Nordic Cyber Group Australia
Cybersecurity, compliance and resilience consulting in Melbourne
Australian regulatory fluency, European regulatory depth, and security-cleared consultants who can work where it matters.
Founded in Stockholm. Operating from Melbourne.
Nordic Cyber Group was founded in Stockholm and built its practice under some of the most demanding regulatory regimes in the world — DORA, NIS 2, GDPR and the EU AI Act. We now run an Australian practice from Melbourne, applying that same discipline to the obligations Australian boards and regulators actually ask about.
That combination matters in two directions. Australian subsidiaries of European groups get one adviser who understands both sets of rules. Australian firms selling into Europe get a partner who has already done the work on the other side.
Who you will be working with
Liam Allison
Country Lead, Australia
Melbourne, Victoria
Liam leads Nordic Cyber Group in Australia, running delivery for Australian clients across regulated industry and government. They are the first point of contact for every Australian engagement.
Government & critical infrastructure
Cleared to work where it counts
Government and critical infrastructure work has an entry requirement before capability is even assessed: cleared people who can be in the room. Our Australian consultants meet it.
Our Australian consultants hold current Australian Government security clearances, and can be engaged on work where clearance is a condition of award.
Security-cleared consultants
Our Australian consultants hold current Australian Government security clearances, so cleared engagements do not wait on a vetting process before they can start.
Essential Eight assessment and uplift
Maturity assessment, a costed uplift plan, and the evidence trail that survives an assessor reading it line by line.
PSPF and ISM control mapping
Mapping your existing controls to the PSPF and ISM, closing the gaps, and preparing the environment so an IRAP assessment finds what it should.
Victorian public sector supply chain
VPDSS obligations for Victorian agencies and, just as often, for the private-sector suppliers those agencies contract with.
Defence supply chain readiness
Security posture work for organisations preparing to supply into defence programmes, including the governance and evidence those programmes expect.
Critical infrastructure obligations
SOCI and CIRMP risk management programmes, board attestation support, and incident reporting readiness for responsible entities.
How our services map to Australian obligations
The same ISMS build, risk assessment, resilience and third-party risk work we do in Europe, expressed in the frameworks an Australian regulator, board or procurement panel will ask you about.
| Obligation | Who it applies to | Service line | What we do |
|---|---|---|---|
| ASD Essential Eight | Increasingly a procurement gate across government and regulated industry | Digital Compliance & Cybersecurity | Maturity assessment against ML1–ML3, a prioritised uplift roadmap, and the evidence pack an assessor will ask for. |
| SOCI Act & CIRMP | Responsible entities for critical infrastructure assets | Risk Management & Resilience | Critical infrastructure risk management programme, board attestation support, and incident reporting readiness. |
| APRA CPS 234 & CPS 230 | APRA-regulated banks, insurers and superannuation funds | Compliance, Resilience & Third-Party Risk | Information security control review, operational risk uplift, and the material service provider register CPS 230 expects. |
| Privacy Act 1988, APPs & the NDB scheme | Most organisations handling Australian personal information | Framework & Policy | Privacy programme design, cross-border disclosure under APP 8, and notifiable data breach response readiness. |
| PSPF & ISM | Commonwealth agencies and the suppliers they onboard | Compliance & ISO-as-a-Service | Control mapping against the PSPF and ISM, gap remediation, and preparing your environment for an IRAP assessment. |
| VPDSF & VPDSS | Victorian public sector bodies and their contracted service providers | Framework & Policy | Protective Data Security Plan support, standards mapping, and supplier attestation for organisations contracting to Victorian agencies. |
| AUSTRAC AML/CTF | Reporting entities under the AML/CTF Act | Digital Fraud & Financial Crime | Programme review, control design, and scams and fraud framework work aligned to AUSTRAC and ASIC expectations. |
| ISO 27001 alongside Essential Eight | Organisations carrying both a certification and a baseline obligation | ISO-as-a-Service | One control set that satisfies both, so you are not running two parallel compliance programmes over the same estate. |
| Identity governance for regulated environments | Organisations where access control is the audited control | Identity Security | Identity governance, privileged access management, and the access evidence that Essential Eight and CPS 234 reviews turn on. |
This table summarises obligations as we understand them and is not legal advice. Applicability, thresholds and commencement dates change — talk to us about your specific circumstances.
Why a Nordic firm in Australia
European regulatory depth, applied locally
We built this practice under DORA, NIS 2, GDPR and the EU AI Act. Those regimes are years ahead of most jurisdictions on operational resilience and third-party risk — the thinking transfers directly to CPS 230, SOCI and the Privacy Act.
One adviser across both jurisdictions
If you are an Australian subsidiary of a European group, or an Australian firm selling into Europe, you are carrying two regulatory regimes. We are one of very few boutiques that can hold both without handing you to a second firm.
Senior-only delivery
The consultant who scopes your engagement delivers it. No pyramid, no bench, no graduate doing the interviews and a partner presenting the findings.
Cleared to be in the room
Security clearance is an entry requirement for government and critical infrastructure work, not a differentiator you can develop mid-engagement. Our Australian consultants hold current clearances.
Questions Australian clients ask us
Does Nordic Cyber Group have consultants in Australia?
Yes. Nordic Cyber Group runs an Australian practice from Melbourne, led by Liam Allison as Country Lead, Australia. Australian engagements are delivered by that team, with the Stockholm practice available where an engagement touches European regulation.
Do your Australian consultants hold security clearances?
Yes. Our Australian consultants hold current Australian Government security clearances and can be engaged on work where clearance is a condition of award. We can confirm the specific level required for your engagement on request.
Can you help us reach Essential Eight Maturity Level 2?
Yes. We assess your current maturity against each of the eight mitigation strategies, produce a prioritised and costed uplift roadmap, and build the evidence pack an assessor will ask for. Where you also hold ISO 27001, we run one control set that satisfies both rather than two parallel programmes.
Do you work with Victorian government suppliers?
Yes. The Victorian Protective Data Security Standards apply to Victorian public sector bodies and, importantly, flow through to the service providers they contract with. We support both sides of that relationship — Protective Data Security Plan work for agencies, and supplier attestation for the private-sector firms serving them.
We are an Australian subsidiary of a European group. Can you cover both regimes?
That is the case we are built for. We work under GDPR and the Australian Privacy Act simultaneously, and can map a single control environment against both European and Australian obligations rather than maintaining two disconnected compliance programmes.
Where is your Australian office?
Melbourne, at 90 Collins Street. Our head office is in Stockholm, Sweden. Australian enquiries are answered on Australian business hours, AEST/AEDT.
Talk to us in Melbourne
Australian enquiries reach our Melbourne office first. You will speak to the consultant who would run the work, not an account manager.
We respond to Australian enquiries within one business day.
Melbourne Office
- Australia
- +61 421 934 521
- Sweden
- +46-732-442-583
- info@ncgrp.se
- Business hours
- Monday–Friday, 9:00–17:30 AEST/AEDT