Nordic Cyber Group Australia

Cybersecurity, compliance and resilience consulting in Melbourne

Australian regulatory fluency, European regulatory depth, and security-cleared consultants who can work where it matters.

Founded in Stockholm. Operating from Melbourne.

Nordic Cyber Group was founded in Stockholm and built its practice under some of the most demanding regulatory regimes in the world — DORA, NIS 2, GDPR and the EU AI Act. We now run an Australian practice from Melbourne, applying that same discipline to the obligations Australian boards and regulators actually ask about.

That combination matters in two directions. Australian subsidiaries of European groups get one adviser who understands both sets of rules. Australian firms selling into Europe get a partner who has already done the work on the other side.

Who you will be working with

Liam Allison

Country Lead, Australia

Melbourne, Victoria

Liam leads Nordic Cyber Group in Australia, running delivery for Australian clients across regulated industry and government. They are the first point of contact for every Australian engagement.

Government & critical infrastructure

Cleared to work where it counts

Government and critical infrastructure work has an entry requirement before capability is even assessed: cleared people who can be in the room. Our Australian consultants meet it.

Our Australian consultants hold current Australian Government security clearances, and can be engaged on work where clearance is a condition of award.

Security-cleared consultants

Our Australian consultants hold current Australian Government security clearances, so cleared engagements do not wait on a vetting process before they can start.

Essential Eight assessment and uplift

Maturity assessment, a costed uplift plan, and the evidence trail that survives an assessor reading it line by line.

PSPF and ISM control mapping

Mapping your existing controls to the PSPF and ISM, closing the gaps, and preparing the environment so an IRAP assessment finds what it should.

Victorian public sector supply chain

VPDSS obligations for Victorian agencies and, just as often, for the private-sector suppliers those agencies contract with.

Defence supply chain readiness

Security posture work for organisations preparing to supply into defence programmes, including the governance and evidence those programmes expect.

Critical infrastructure obligations

SOCI and CIRMP risk management programmes, board attestation support, and incident reporting readiness for responsible entities.

How our services map to Australian obligations

The same ISMS build, risk assessment, resilience and third-party risk work we do in Europe, expressed in the frameworks an Australian regulator, board or procurement panel will ask you about.

ObligationWho it applies toService lineWhat we do
ASD Essential EightIncreasingly a procurement gate across government and regulated industryDigital Compliance & CybersecurityMaturity assessment against ML1–ML3, a prioritised uplift roadmap, and the evidence pack an assessor will ask for.
SOCI Act & CIRMPResponsible entities for critical infrastructure assetsRisk Management & ResilienceCritical infrastructure risk management programme, board attestation support, and incident reporting readiness.
APRA CPS 234 & CPS 230APRA-regulated banks, insurers and superannuation fundsCompliance, Resilience & Third-Party RiskInformation security control review, operational risk uplift, and the material service provider register CPS 230 expects.
Privacy Act 1988, APPs & the NDB schemeMost organisations handling Australian personal informationFramework & PolicyPrivacy programme design, cross-border disclosure under APP 8, and notifiable data breach response readiness.
PSPF & ISMCommonwealth agencies and the suppliers they onboardCompliance & ISO-as-a-ServiceControl mapping against the PSPF and ISM, gap remediation, and preparing your environment for an IRAP assessment.
VPDSF & VPDSSVictorian public sector bodies and their contracted service providersFramework & PolicyProtective Data Security Plan support, standards mapping, and supplier attestation for organisations contracting to Victorian agencies.
AUSTRAC AML/CTFReporting entities under the AML/CTF ActDigital Fraud & Financial CrimeProgramme review, control design, and scams and fraud framework work aligned to AUSTRAC and ASIC expectations.
ISO 27001 alongside Essential EightOrganisations carrying both a certification and a baseline obligationISO-as-a-ServiceOne control set that satisfies both, so you are not running two parallel compliance programmes over the same estate.
Identity governance for regulated environmentsOrganisations where access control is the audited controlIdentity SecurityIdentity governance, privileged access management, and the access evidence that Essential Eight and CPS 234 reviews turn on.

This table summarises obligations as we understand them and is not legal advice. Applicability, thresholds and commencement dates change — talk to us about your specific circumstances.

Why a Nordic firm in Australia

European regulatory depth, applied locally

We built this practice under DORA, NIS 2, GDPR and the EU AI Act. Those regimes are years ahead of most jurisdictions on operational resilience and third-party risk — the thinking transfers directly to CPS 230, SOCI and the Privacy Act.

One adviser across both jurisdictions

If you are an Australian subsidiary of a European group, or an Australian firm selling into Europe, you are carrying two regulatory regimes. We are one of very few boutiques that can hold both without handing you to a second firm.

Senior-only delivery

The consultant who scopes your engagement delivers it. No pyramid, no bench, no graduate doing the interviews and a partner presenting the findings.

Cleared to be in the room

Security clearance is an entry requirement for government and critical infrastructure work, not a differentiator you can develop mid-engagement. Our Australian consultants hold current clearances.

Questions Australian clients ask us

Does Nordic Cyber Group have consultants in Australia?

Yes. Nordic Cyber Group runs an Australian practice from Melbourne, led by Liam Allison as Country Lead, Australia. Australian engagements are delivered by that team, with the Stockholm practice available where an engagement touches European regulation.

Do your Australian consultants hold security clearances?

Yes. Our Australian consultants hold current Australian Government security clearances and can be engaged on work where clearance is a condition of award. We can confirm the specific level required for your engagement on request.

Can you help us reach Essential Eight Maturity Level 2?

Yes. We assess your current maturity against each of the eight mitigation strategies, produce a prioritised and costed uplift roadmap, and build the evidence pack an assessor will ask for. Where you also hold ISO 27001, we run one control set that satisfies both rather than two parallel programmes.

Do you work with Victorian government suppliers?

Yes. The Victorian Protective Data Security Standards apply to Victorian public sector bodies and, importantly, flow through to the service providers they contract with. We support both sides of that relationship — Protective Data Security Plan work for agencies, and supplier attestation for the private-sector firms serving them.

We are an Australian subsidiary of a European group. Can you cover both regimes?

That is the case we are built for. We work under GDPR and the Australian Privacy Act simultaneously, and can map a single control environment against both European and Australian obligations rather than maintaining two disconnected compliance programmes.

Where is your Australian office?

Melbourne, at 90 Collins Street. Our head office is in Stockholm, Sweden. Australian enquiries are answered on Australian business hours, AEST/AEDT.

Talk to us in Melbourne

Australian enquiries reach our Melbourne office first. You will speak to the consultant who would run the work, not an account manager.

We respond to Australian enquiries within one business day.

Melbourne Office

90 Collins Street
Melbourne VIC 3000
Australia
Business hours
Monday–Friday, 9:00–17:30 AEST/AEDT