- Name
- Catalyst Cyber
- Legal name
- Catalyst Cyber Pty Ltd
- Website
- https://catalystsec.com.au
- Company type
- Private
- Operating status
- Acquired
- Headcount range
- 11–50 employees
- Short description
- Catalyst Cyber is a Canberra-based cybersecurity consultancy specializing in federal government cyber assurance, advisory, and compliance services, including IRAP, Essential Eight, offensive assurance, and security engineering, delivered by security-cleared personnel and now operating as a subsidiary of Infotrust Ltd.
- Ownership category
- akta.pro rank
Catalyst Cyber industry classification
Industry- Product category
- Cybersecurity Consulting Services
- NAICS
- Computer Systems Design and Related Services (5415), Other Computer Related Services (541519)
- akta.pro primary industry
- Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF)
- akta.pro secondary industries
- IT Risk Management (ITRM) (HDADAIAD), Cyber Defense, Offensive Cyber & Information Operations Systems (IMABAOAC), Cyber Defense & Information Security (National Security) (BPAIAHAE), Security Awareness, Training & Compliance Attestation (HDADAIAJ)
Keywords
Where Catalyst Cyber is headquartered
LocationHeadquarters
- HQ city
- Canberra
- HQ country
- Australia
- HQ region
- Oceania
Offices1 record
Markets served
Catalyst Cyber business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales
Revenue model
- Cybersecurity Consulting Services: Professional services revenue from cybersecurity consulting including assessments, advisory, and compliance services for government and private sector clients. Expected annual revenue contribution of approximately $1.3 million following acquisition by Infotrust.
Go-to-market motion1 record
Distribution channels1 record
Marketing channels2 records
Catalyst Cyber product offering
Product offeringCore offering
Catalyst Cyber is an Australian-owned cybersecurity consultancy that delivers specialist cyber assurance, advisory, and compliance services to Australian federal government agencies and private sector clients. The firm offers seven service lines: Governance Risk and Compliance, Digital and Data, Offensive Assurance (penetration testing, red/purple team, AI/LLM and cloud adversary simulation), Essential Eight maturity assessments, Framework Evaluation and IRAP, Strategy and Planning including virtual CISO, and Security Engineering, delivered by security-cleared personnel.
Product overview
Catalyst Cyber is an Australian-owned cyber security consultancy offering a portfolio of seven specialized service offerings. The services include Governance, Risk and Compliance (GRC); Digital and Data transformation; Offensive Assurance (penetration testing and red team services); Essential Eight assessments aligned with ACSC maturity model; Framework Evaluation and IRAP assessments; Strategy and Planning; and Security Engineering. These services are delivered by security-cleared personnel and are tailored for federal government and private sector clients requiring high-assurance cyber security capabilities.
Differentiator
Problem solved
Functional benefit
Products and services
- Governance, Risk and Compliance (GRC) Comprehensive GRC solutions for organisations including governance framework development, risk management and assessment, compliance program management, policy documentation, risk register and treatment planning, regulatory mapping, and GRC technology implementation, targeted at federal government and private sector clients.
- Digital and Data Digital transformation and data services including digital strategy, legacy system modernisation, data analytics and business intelligence, machine learning implementation, and technology architecture, for clients pursuing secure digital modernisation.
- Offensive Assurance Comprehensive offensive security testing services including AI and LLM security testing, red team engagements, purple team, assumed breach, physical security, network infrastructure testing, web application and API testing, cloud security testing, build hardening, secure code review, vulnerability assessment, and wireless infrastructure assessments for government and enterprise clients.
- Essential Eight End-to-end Essential Eight services assessing the eight ACSC mitigation strategies including application control, patch applications, restrict Microsoft Office macros, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups, aimed at federal government and Australian private sector clients.
- Framework Evaluation and IRAP Framework evaluation and Information Security Registered Assessor Program (IRAP) services covering IRAP assessments, ISM compliance, NIST Framework assessment, ISO 27001 implementation and certification support, PSPF compliance, and gap analysis and remediation planning for government and enterprise organisations.
- Strategy and Planning Strategic cyber security planning services including cyber strategy development, current state assessment, risk-based roadmap planning, governance and operating model design, business alignment and engagement, and continuous review and advisory including virtual CISO services for organisations seeking cyber resilience uplift.
- Security Engineering Security architecture and engineering services covering security tooling and automation, SIEM and SOAR integration, security architecture and design, secure configuration and hardening, DevSecOps, cloud and infrastructure security across AWS, Azure and GCP, and continuous improvement and uplift.
Quantifiable outcome
- Expected to contribute approximately $1.3 million in annual revenue
- +1 more outcomes
Companies that use Catalyst Cyber
Customer profileNamed customers2 records
Segments2 records
Ideal customer profiles2 records
Catalyst Cyber technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability1 record
Feature6 records
Catalyst Cyber partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- Infotrust Ltd (ASX: ITS)coreInfotrust Ltd acquired 100% of Catalyst Cyber in a performance-linked transaction valued at approximately AUD $5 million. The acquisition provides Infotrust immediate entry into high-barrier federal government cyber security markets, strengthening its position as a sovereign Australian cyber security provider focused on regulated and high-assurance environments. Catalyst Cyber brings established agency relationships, security-cleared personnel, and specialist accreditations for IRAP assessments and the Essential Eight framework.
Scale indicators5 records
Expansion highlights4 records
Catalyst Cyber competitors and assessment
Company assessmentDirect peers
- Tesserent: Australian cybersecurity consulting and managed services firm (now part of Thales) with deep federal government footprint, IRAP assessor status, and full GRC/offensive assurance/IRAP capabilities. Closely comparable to Catalyst in service mix and customer base.
- CyberCX: Australia's largest sovereign cybersecurity services firm, headquartered in Melbourne with significant Canberra presence. Offers GRC, offensive security, IRAP, Essential Eight, and managed security services to federal government and enterprise — directly comparable offerings and customer base to Catalyst Cyber.
- NCC Group: Global cybersecurity consulting firm offering GRC, offensive assurance, IRAP-equivalent assessments, and managed security. Comparable service mix and consulting-led business model to Catalyst, with similar exposure to regulated government clients.
- Loop Secure: Canberra-based Australian cybersecurity consultancy specialising in federal government and Defence ICT, with IRAP and offensive security offerings. Direct head-to-head competitor in Catalyst's primary segment and geography.
- Sekuro: Australian cybersecurity consultancy providing GRC, offensive security, cloud security, and IRAP-adjacent advisory services to government and enterprise. Comparable boutique scale and service portfolio to Catalyst Cyber.
Broad incumbents
- Trustwave: Global cybersecurity firm providing GRC, offensive security, managed detection, and IRAP-style assessments. Overlaps with Catalyst in consulting-led advisory offerings, though typically at larger enterprise scale.
- BAE Systems Australia: Major defence prime with a substantial Australian cyber and intelligence business, employing security-cleared personnel to deliver IRAP, GRC, and security engineering to federal agencies. Competes for the same large federal contracts Catalyst supports as a sub-contractor.
- Mandiant (Google Cloud): Global incident response, threat intelligence, and cyber advisory firm (now part of Google Cloud). Provides IRAP, GRC, and offensive assurance at much larger scale, competing for high-end federal and enterprise engagements Catalyst targets.
- Thales Australia: Defence and digital security prime operating in Australia, with cyber and GRC capabilities serving federal government. Comparable customer set and regulatory positioning, but at vastly greater scale and breadth.
Regional players
- Aurecon / Slalom (cyber practices): Large international consulting firms with Australian cyber advisory practices serving federal government and enterprise on GRC, IRAP, and digital transformation. Comparable in service type but operate as part of broader consulting firms, often competing for advisory-led engagements.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Catalyst Cyber social profiles
Digital presenceCatalyst Cyber financial estimates
Financial estimateRevenue estimate
Valuation estimate
Catalyst Cyber leadership team
Management profileNumber of profiles
Catalyst Cyber funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Catalyst Cyber M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Catalyst Cyber
What does Catalyst Cyber do?
Catalyst Cyber is an Australian-owned cybersecurity consultancy that delivers specialist cyber assurance, advisory, and compliance services to Australian federal government agencies and private sector clients. The firm offers seven service lines: Governance Risk and Compliance, Digital and Data, Offensive Assurance (penetration testing, red/purple team, AI/LLM and cloud adversary simulation), Essential Eight maturity assessments, Framework Evaluation and IRAP, Strategy and Planning including virtual CISO, and Security Engineering, delivered by security-cleared personnel.
Is Catalyst Cyber a public or private company?
Catalyst Cyber is a private company. It is classified as corporate owned and is currently acquired.
When was Catalyst Cyber founded?
Catalyst Cyber was founded in -1. It employs 11 to 50 people.
Where is Catalyst Cyber based?
Catalyst Cyber is headquartered in Canberra, Australia, in the Oceania region.
How does Catalyst Cyber make money?
One revenue line is on record: cybersecurity Consulting Services.
Who are Catalyst Cyber's main competitors?
Direct peers on record are Tesserent, CyberCX, NCC Group, Loop Secure and Sekuro. Broad incumbents are Trustwave, BAE Systems Australia, Mandiant (Google Cloud) and Thales Australia. Aurecon / Slalom (cyber practices) is listed as a regional player.
Does Catalyst Cyber have an API?
No public API is recorded for Catalyst Cyber.
What industry is Catalyst Cyber in?
Catalyst Cyber's product category is Cybersecurity Consulting Services. Its primary akta.pro industry code is BPAHAFAF, Privacy, Data Protection & Cyber Governance (GRC), with a secondary code of HDADAIAD, IT Risk Management (ITRM). Its NAICS code is 5415.