Cyber assurance and Defence consulting
Assurance without the noise.
Burley Assurance is a Canberra-based practice specialising in IRAP and entity ICT security assessments, Defence sector consulting, and GRC project delivery. We work directly with Australian Government agencies, Defence organisations, and technology vendors preparing for government markets.
We deliver three core capabilities from Canberra.
Each engagement is led directly by the principal, no intermediaries, no junior back-fill.
Our Services
01
ICT Security Assessments
Our ASD-endorsed IRAP assessors can conduct cloud, ICT outsourced service providers and gateway systems (up to SECRET).
We also have extensive experience in entity assessments as part of an organisation’s Assessment and Authorisation (A&A) process. These independent reports act as an input as part of the Authorisation Package which gives the Authorising Officer the evidence needed to make an informed risk-based decision on whether to issue an Authority to Operate (ATO).
If you are not ready for a formal assessment, we offer readiness reviews and short advisory engagements to identify gaps and determine the most practical path to assessment.
02
Security Consulting & Advisory
We provide independent security advice to government agencies, Defence capability programs, DISP entities, and technology vendors operating in or entering government markets. Engagements cover security architecture and design, risk assessments, security requirements for capability delivery, and independent review of security posture at the decision points where clear, expert input matters most.
We work on a fixed-scope basis without ongoing retainers. Short-form engagements are available for organisations that need a specific questions answered, a path forward, a design reviewed, or a security position validated without committing to a longer program of work.
03
GRC and Project Delivery
We develop, review, and uplift the security documentation that underpins security programs and project delivery as well as technical GRC engineering for cloud environments. This includes security documentation suites, policies and procedures, framework reviews, and enterprise policy analysis and uplift. All aligned to the PSPF, ISM and relevant departmental policy requirements.
We also support projects requiring security input as a deliverable preparing documentation packages, contributing to assessment and authorisation artefacts, and providing structured security engineering support where the output is a document or framework rather than simply advice.
Extended Capabilities
Effective security outcomes rarely stop at assessment and artefacts. Organisations that understand their attack surface, risk posture, operational and business processes are better positioned to make decisions, prioritise investment and defend what matters.
Where engagements require that broader capability, we draw on a trusted Canberra-based partner with expertise in business analysis, data intelligence, and security testing.
01
Business Analysis and Process Review
Structured analysis of organisational workflows, decision processes, and operational environments to identify where effort is misallocated and where targeted intervention produces disproportionate improvement. Outputs are practical and actionable.
02
Data Intelligence and Reporting
Translation of complex data into clear, decision ready reporting for leadership teams. This includes data interrogation, dashboards, KPI design, and executive-ready visualisation of information that would otherwise remain buried in systems.
03
Technical Security Testing
Network visibility, vulnerability assessments, phishing simulations and organisational systems review conducted by a specialist. Findings are identified, prioritised and structured to feed directly into remediation planning or an existing assurance program.
About
Some engagements need a large team. Most do not. What they need is the right people, with the right background, focused entirely on the problem at hand.
Our engagements are scoped precisely, delivered to brief, and closed when the work is done. We do not extend beyond scope, manufacture complexity, or position ourselves as an ongoing dependency.
The practice combines structured consulting methodology with direct practitioner access and sustained proven delivery across Australian Government and Defence, and active ASD-endorsed IRAP assessors. Direct delivery, no intermediaries, minimal overhead.
Let’s begin the conversation.
Use the form to lodge a query or request a meeting. For assessment enquiries, include high level system context and your target timelines if known.