Skip to content
Specialist Security Providers Carve Out Cyber Security Niches

Specialist Security Providers Carve Out Cyber Security Niches

www.arnnet.com.au • October 9, 2026

As Australian organisations grapple with the shift in cybersecurity from an IT issue to governance, risk and compliance, demand is growing for managed security services, compliance support and specialist expertise.

This has led to managed service providers (MSPs) seeking out to seek out specialist partners like WhiteRook Cyber to help meet growing customer and regulatory demands.

They’re partnering with us to be an extension of what we see in the market as a “powered by” approach,” said William Ulyate WhiteRook Cyber national cyber security director and co-founder.

“The ‘demand for cyber is at a record level year on year’ and a lot of MSPs are now being specifically asked by their clients, “What are you doing security? How are you securing us?”

But for an MSP that’s never done security “it’s a huge ask”, Ulyate observed.

“The resources are scarce, the experience is extremely expensive, and a lot of MSPs aren’t willing to take on the risk that’s involved,” he said.

“We’re seeing a lot of demand from the channel coming to businesses like ours and saying, “Can you provide us with almost a white-labelled security service so we’re able to actually help their clients?

“I guess the benefit of doing this is that they don’t have to refer their clients to a third party, because we’re basically doing this as a partnership.”

According to Ulyate WhiteRook has partners that have said they’ll give their “pen testing, for example”, or it will provide the MSP with a security operations centre (SOC).

“We’re working with their clients and the MSP, and their clients don’t have to necessarily go to a potential competitor.”

That model aligns with the broader strategy behind Screwloose IT’s 2024 acquisition of WhiteRook Cyber. Which helped to create an integrated managed cybersecurity offering spanning SOC, penetration testing, compliance and managed security services.

This led the cybersecurity company to partner with a defence advisory to expand into newer areas of compliance support.

Working from the same office, WhiteRook , Screwloose IT and The Defence Advisory developed a service designed to help organisations in the defence supply chain meet the requirements of the Defence Industry Security Program (DISP).

The Defence Advisory was founded by Aaron Pollard in 2024, who was the former head of security for Boeing Defence and Airbus and set up the defence business for CyberCX.

“We’re basically helping Australian businesses wanting to work in defence, and we offer a fully managed service that Emerson [Pyrke, WhiteRook Cyber head of cyber security services], Aaron and I put together.

“Aaron came up with the idea, and we provide the technical platform to deliver it.”

The offering aims to solve the key challenge defence suppliers face – where security maturity required to work with defence organisations can often become a significant roadblock, added Ulyate.

“If you’ve got a small or medium-sized business that makes a component or a product for defence, we basically fully manage their defence platform,” he explained. “They can carry on doing whatever they’re doing and leave it up to us to make sure that they’re fully compliant.”

The model could become increasingly relevant as the security and compliance challenges facing defence suppliers begin to emerge across ASD’s cyber security recommendations to aid critical infrastructure (CI) in ensuring the continued provision of critical services during crisis or service disruption.

The guidance, CI Fortify, includes cyber security recommendations for Australian CI operators to strengthen their security posture and resilience in preparation for instances of crisis or service disruption. “There are a lot of MSPs who want to get into critical infrastructure and those more regulated sectors,” said Pollard. “But they don’t have any idea the security frameworks that you need to demonstrate compliance with.

“There’s not tonnes of detail in terms of what CI Fortify looks like and the level of evidence you need to demonstrate that compliance.”

According to Pollard they “burned a lot of energy to make sure” to get this for the defence sector.

That uplift will help organisations of all sizes navigate increasingly complex security and compliance requirements across regulated sectors.

“For a long time, I used to spend a lot of time selling SOCs years ago when Symantec was the king,” explained Ulyate. “It was a million dollars-plus for a dedicated team to monitor a company’s environment.

“It was well outside the budget of an SMB business to spend a million dollars just on monitoring and detection. Over the last five or six years, that has drastically reduced.”

Ulyate felt that it one of the first times ever where the ability to offer a fully functional SOC, security operations centre, at SMB pricing.

“It used to be that only enterprise could afford to buy enterprise tools,” he explained. “Now you have enterprise-grade tools at an affordable level for SMBs, and there’s an ability to go to buyers and say, “Listen, you’re going to get all of this for SMB pricing.

“I’m a firm believer that we do a lot of incident response, and I’ve done it for years and years.

“Most of the attacks that happen usually happen on a Friday or a weekend when no one’s watching the systems.”

Recently White Rook Cyber and TDA were recently chosen to be part of the Queensland Trade and Investment representative delegation for the 2026 Land Forces Conference in Perth.