Market view from CYBORIUM

The cyber security services Australian organisations are putting to market

Four parties now ask the same organisation to prove the same controls, and none of them accept the same evidence. This page sets out what we keep hearing on the evaluation side of the table, the rules we apply when we run one, and the categories where testing the market changes the answer.

Independent by designThe client pays no fee to CYBORIUM.The selected provider pays a capped fee.The client contracts directly with the provider.CYBORIUM does not resell or operate technology.

The pattern repeats

Six sentences we hear, and what each one costs at market

None of these are wrong. Each one hides a decision that gets made by whoever answers first, unless the organisation makes it deliberately.

What we hearWhat it decides

"We need MDR, and we need it before the audit."

The deadline is doing the scoping

Log source coverage, response authority and after-hours escalation all get settled by whoever replies fastest. Fix the outcome, then set the date.

"Our provider already does security."

Usually it does some of it

Ask which controls the provider owns, which ones your team owns, and which ones nobody has written down. The exposure sits in the third group.

"The board wants a number."

A score is an output, not a control

Ask what evidence produced the number, who can reproduce it without the provider present, and how long it stays true.

"It came in cheaper than the others."

Cheaper per endpoint is not cheaper

Ingest limits, retention, response scope and exit costs move total cost far more than the licence line does.

"We just need someone to run the tool."

Tooling without an owner produces alerts

Name the person who acts on a detection at 2am, and the authority they hold to isolate a host without waiting for you.

"Legal will handle the contract."

The obligation does not transfer

CPS 234 and CPS 230 duties stay with your organisation. The contract has to carry what the standard already places on you.

How CYBORIUM runs one

Five rules we apply to every security evaluation

They are not clever. They are the ones that hold when the timeline compresses and the field starts answering back.

  1. 01

    Buy the outcome you can test

    A tier name is not an outcome. Write what has to be true when the service is working, then ask the market to prove it.

  2. 02

    Name the evidence before you name the provider

    Decide which artefact settles each requirement, a log sample, a runbook, a report, a named responder, while the field is still open.

  3. 03

    One owner per control

    Shared responsibility with no name against it is unowned responsibility. Split the model line by line and put initials on each line.

  4. 04

    Price the exit with the entry

    Data portability, log retention, tool ownership and transition support all cost more to negotiate after signature than before it.

  5. 05

    Make the contract carry what the standard carries

    Notification windows, access to evidence and audit rights belong in the schedule. A sales deck is not an obligation.

Ten categories, no vendor names

Where testing the market changes the answer

These are the categories organisations bring to us most often. In every one, what gets asked for at the start is rarely what settles it at the end.

CategoryWhat gets asked forWhat settles it

Managed detection and response

Around the clock monitoring across the environment.

Which log sources are genuinely ingested, what the provider may do without ringing you, and how long you keep the data after you leave.

Identity and privileged access

Multi-factor everywhere and a password vault.

Joiner, mover and leaver timing, how much standing admin access survives, and who approves break-glass at 3am.

Data security posture and classification

Find our sensitive data.

Whether a finding gets a remediation owner, and whether the scan reaches the platforms your business actually stores data in.

Email and collaboration security

Stop the phishing.

Time to act on a reported message, and whether quarantine release sits with the provider or with your service desk.

Vulnerability and exposure management

Scan the estate every month.

Who fixes what by when, and how an exception gets approved, recorded and reviewed rather than forgotten.

Cloud and platform security posture

Check our cloud configuration.

Coverage across every subscription and account, including the ones a project spun up two years ago and never told anyone about.

Third party and supply chain risk

A questionnaire we can send out.

What you do with an answer you do not accept, and whether the register lines up with CPS 230 material service providers.

Incident response retainer

Someone to call.

Contracted response time, whether prepaid hours expire unused, and who holds the forensic evidence when it is over.

Security awareness and phishing simulation

Annual training for staff.

Whether reporting rates move, and whether a reported message reaches anyone with the authority to act on it.

Security leadership and assurance

A few days a month of a CISO.

Which decisions the role can make without you in the room, and what knowledge leaves the building at the end of the term.

No provider is named on this page. Names belong in an evaluation, next to the evidence that earned them a place.

Where the obligation sits

You can outsource the service. You cannot outsource the duty.

Two APRA standards shape most of the security procurement we see. They pull in different directions, and organisations often answer the wrong one.

CPS 234, information security

An APRA regulated entity stays responsible for the information security capability of any party that holds or processes its information, including a related party. The standard also sets reporting duties the entity carries itself: notify APRA no later than 72 hours after becoming aware of a material information security incident, and no later than 10 business days after becoming aware of a material control weakness it expects it cannot remediate in a timely manner.

That is why evidence access belongs in the contract. A provider cannot file those notifications for you, and you cannot file them from a status page.

Read CPS 234 at APRA

CPS 230, operational risk

CPS 230 has applied since 1 July 2025. It brought a register of material service providers, due back to APRA by 1 October 2025, and contract requirements that reach pre-existing agreements from the earlier of the next renewal or 1 July 2026. APRA made targeted amendments on 30 April 2026 that added limited exemptions from specific contractual requirements for certain categories of provider.

Security services often sit in both places at once: a CPS 234 control and a CPS 230 material arrangement. Sort out which one you are answering before you write the requirement.

CPS 230 due diligence guidance

If APRA does not regulate your organisation, the security schedule in your largest customer's contract usually does the same work with less notice.

The engagement boundary

The hints are public. The evaluation is built around your environment.

This page helps you recognise the questions worth asking. A CYBORIUM evaluation maps them to your systems, obligations, provider evidence and commercial position, then produces something a board can challenge.

Questions we get asked before an evaluation starts

Which cyber security services are Australian organisations evaluating most often?

Managed detection and response, identity and privileged access, third party risk and incident response retainers come up most frequently. The category matters less than whether the requirement was written before the market saw it.

Does CPS 234 apply to our providers or to us?

To you. CPS 234 holds the regulated entity responsible for the information security capability of parties that hold or process its information. The notification duties, 72 hours for a material incident and 10 business days for a material control weakness it cannot remediate in a timely manner, stay with the entity and cannot be delegated to a provider.

How is this different from CPS 230 due diligence?

CPS 230 covers operational risk, material service providers, the register and the contract terms. Our CPS 230 guidance covers that path. This page covers what to test inside the security service itself, whichever standard brought you to market.

Will CYBORIUM recommend specific vendors?

Not on a public page. Inside an engagement we test suitable providers against the same criteria and hand over a decision record showing why one was recommended and what the others offered.

What does an evaluation cost the organisation?

No fee is paid to CYBORIUM by the client. The selected provider pays a capped fee and your organisation contracts directly with that provider.

Test the market before the deadline picks for you.

Most of the cost we find in security procurement was decided in the first fortnight, by an organisation answering a question it had not written down yet. That part is fixable.