Cybersecurity & secure AI · Defending Australian business since 2018

We hunt the threat before it finds you.

Continuous monitoring, threat hunting and incident response for Australia's most regulated businesses — and the sovereign, secure foundation for the AI you're about to run.

We defend to Essential Eight ISO/IEC 27001 APRA CPS 234 NIST CSF 2.0 Privacy Act 1988

The attacker only needs to be right once.

01 / The threat
Their reality
One click on one phishing email is a foothold. From there it's hours to your domain controllers.
Your reality
The board, the regulator and your customers all assume someone is watching. Most of the time, no one is.
Threats don't keep office hours, and a part-time defence is no defence. QROM is the team watching while you sleep — hunting, detecting and shutting it down before it becomes the incident you have to disclose.

One partner across the whole defensive line.

02 / What we do
SecOps

Continuous monitoring & response

Monitor · Hunt · Respond

Around-the-clock monitoring across endpoints, identity and cloud, with proactive threat hunting and rapid human response when something fires — so threats are found and contained, not discovered in the post-mortem.

IR

Incident Response & Forensics

Contain · Investigate · Recover

When it happens, we're the call you make first. Rapid containment, forensic evidence packs, and a clear account of what occurred — with the documentation your insurer and regulator will demand.

GRC

Compliance & Hardening

Essential Eight · ISO 27001 · CPS 234

Tenant hardening, conditional access, email authentication and the controls that pass an audit. We close the gaps mapped to the frameworks your industry answers to — and prove it on paper.

Built for the industries that can't afford to be wrong.

03 / Industries
Financial services

Banking, fintech & advice

APRA CPS 234 obligations, payment data, and fraud exposure — defended and evidenced to the standard your regulator expects.

Healthcare & NDIS

Care providers

Patient and participant data carries privacy obligations and real human stakes. We protect it and keep the audit trail clean.

Legal & professional

Firms & advisors

Your clients' confidential data is your reputation. A breach is a trust event, not just an IT event — we treat it that way.

Government-adjacent

Suppliers & contractors

Winning and keeping public-sector work increasingly means provable Essential Eight maturity. We get you there and keep you there.

Property & construction

Builders & developers

High-value payments make you a prime target for business email compromise. We close the gaps attackers exploit for invoice fraud.

Professional SMB

Growing businesses

Too big to ignore, too lean for a security team. We are your security team — enterprise-grade defence, sized to you.

Anatomy of a breach — and where we break it.

04 / The kill chain
01
Phishing email landsAn employee clicks. Malware installs.
Caught at delivery
02
Foothold establishedCredentials harvested from the device.
Detected on endpoint
03
Lateral movementAttacker moves across the network via RDP and stolen logins.
Flagged in identity
04
Privilege escalationDomain controllers compromised, accounts seized.
Contained & isolated
05
Ransomware deployedServers encrypted. Data held hostage.
Never gets here
QROM breaks the chain at every link — and the earlier the link, the cheaper the outcome. Most attackers monitored by us never get past the first.

Where you sit on the Essential Eight — and how we move you up.

05 / Essential Eight

The Essential Eight is the Australian Signals Directorate's security baseline — eight mitigation strategies, scored across four maturity levels (ML0–ML3).

Most businesses assume they're at Level One. Most are at Level Zero on at least one control. And winning government and enterprise work increasingly means proving your maturity, not asserting it.

QROM assesses your real maturity across all eight, closes the gaps in priority order, and hands you the evidence to show an auditor, board or insurer.

ML0
Gaps a common attacker can walk straight through
ML1
Resilient to widespread, opportunistic attacks
ML2
Resilient to attackers willing to invest more effort
ML3
Resilient to adaptive, well-resourced adversaries
Control 01

Application control

Only approved applications are allowed to run.

Control 02

Patch applications

Known-exploited app vulnerabilities patched fast.

Control 03

Configure Office macros

Macros blocked or tightly restricted by default.

Control 04

User application hardening

Browsers and Office locked down; risky content blocked.

Control 05

Restrict admin privileges

Admin rights limited to those who need them, and reviewed.

Control 06

Patch operating systems

Critical OS vulnerabilities patched on a tight clock.

Control 07

Multi-factor authentication

Phishing-resistant MFA on every account that matters.

Control 08

Regular backups

Backed up, isolated, and restore-tested — not assumed.

Maturity-level descriptions are summarised. QROM aligns to the ACSC Essential Eight Maturity Model and presents findings as advisory; we are not an accredited assessment body.

Where do you sit on the Essential Eight?

06 / Maturity check
Six questions. Sixty seconds.
Not started
A quick check against the Essential Eight controls. Indicative only — anonymous, nothing is sent or stored.
Indicative read:
Book a security review

When it happened, we were the first call.

07 / Proof
Incident response · illustrative
Business email compromise, contained
Sydney professional-services firm · Microsoft 365
Same day
From detection to full containment
Stopped
Fraudulent payment blocked before release
Hardened
Tenant locked down so it couldn't recur
An attacker was already inside the mailbox, quietly watching invoices and preparing to redirect a payment.

QROM detected the anomalous sign-in pattern, confirmed the business email compromise, and contained it before a fraudulent invoice could be paid — isolating the account, expelling the attacker, and preserving forensic evidence.

We then hardened the tenant so it couldn't recur: enforced conditional access and MFA, fixed email authentication (DKIM, DMARC, SPF), and stood up a break-glass admin account with monitoring on top.

Illustrative scenario, representative of QROM incident-response work. Replace with a real, permissioned client engagement before publishing.

The AI you deploy is now part of your attack surface.

08 / Secure AI

We secure the AI, not just the network around it.

Every model, prompt pathway and data pipeline you stand up is a new way in — and a new question your auditor will ask. QROM extends the same discipline that protects your network to the AI running on top of it.

Sovereign by default. Inference and data stay onshore. Governance, access controls and audit trails are built in, not bolted on — so the AI you run can survive the same scrutiny everything else in your estate does.

  • Sovereign AI infrastructure
  • Model & data security
  • AI governance & audit trails
  • Access & identity controls
The AI practice of QROM

Need the AI itself designed, built and deployed?

That's QuietTango — our AI practice. Secure, audit-ready, sovereign AI for regulated businesses: strategy, readiness audits and production deployment. QROM secures it; QuietTango builds it. One partnership, both sides of the line.

Meet QuietTango →

Nobody gets blamed for calling QROM.

09 / Why QROM

We've been defending Australian businesses since 2018 — through real breaches, real incident response, and real audits.

That track record is the point. When the spend lands on someone's desk to justify, bringing in the partner your security already runs through is the defensible call — before an incident, and especially after one.

Onshore. Always on. Specialist, not generalist.

2018
On the clock for Australian business every year since
24×7
Monitoring runs around the clock; response is rapid and human
AU only
Sovereign by default — detection and data stay onshore
Hours
Incident containment measured in hours, not days

What we're seeing.

10 / Field notes
Ransomware

Identity is the new perimeter

Most breaches we see don't start with malware — they start with a stolen login and weak MFA. The cheapest control with the biggest payoff is still phishing-resistant authentication on every account.

Email fraud

The invoice in your inbox may not be real

Business email compromise quietly costs Australian firms more than ransomware. Attackers watch, wait, and redirect a single payment. Email authentication (SPF, DKIM, DMARC) and payment-change verification stop most of it.

AI security

You're adopting AI faster than you're securing it

Every model and data pipeline you add is new attack surface and a new audit question. Treat AI like any other production system: access controls, logging, and data that stays onshore.

Straight answers.

11 / FAQ

A fixed-scope assessment of your real exposure — external attack surface, identity and access, endpoint coverage, email and cloud configuration — measured against the Essential Eight and the frameworks your industry answers to. You get a board-ready report with what's exploitable now, your indicative Essential Eight maturity level, quick wins, and a prioritised fix-it order. (See "The security review" above for the full picture.)

Yes. We're built for the organisations too big to ignore security but too lean for a full in-house team. You get enterprise-grade defence sized to you, not a tool you have to run yourself.

Onshore. Australian data sovereignty is a default, not an upgrade — your detection data and any AI infrastructure stay in Australia.

That's core to what we do. We assess your current maturity, close the gaps with concrete hardening, and produce the evidence your auditor, board or insurer needs.

We're the call you make first. Rapid containment, forensic investigation, recovery, and the documentation your insurer and regulator will require — handled with the goal of telling your stakeholders before anyone else does.

What a security review actually is.

12 / The security review

A fixed-scope assessment — not a sales call. We examine what an attacker would: your external attack surface, identity and access, endpoint coverage, email authentication, backups, and your maturity across all eight Essential Eight controls.

You leave with a board-ready report — what's exploitable now, your indicative Essential Eight maturity, the quick wins, and a prioritised plan to close the gaps. Fixed fee, fixed scope, no surprises.

Fixed
Fixed fee and scope agreed up front
Onshore
Australian team, Australian data
Board-ready
A report you can hand to leadership or your insurer
No lock-in
The fixes are yours, whoever implements them
Step 01

Scope

A short call

We confirm boundaries, access and what matters most to you. You get a fixed fee and a clear scope before anything starts.

Step 02

Assess

The technical work

We test what's actually exploitable and measure your maturity across all eight Essential Eight controls — evidence, not assumptions.

Step 03

Report & roadmap

What you keep

A board-ready report: what's exposed now, your indicative maturity level, quick wins, and a prioritised plan to close the gaps.

Before the incident — not after

Find out what's already on your network.

Start with a security review — pick a time and we'll show you where you stand, what's exposed, and what to fix first.

Prefer email, or want to talk first? Contact QROM →