DISP MEMBER · AUSTRALIAN SOVEREIGN · ALL FOUR OUTCOME AREAS
Your Trusted Partner for the Full DISP Lifecycle
Red Piranha delivers DISP governance, Essential Eight ML2 uplift, and 24/7 sovereign cyber operations under one Australian engagement.
Defence’s ICT and Cyber domain require operating controls and continuous evidence - not just compliant documentation. Red Piranha delivers both the governance layer and the operational platform behind it.
As your trusted DISP partner, we can help with:
Governance
Personnel Security
Physical Security
Information Security
All four outcome areas
Licensed Australian Defence Exporter
Certified security management
Australian SOC, Australian jurisdiction
ICT and Cyber supplier listing
THE PROBLEM
Where DISP Applications Stall.
DISP is a security maturity assessment, not a checklist. The Governance and ICT/Cyber domains carry the assessment depth, and that is where most applications fail — not because the documentation is wrong, but because there are no operating controls behind it.
MOST PROVIDERS
Documentation consultants author your SRMP and advise on the process. When it comes to the ICT/Cyber controls - Essential Eight ML2, the 107-control CSQ, continuous monitoring - they refer you to a separate IT provider. The result is fragmented accountability between documentation and operational security.
RED PIRANHA
We author the governance documentation and deploy Crystal Eye for the ICT/Cyber domain under one engagement. The 107-control CSQ evidence comes from live telemetry, not a spreadsheet. The 24/7 Australian SOC produces the operational data that supports your Annual Security Report and Ongoing Suitability Assessment. One vendor is accountable for the full chain.
DIFFERENTIATION
Why Red Piranha over every other option.
The DISP vendor market splits between consultancies that document and MSSPs that monitor. Neither does the other's job. Red Piranha does both, under one Australian-owned engagement.
ONE VENDOR. NO HANDOFF.
SRMP authorship, Essential Eight ML2 deployment, 107-control CSQ evidence generation, and 24/7 SOC monitoring are delivered under a single engagement. The consultant and the platform are the same organisation. There is no point at which accountability transfers.
EVIDENCE FROM OPERATIONS, NOT TEMPLATES.
Crystal Eye generates CSQ evidence from live network and endpoint telemetry. 18 or more months of data retention supports forensic investigation and audit trail requirements. When Defence tests your operating controls, the data exists because Crystal Eye has been running them — not because they were written down.
SOVEREIGN FROM THE GROUND UP.
Crystal Eye is developed, owned, and supported onshore. All intellectual property is held by Red Piranha. The SOC operates 24/7 from Australia with Australian analysts. Defence-related telemetry remains under Australian jurisdiction throughout the engagement. FOCI-clean by construction — no foreign parent, no offshore development chain.
CRYSTAL EYE PLATFORM
What Crystal Eye Delivers for DISP Compliance.
The ICT/Cyber domain is where DISP requires evidence of operating controls — not policy documents. Crystal Eye is the platform that produces that evidence, across the network, endpoint, and behavioural layers.
E8
Essential Eight ML2, organisation-wide
Crystal Eye deploys and enforces the Essential Eight Maturity Level 2 baseline across the organisation without requiring major infrastructure changes. Inline deployment eliminates engineering overhead.
CSQ
107-control CSQ evidence from live telemetry
The Cyber Security Questionnaire evidence pack is generated from operational data, not manually assembled. Every control maps to real telemetry. Defence tests operating controls — Crystal Eye produces them.
SOC
24/7 Australian SOC monitoring
Round-the-clock detection and response from the Red Piranha SOC, staffed by Australian analysts. All telemetry under Australian jurisdiction. Push-button escalation from Crystal Eye to the SOC team without IR retainers.
18M
18+ months data retention
DISP requires demonstrable audit trails and the ability to support forensic investigation. Crystal Eye retains 18 or more months of log and event data, with integrated PCAP analysis to reduce attacker dwell time.
10x
10x network visibility
Crystal Eye provides significantly greater visibility across the network than conventional point solutions, covering NDR, EDR, SIEM, Managed Firewall, Vulnerability Scanning, and behavioural anomaly detection in a unified platform.
TI
Operationalised threat intelligence
Automated threat intelligence integration across all security layers. Detection content mapped to MITRE ATT&CK for ICS and enterprise. Proactive threat hunting capability for increased assurance against APTs and unknown threats.
COVERAGE
All Four DISP Domains. One Engagement.
Governance and Information and Cyber Security are direct delivery — we build, deploy, and run them. Personnel and Physical Security are guided — we specify what is required and support you through the process.
DOMAIN
ICT & CYBER
DELIVERY
WHAT RED PIRANHA PROVIDES
- Essential Eight ML2 deployment via Crystal Eye
- 107-control CSQ evidence from live telemetry
- 24/7 Australian SOC — TDIR, NDR, EDR
- Continuous monitoring and MITRE ATT&CK-mapped detection
- Maturity Action Plan and ongoing uplift
GOVERNANCE
- Security Risk Management Plan authorship
- Incident Response Plan
- CSO and SO role definition and training
- Annual Security Report preparation
- eCISO retainer for ongoing governance
PERSONNEL
- AGSVA clearance pathway guidance
- AS 4811:2022 workforce screening requirements
- Insider threat policy and Assessed Position definition
PHYSICAL
- Zone classification mapping
- ASIO T4 standards alignment
- Facility certification readiness
ENGAGEMENT MODEL
From First Conversation to Sustained Membership.
The DISP cycle runs continuously. Red Piranha stays engaged across every stage — eligibility through to the Ongoing Suitability Assessment and Deep Dive Audit. There is no point at which the engagement ends and you are left to maintain it alone.
STAGE 1
ASSESS
Eligibility check, gap analysis against all four domains, eCISO engagement scoping. Determine the correct membership level for your contracted work.
OUTPUT
DISP gap snapshot and Maturity Action Plan
STAGE 2
BUILD
SRMP and IRP authored. Crystal Eye deployed. Essential Eight ML2 operationalised. CSQ evidence pack assembled from live telemetry.
OUTPUT
DISP gap snapshot and Maturity Action Plan
STAGE 3
OPERATE
Crystal Eye TDIR running 24/7. Australian SOC monitoring active. Proactive threat hunting. Incident detection and response without separate IR retainers.
OUTPUT
Continuous detection, operational audit trail
STAGE 4
SUSTAIN
Annual Security Report preparation. OSA gap closure. DDA evidence pack. eCISO retainer for ongoing governance and membership obligations.
OUTPUT
Annual cycle, ongoing DISP membership
GET STARTED
Where are you in the DISP Cycle?
Each conversation starts the same way — 30 minutes with a specialist who has operated inside the DISP program. No obligation. No sales deck.
STARTING OUT
Get your DISP Readiness Score.
Gap snapshot. Maturity Action Plan. Eligibility review and eCISO™ engagement scoping.
MID-APPLICATION
Book a CSQ Evidence Review.
Walk through your 107-control submission. Identify gaps against live telemetry before lodgement.
ALREADY A MEMBER
Book an OSA / DDA Readiness Check.
Annual Security Report preparation. OSA gap closure. Deep Dive Audit evidence pack.
GRANT ASSISTANCE
Defence Grants can fund the Security Uplift DISP Requires.
The Defence Industry Development Grants (DIDG) program funds Australian SMEs building sovereign capability for the Defence sector. Up to $1 million per project at 50% cost-share, across four streams: Exports, Security, Skilling, and Sovereign Industrial Priorities. Red Piranha assists with applications and delivers what the grant funds.
ELIGIBILITY AND APPLICATION SUPPORT
Australian state and federal grant programs provide funding pathways for defence-sector SMEs undertaking security uplift and capability development. Available grants and eligibility criteria vary by state and change regularly. Red Piranha assists clients with identifying applicable programs, preparing applications, and delivering the security outcomes the funding supports. Contact the team to understand what current programs may apply to your situation.
Start your DISP journey with
Red Piranha.
Whether scoping eligibility for the first time, mid-application, or already a member preparing for your next ASR - the conversation starts with 30 minutes and a specialist who has run the DISP cycle from inside.
Book your free assessment.