Three segments. One specialist practice.

Built for organisations
with obligations they can't ignore

Outplat is a specialist GRC practice. We focus on three types of WA organisations that share a common challenge — external compliance pressure with no internal cyber team to manage it. Our team span the full spectrum: regulatory frameworks, compliance management, and Australian obligations on one side — cloud security engineering, DevSecOps, AI engineering, and application security on the other. Most GRC firms advise. We can also build.

Practice credentials
CISSP ISO 27001 Lead Auditor ISO 42001 AI Governance AWS Certified Security Specialist AWS Solutions Architect CrowdStrike Certified Cloud Specialist AI Engineering DevSecOps & SAST/DAST/SCA Cloud Security — CSPM & CNAPP Threat Intelligence Engineering Application Security & Penetration Testing ITIL Foundation OWASP Open Source Contributor DISP-experienced practitioners Australian regulatory specialists
Mining & Resources

WA contractors supplying
the resources sector

BHP, Rio Tinto, Fortescue, and Chevron are tightening their supply chain security requirements. If you supply them, your compliance obligations are no longer optional — they're a condition of doing business.

  • Received an Essential Eight maturity questionnaire from a tier-1 client with a 30-day deadline
  • No dedicated cyber or IT security staff — compliance falls on the IT manager or CFO
  • Contract renewal at risk if you can't demonstrate ML2 compliance
  • Unsure which controls you actually need vs what you're being asked to self-attest
  • Previous attempts to use a generalist IT company resulted in failed assessments
Frameworks our team manages for this segment
Essential Eight ML1–ML3ISO 27001Privacy Act / APPSOCI Act
Why mining contractors choose Outplat
30+
days — typical deadline for supply chain questionnaires
ML2
Minimum maturity level required by most tier-1 contractors
3wk
Typical time to complete our readiness assessment
1
Fixed monthly retainer — no billing surprises

"Our tier-1 client just sent a compliance questionnaire and we have no idea where to start."

How would you like to engage?
Defence Supply Chain

Contractors pursuing
DISP membership

DISP membership is mandatory to hold or bid for Defence contracts in Australia. With AUKUS driving significant new opportunities in Western Australia, more WA businesses are seeking DISP — but the application and ongoing compliance is complex.

  • Need DISP membership to bid for a specific Defence contract or prime contractor subcontract
  • DISP applications take 90+ days — unsure how to start or what's required
  • Essential Eight ML2 required for DISP but no internal security capability
  • Holding DISP but struggling to maintain the ongoing security obligations
  • AUKUS opportunities visible but compliance readiness is a barrier
Frameworks our team manages for this segment
DISPEssential Eight ML2PSPFISO 27001
Why defence contractors choose Outplat
90+
days — minimum DISP application processing time
ML2
Essential Eight level required for DISP membership
3
Frameworks typically required: E8, PSPF, ISO 27001
2
Principals managing your obligations end-to-end

"We need DISP membership to bid for this Defence contract but we don't have a security team."

How would you like to engage?
Anglican & Independent Schools

Schools managing
student data obligations

Your school holds sensitive personal data on thousands of students and families. Under the Privacy Act, you have significant obligations — and with 2024 reforms dramatically increasing penalties, the cost of non-compliance is no longer theoretical.

  • Small IT team with no dedicated privacy or security compliance capability
  • Board or diocese requesting evidence of Privacy Act and cyber compliance
  • Cyber insurance requiring evidence of Essential Eight controls at renewal
  • Data breach headlines in the education sector creating board-level anxiety
  • No budget for a full-time security hire — fixed monthly fee model is attractive
Frameworks our team manages for this segment
Privacy Act / APPEssential EightISO 27001
Why schools choose Outplat
$50M
Maximum penalty for serious Privacy Act breach (2024 reforms)
16+
Anglican schools across WA, VIC and NSW in our network
1
Fixed monthly fee your board can approve
0
Internal cyber hires required

"Our school holds data on thousands of students and I'm not confident we're meeting our Privacy Act obligations."

How would you like to engage?
Get Started

Not sure which engagement
fits your situation?

Book a free 30-minute discovery call with our team. We'll tell you exactly which frameworks apply to your organisation, which engagement model makes sense, and what it would take to get compliant.

Talk to our team See all services