We're an Australian cybersecurity company that helps businesses get certified and stay protected, without the complexity or the budget surprises.
Australian team, every engagement. Every person you work with is based in Australia. No offshore outsourcing, no language barriers, no chasing responses across time zones. When you call, you speak to the people doing the work.
We service all of Australia. It doesn't matter where you're based; we work with clients in every state and territory.
Fixed pricing, no budget creep. Our services are delivered as fixed-price packages, so you know exactly what you're paying before we start. No day-rate consulting, no surprise invoices.
Certified specialists, not generalists. Our penetration testers and compliance consultants hold industry-recognised certifications. You're getting people who know what auditors expect, because they've done this hundreds of times.
I started Siege Cyber with a simple goal: to help Australian businesses get cybersecurity right without the complexity, the jargon, or the budget blowouts.
After 25 years in this industry, I've seen too many companies pay for advice they can't action, or get handed a compliance certificate that doesn't actually make them safer. That's not how we operate.
At Siege Cyber, we do two things really well: we test your defences through penetration testing, and ensure you PASS and MAINTAIN compliance certifications like ISO 27001 and SOC 2. We do it at a fixed price, on a clear timeline, and we stick with you until it's done.
Our goal is straightforward: we want to be the cybersecurity partner that Australian businesses actually trust to get them across the line.
If that sounds like what you're looking for, I'd love to have a chat.
Every consultancy publishes a values list. These are ours written as things you can hold us to, rather than words.
The person who tests writes the report. No handoff to a report writer who was not in the engagement, and no account manager fielding your technical questions afterwards. You talk to whoever found the finding.
Fixed price, fixed scope. The number in the proposal is the number on the invoice. Scope is written down in enough detail that neither side can be surprised by it later.
We will tell you when you do not need the work. Advisory engagements regularly end with a recommendation to do something smaller, or to close known gaps before testing rather than paying us to confirm them. That costs us revenue in the short term and it is the main reason clients come back.
Findings ranked by what they would let an attacker do. Not by a scanner score. A report your engineers can act on and your auditor will accept, with reproduction steps and specific remediation.
Australian team, every engagement. Every person who touches your environment is based in Australia. No offshore subcontracting and no time zone gaps.
Accreditation you can verify. Siege Cyber is a CREST-accredited company for penetration testing. You can confirm that yourself on the CREST Australia New Zealand approved companies register rather than taking our word for it.
Through direct collaborations with businesses and managed service providers, we have delivered comprehensive cyber security services, advisory and penetration testing to various industries, including manufacturing, commercial, legal, and various others.
Our expertise spans a broad spectrum, allowing us to cater to the unique cyber security needs of organisations across different sectors.
Siege Cyber is an Australian cyber security consultancy based in Brisbane. It delivers two things: CREST accredited penetration testing across networks, web applications, APIs, mobile applications and cloud environments, and fixed-price certification programmes that take organisations to ISO 27001, SOC 2 or ISO 42001.
Yes. Siege Cyber is the trading name of Siege Group Pty Ltd, ABN 14 639 942 877, based at Level 27, 32 Turbot Street, Brisbane, Queensland. Every person who works on an engagement is based in Australia. There is no offshore subcontracting.
Siege Cyber is a CREST-accredited company for penetration testing, which is assessed and held at company level and can be verified on the CREST Australia New Zealand approved companies register. It also holds SMB1001 Gold Level 3 and was a finalist in the 2025/2026 Australian Cyber Awards. CREST accredits companies and certifies individuals, and accreditation is granted separately by discipline.
Engagements are led by Peter Stewart, the founder and Managing Director, who holds CISSP and MAICD and has more than twenty years in cyber security including senior engineering roles at SentinelOne. The person who does your testing is the person who writes your report and answers your questions afterwards.