dotSec: Learn more about us

A brief history

dotSec started out in January of 2000. Back then, infosec (now we call it cyber) was relatively new in the commercial world, and so our first clients were mostly at the big end of town:  Federal government (really just one department), Telcos, regulators and software/system developers.  Some of our initial projects included:

  • Assistance with security for the national mobile number portability scheme.
  • Support for cryptographic services for APRA’s D2A project.
  • Security architecture work.

Now, a quarter of a century later, cyber security is generally understood to be important to the ongoing viability and resilience of all businesses and individuals. There is a lot that is new (consider for example AI, Cloud-services and post-quantum crypto) but there’s also a lot (software supply-chain risks and, who could forget, passwords!) that remains pretty much the same.  

What has certainly changed though is that security now is big business!  And where there is lots of money to be made, there is lots of temptation to cut corners and push silver-bullet solutions for a percentage cut.  That’s where dotSec is different.  For over 25 years, we have worked as a collaborative partner, enhancing our clients’ capabilities and working together to support security-maturity improvements, even if there are no licenses or products to be sold.  But don’t just take our word for that:  We’ve worked with our oldest client for over 20 years, our average client-retention time is around 10 years, and we have lots of references that we can share to bona fide enquiries.  

25 years in and we’re still improving our processes, skills, knowledge and effectiveness.  We look forward to working with you. 

dotSec's culture

dotSec’s culture, summarised in one sentence:

“A good working environment for smart people to achieve great outcomes”

But what does “good”, “smart” and “great” mean?

Good

A good working environment is one where everyone is encouraged to grow, collaborate and excel, where everyone is treated with respect and dignity, and where people can grow their professional careers without putting their personal lives and interests at risk or on hold.

Smart

Smart people think deeply and consider consequences and alternative approaches before acting; they also crave knowledge and intellectual challenge, and so training is integral to the dotSec vision of creating a good working environment for smart people. To that end, dotSec provides significant opportunities for training and staff are highly qualified to deliver assessment and testing, managed security, and governance, risk and compliance services.

dotSec’s team members hold degrees and credentials from leading universities, industry suppliers and organisations, including:

  • Payment Card Industries Security Standards Council (PCI SSC) Qualified Security Assessor (QSA)
  • Splunk; Enterprise Administrator, Enterprise Security Administrator, Cyber Security Defence Analyst
  • Professional Evaluation and Certification Board (PECB); ISO/IEC 27001 Lead Implementer, and Lead Auditor
  • Information Systems Audit and Control Association Certified Information; Systems Auditor (CISA), Security Manager (CISM), Risk and Information Systems Control (CRISC), and Data Privacy Solutions Engineer (CDPSE)
  • Bachelors, Masters and PhD degrees in computer science, mathematics and physics.

Our training program is aggressive, and we spend lots of time and money to improve the skills of everyone that works in our team.

Great

Which leads us to great outcomes. Great outcomes are achieved when smart people collaborate in a good environment, and when the customer’s expectations are met or exceeded in every engagement, project or task.  

DotSec can only rely on our customer’s feedback to know for sure that great outcomes have been achieved, and the testimonials (included below) that have been provided indicate that is the case.

OUR CYBER SERVICES