# Fortian > Fortian is an Australian cyber security firm established in 2013, providing consulting and 24x7 managed security services. The company helps organisations build digital trust through a blend of deep technical expertise and strategic, business-focused advisory. Fortian is 100% Australian-owned and operated, with offices in Sydney, Melbourne, Brisbane, and Perth. The firm is ISO 27001 certified, SOC 2 compliant, and a CREST-approved penetration testing provider. ## Contact - Phone: 1800 717 545 - Email: contact@fortian.com.au - Sydney: Level 8, 56 Pitt St - Melbourne: Level 11, 276 Flinders St - LinkedIn: https://au.linkedin.com/company/fortian ## Services Fortian's services are divided into two primary offerings: consulting and managed security. ### Consulting Fortian's consulting practice covers six service areas. - [Security Strategy and Architecture](https://fortian.com.au/security-strategy-and-architecture.html): Security strategy development, security reviews, security architecture, zero trust consulting, and identity security. Assessments are aligned with the US NIST Cyber Security Framework, with support for other frameworks. - [Governance, Risk and Compliance](https://fortian.com.au/governance-risk-compliance.html): Executive cyber security briefings, cyber governance, ISO 27001 and SOC 2 certification support, security policies and standards development, supply chain security assessments, security awareness and phishing simulation, and compliance with the Privacy Act (1988), APRA CPS 234, and NIST CSF. - [Security Assurance](https://fortian.com.au/security-assurance.html): Penetration testing (CREST-approved), vulnerability management (recurring or one-time), and source code review using both manual and automated methods. - [Security Engineering](https://fortian.com.au/security-engineering.html): Secure DevOps integration across the software development lifecycle, including threat modelling, vulnerability assessments, code analysis, compliance checks, and secure deployment practices. - [Forensics and Incident Response](https://fortian.com.au/forensics-and-incident-response.html): Security incident and data breach investigation, digital forensic evidence collection and analysis, forensic security monitoring architecture, and forensic expert services including affidavits, litigation support, and court testimony. - [Privacy](https://fortian.com.au/privacy.html): Privacy advisory, privacy impact assessments aligned with Australian privacy authority guidelines, and privacy assurance reviews covering governance, policies, procedures, training, risk frameworks, and technology. ### Managed Security - [24x7 Managed Security Services](https://fortian.com.au/managed-security-services-australia.html): Real-time security monitoring across endpoints, servers, and cloud infrastructure through Fortian's Australian-based Security Operations Centre. Includes security monitoring with manual alert validation, incident response and escalation, proactive threat hunting, vulnerability management, and cyber threat intelligence. Operates within client Azure tenants with data retained in the client environment. - [Security Monitoring](https://fortian.com.au/mss-security-monitoring.html): 24x7 security monitoring by Australian analysts deployed within your own Azure tenant. Real-time alerting, manual validation, and full data sovereignty. - [Vulnerability Management](https://fortian.com.au/mss-vulnerability-management.html): Continuous vulnerability scanning, intelligent prioritisation, and clear remediation guidance — delivered as a fully managed service. ## Case Studies - [Case Studies](https://fortian.com.au/case-studies.html): Real-world examples of how Fortian has helped organisations strengthen their security posture. - [Cloud Architecture](https://fortian.com.au/case-studies/cloud-architecture.html): Designed and delivered a global Azure cloud architecture for an ASX-listed company, meeting complex multi-jurisdictional regulatory requirements and enabling efficient global expansion. - [Security Uplift and Managed SOC](https://fortian.com.au/case-studies/security-uplift-managed-soc.html): Comprehensive security transformation for a large not-for-profit, spanning governance, technology, and business streams with 24x7 managed SOC deployment. - [Security Maturity Assessment](https://fortian.com.au/case-studies/security-maturity-assessment.html): Technical review of cyber security controls for an ASX-listed company against the NIST Cybersecurity Framework, delivering a prioritised strategy and roadmap using Fortian's Security Capability Model (SCM). - [ISO 27001 Gap Assessment and Certification Roadmap](https://fortian.com.au/case-studies/iso-27001-gap-assessment.html): Gap assessment of a mid-tier Australian retail service provider against ISO/IEC 27001:2022 by a qualified ISO 27001 Lead Auditor, covering the management system clauses and Annex A controls, delivering a prioritised remediation roadmap that led to first-time certification. - [APRA CPS 234 Policy and Standards Uplift](https://fortian.com.au/case-studies/apra-cps-234-policy-standards-uplift.html): Uplift of a mid-tier APRA-regulated financial services organisation's information security policy and standards suite, aligned to APRA CPS 234 and NIST CSF 2.0, establishing a risk-based control framework and closing outstanding audit findings. ## Company - [About Us](https://fortian.com.au/about-us.html): Company background, vision, values, and leadership team including Jason Wood (CTO), Barry Schramm (CRO), and Marcus Wong (COO). - [Careers](https://fortian.com.au/careers.html): Open positions and internship programs. All applicants must be Australian permanent residents or citizens. - [Security Insights](https://fortian.com.au/blog.html): Blog covering monthly cyber environment updates, threat analysis, and technical articles on topics such as threat hunting, identity security, supply chain risk, and forensic tooling. Posts are grouped into five categories, each linkable directly: Monthly Update (https://fortian.com.au/blog.html#monthly-update), Threat Update (https://fortian.com.au/blog.html#threat-update), Advisory & Governance (https://fortian.com.au/blog.html#advisory-governance), Identity & Cloud (https://fortian.com.au/blog.html#identity-cloud) and Life at Fortian (https://fortian.com.au/blog.html#life-at-fortian). - [Contact Us](https://fortian.com.au/contact-us.html): Enquiry form and office locations. - [Privacy Policy](https://fortian.com.au/privacy-policy.html): How Fortian collects, uses, and protects personal information in accordance with Australian Privacy Principles. ## Selected Blog Posts - [Trusted Domains, Disposable Infrastructure: Tax-Season Phishing on Vercel](https://fortian.com.au/blog/trusted-domains-disposable-infrastructure-tax-season-phishing-on-vercel.html): Fortian's analysis of a sharp rise in campaigns abusing legitimate application hosting platforms - Vercel, Cloudflare Workers and Netlify - as disposable staging infrastructure. The platforms are not compromised; attackers deploy from free-tier accounts and inherit the clean domain reputation of vercel.app, workers.dev and netlify.app, bypassing URL reputation filters and domain block lists. Covers three distinct July 2026 campaigns, all using tax-season lures and vercel.app subdomains: an entirely AI-generated JavaScript loader (identifiable by verbose inline comments and emoji annotations) that installs LogMeIn RMM behind a fake ATO document while redirecting the victim to the real ATO homepage; a UPS shipment-notification lure delivering ScreenConnect via a VBS script disguised as an Adobe Flash updater; and indiscriminate Australian Taxation Office credential harvesting behind fake myGov notifications. Because the payloads are legitimate RMM tools rather than commodity malware, EDR does not flag them and detection depends on behavioural analytics and threat hunting. Includes three KQL hunting queries (CommonSecurityLog, DeviceFileEvents, UrlClickEvents) and indicators of compromise. - [July 2026 Cyber Environment Update](https://fortian.com.au/blog/july-2026-cyber-update.html): OpenAI and Anthropic both disclosed within ten days of each other that their own AI models escaped evaluation environments and compromised real production systems, researchers documented the first ransomware operation run start to finish by an LLM (JadePuffer) alongside an AI-supply-chain npm worm (SANDWORM_MODE), Scattered Spider members were jailed over the 2024 Transport for London attack, ShinyHunters claimed Ernst & Young, Russian intelligence was found hijacking IP cameras across Europe for military reconnaissance, and CISA warned of escalating attacks on water treatment PLCs. In Australia, AML/CTF Tranche 2 brought roughly 90,000 professional services firms under the Privacy Act, the Office of AI was established within PM&C, the OAIC closed its Qantas vishing inquiry without action, and breaches hit Partnered Health, Origin Energy, LR Reed, Royal Foods, CubePilot and GO2 Health. - [Nothing to Take Down: IPFS-Hosted Phishing With Runtime Brand Impersonation](https://fortian.com.au/blog/nothing-to-take-down-ipfs-hosted-phishing-with-runtime-brand-impersonation.html): Fortian's technical analysis of a credential harvesting campaign against ASX-listed organisations that combines three techniques - phishing pages published to IPFS and addressed by content hash (removing any single takedown-able host), dynamic per-victim brand impersonation constructed at runtime from the victim's own email domain using the Clearbit logo, Google favicon and Microlink screenshot APIs, and real-time exfiltration to the operator via the Telegram Bot API. Covers the ShareFile lure sent from a compromised Spanish university mailbox, the kit's anti-analysis techniques (debugger timing loop, devtools shortcut blocking, viewport-delta detection) and analyst bypasses, Telegram operator attribution artefacts, indicators of compromise and detection opportunities. - [Q2 2026 Quarterly Cyber Threat Review](https://fortian.com.au/blog/q2-2026-quarterly-cyber-threat-review.html): A synthesis of the significant global and Australian cyber events of April, May and June 2026, structured around five themes - AI as offensive weapon, defensive shield and regulatory flashpoint; the collapse of software supply chain trust (signed, provenance-verified npm packages shipping malware); identity as the dominant breach vector (ShinyHunters and The Com); nation-state pre-positioning in critical infrastructure; and an accelerating Australian regulatory response (APRA's AI letter, the retirement of the Essential Eight, the ISM update, the Cyber Incident Review Board and Horizon 2). The full rich-format report is at https://fortian.com.au/reports/q2-2026-quarterly-cyber-threat-review.html. - [Detection of Multi-Accounting Campaigns with Machine Learning](https://fortian.com.au/blog/detection-of-multi-accounting-campaigns-with-machine-learning.html): Fortian's unsupervised machine-learning approach to detecting large-scale automated account-creation (multi-accounting) campaigns, using bisecting k-means clustering over engineered username, user-agent and IP features to surface campaigns that randomise fields and use residential IP proxies to evade rule-based detection. - [June 2026 Cyber Environment Update](https://fortian.com.au/blog/june-2026-cyber-update.html): The Five Eyes AI warning to boards, the FBI takedown of an AI-powered phishing service blamed for $1.9 billion in losses, US export controls on Anthropic and OpenAI frontier models, ShinyHunters' Oracle PeopleSoft zero-day compromising 100+ organisations, FortiBleed affecting 75,000 Fortinet devices, the ASD's retirement of the Essential Eight and ISM update, the OAIC's ruling against American Express, and Australian breaches including Australian Clinical Labs. - [Fortian Summer Internship 2026](https://fortian.com.au/blog/summer-2026-internship.html): Casey Wilfling's summer 2026 internship with Fortian's MSS team, covering ransomware attack analysis with Cyber Kill Chain mapping, custom Microsoft Sentinel detection engineering, and building an automated IoC extraction and STIX 2.1 conversion pipeline for multi-tenant threat intelligence distribution using Azure Logic Apps and OpenCTI. - [May 2026 Cyber Environment Update](https://fortian.com.au/blog/may-2026-cyber-update.html): TanStack and AntV npm supply chain compromises, ShinyHunters' extortion of Instructure exposing 275 million records, CISA's CI Fortify wartime-footing guidance, Australia's Federal Budget and Cyber Incident Review Board, ClickFix campaign abusing Australian WordPress sites, and domestic ransomware incidents. - [Webinar: Understanding Adversary-in-the-Middle Attacks](https://fortian.com.au/blog/understanding-adversary-in-the-middle-attacks-webinar.html): Live webinar on 9 June 2026 covering AiTM phishing attacks that bypass MFA via session token theft, with a live demo and Microsoft Sentinel detection strategies. - [Fortian at the 2026 Technology for Social Justice Conference](https://fortian.com.au/blog/infoexchange-2026.html): Fortian sponsors the Infoxchange Technology for Social Justice Conference in Melbourne, supporting NFP cybersecurity capability building. - [April 2026 Cyber Environment Update](https://fortian.com.au/blog/april-2026-cyber-update.html): Iranian attacks on US infrastructure, North Korean supply chain operations, Anthropic's Claude Mythos Preview, ShinyHunters breach spree, and Australian incidents. - [March 2026 Cyber Environment Update](https://fortian.com.au/blog/march-2026-cyber-update.html): US-Israeli operations against Iran and expanded cyber conflict affecting commercial cloud infrastructure. - [February 2026 Cyber Environment Update](https://fortian.com.au/blog/february-2026-cyber-update.html): Sydney fintech data exposure and Australian ransomware payment trends. - [2025 Cyber Threats: A Frontline Perspective](https://fortian.com.au/blog/2025-cyber-threats-a-frontline-perspective.html): SOC report on the shift toward identity abuse, SaaS data theft, and defence evasion. - [The Hidden Third-Party Risk: How Shadow IT Escapes Governance](https://fortian.com.au/blog/hidden-third-party-risks-how-shadow-it-escapes-governance.html): Analysis of unsanctioned tools expanding vendor ecosystems beyond governance controls. - [The Great Wall of Nope: Why Firewall Logs Aren't Enough](https://fortian.com.au/blog/the-great-wall-of-nope-why-firewall-logs-arent-enough.html): The importance of host, identity, and cloud telemetry beyond perimeter logging. - [Extending Defender XDR with Velociraptor](https://fortian.com.au/blog/extending-defender-xdr-with-velociraptor.html): Technical integration for forensic telemetry beyond standard SIEM capabilities.