DISP MEMBER  ·  AUSTRALIAN SOVEREIGN  ·  ALL FOUR OUTCOME AREAS

Your Trusted Partner for the Full DISP Lifecycle

Red Piranha delivers DISP governance, Essential Eight ML2 uplift, and 24/7 sovereign cyber operations under one Australian engagement.


Defence’s ICT and Cyber domain require operating controls and continuous evidence - not just compliant documentation. Red Piranha delivers both the governance layer and the operational platform behind it.

As your trusted DISP partner, we can help with:

Governance
DIRECT DELIVERY

Personnel Security
GUIDED

Physical Security
GUIDED

Information Security
DIRECT DELIVERY


DISP MEMBER
All four outcome areas

TEAM DEFENCE AUSTRALIA
Licensed Australian Defence Exporter

ISO/IEC 27001:2022
Certified security management

100% AUSTRALIAN
Australian SOC, Australian jurisdiction

DEFENCE EXPORT CATALOGUE
ICT and Cyber supplier listing

THE PROBLEM

Where DISP Applications Stall.

DISP is a security maturity assessment, not a checklist. The Governance and ICT/Cyber domains carry the assessment depth, and that is where most applications fail — not because the documentation is wrong, but because there are no operating controls behind it.

MOST PROVIDERS

Documentation consultants author your SRMP and advise on the process. When it comes to the ICT/Cyber controls - Essential Eight ML2, the 107-control CSQ, continuous monitoring - they refer you to a separate IT provider. The result is fragmented accountability between documentation and operational security.

RED PIRANHA

We author the governance documentation and deploy Crystal Eye for the ICT/Cyber domain under one engagement. The 107-control CSQ evidence comes from live telemetry, not a spreadsheet. The 24/7 Australian SOC produces the operational data that supports your Annual Security Report and Ongoing Suitability Assessment. One vendor is accountable for the full chain.

DIFFERENTIATION

Why Red Piranha over every other option.

The DISP vendor market splits between consultancies that document and MSSPs that monitor. Neither does the other's job. Red Piranha does both, under one Australian-owned engagement.

looks_one

ONE VENDOR. NO HANDOFF.

SRMP authorship, Essential Eight ML2 deployment, 107-control CSQ evidence generation, and 24/7 SOC monitoring are delivered under a single engagement. The consultant and the platform are the same organisation. There is no point at which accountability transfers.

looks_two

EVIDENCE FROM OPERATIONS, NOT TEMPLATES.

Crystal Eye generates CSQ evidence from live network and endpoint telemetry. 18 or more months of data retention supports forensic investigation and audit trail requirements. When Defence tests your operating controls, the data exists because Crystal Eye has been running them — not because they were written down.

looks_3

SOVEREIGN FROM THE GROUND UP.

Crystal Eye is developed, owned, and supported onshore. All intellectual property is held by Red Piranha. The SOC operates 24/7 from Australia with Australian analysts. Defence-related telemetry remains under Australian jurisdiction throughout the engagement. FOCI-clean by construction — no foreign parent, no offshore development chain.

CRYSTAL EYE PLATFORM

What Crystal Eye Delivers for DISP Compliance.

The ICT/Cyber domain is where DISP requires evidence of operating controls — not policy documents. Crystal Eye is the platform that produces that evidence, across the network, endpoint, and behavioural layers.

E8

Essential Eight ML2, organisation-wide

Crystal Eye deploys and enforces the Essential Eight Maturity Level 2 baseline across the organisation without requiring major infrastructure changes. Inline deployment eliminates engineering overhead.

CSQ

107-control CSQ evidence from live telemetry

The Cyber Security Questionnaire evidence pack is generated from operational data, not manually assembled. Every control maps to real telemetry. Defence tests operating controls — Crystal Eye produces them.

SOC

24/7 Australian SOC monitoring

Round-the-clock detection and response from the Red Piranha SOC, staffed by Australian analysts. All telemetry under Australian jurisdiction. Push-button escalation from Crystal Eye to the SOC team without IR retainers.

18M

18+ months data retention

DISP requires demonstrable audit trails and the ability to support forensic investigation. Crystal Eye retains 18 or more months of log and event data, with integrated PCAP analysis to reduce attacker dwell time.

10x

10x network visibility

Crystal Eye provides significantly greater visibility across the network than conventional point solutions, covering NDR, EDR, SIEM, Managed Firewall, Vulnerability Scanning, and behavioural anomaly detection in a unified platform.

TI

Operationalised threat intelligence

Automated threat intelligence integration across all security layers. Detection content mapped to MITRE ATT&CK for ICS and enterprise. Proactive threat hunting capability for increased assurance against APTs and unknown threats.

COVERAGE

All Four DISP Domains. One Engagement.

Governance and Information and Cyber Security are direct delivery — we build, deploy, and run them. Personnel and Physical Security are guided — we specify what is required and support you through the process.

DOMAIN

ICT & CYBER
DELIVERY

WHAT RED PIRANHA PROVIDES

  •  Essential Eight ML2 deployment via Crystal Eye
  •  107-control CSQ evidence from live telemetry
  •  24/7 Australian SOC — TDIR, NDR, EDR
  •  Continuous monitoring and MITRE ATT&CK-mapped detection
  •  Maturity Action Plan and ongoing uplift

GOVERNANCE
  •  Security Risk Management Plan authorship
  •  Incident Response Plan
  •  CSO and SO role definition and training
  •  Annual Security Report preparation
  •  eCISO retainer for ongoing governance

PERSONNEL
  •  AGSVA clearance pathway guidance
  •  AS 4811:2022 workforce screening requirements
  •  Insider threat policy and Assessed Position definition

PHYSICAL
  • Zone classification mapping
  • ASIO T4 standards alignment
  • Facility certification readiness
ENGAGEMENT MODEL

From First Conversation to Sustained Membership.

The DISP cycle runs continuously. Red Piranha stays engaged across every stage — eligibility through to the Ongoing Suitability Assessment and Deep Dive Audit. There is no point at which the engagement ends and you are left to maintain it alone.

STAGE 1

ASSESS

Eligibility check, gap analysis against all four domains, eCISO engagement scoping. Determine the correct membership level for your contracted work.


OUTPUT
DISP gap snapshot and Maturity Action Plan

STAGE 2

BUILD

SRMP and IRP authored. Crystal Eye deployed. Essential Eight ML2 operationalised. CSQ evidence pack assembled from live telemetry.


OUTPUT
DISP gap snapshot and Maturity Action Plan

STAGE 3

OPERATE

Crystal Eye TDIR running 24/7. Australian SOC monitoring active. Proactive threat hunting. Incident detection and response without separate IR retainers.


OUTPUT
Continuous detection, operational audit trail

STAGE 4

SUSTAIN

Annual Security Report preparation. OSA gap closure. DDA evidence pack. eCISO retainer for ongoing governance and membership obligations.


OUTPUT
Annual cycle, ongoing DISP membership

GET STARTED

Where are you in the DISP Cycle?

Each conversation starts the same way — 30 minutes with a specialist who has operated inside the DISP program. No obligation. No sales deck.

STARTING OUT

Get your DISP Readiness Score.

Gap snapshot. Maturity Action Plan. Eligibility review and eCISO™ engagement scoping.
MID-APPLICATION

Book a CSQ Evidence Review.

Walk through your 107-control submission. Identify gaps against live telemetry before lodgement.
ALREADY A MEMBER

Book an OSA / DDA Readiness Check.

Annual Security Report preparation. OSA gap closure. Deep Dive Audit evidence pack.
GRANT ASSISTANCE

Defence Grants can fund the Security Uplift DISP Requires.

The Defence Industry Development Grants (DIDG) program funds Australian SMEs building sovereign capability for the Defence sector. Up to $1 million per project at 50% cost-share, across four streams: Exports, Security, Skilling, and Sovereign Industrial Priorities. Red Piranha assists with applications and delivers what the grant funds.

ELIGIBILITY AND APPLICATION SUPPORT
Australian state and federal grant programs provide funding pathways for defence-sector SMEs undertaking security uplift and capability development. Available grants and eligibility criteria vary by state and change regularly. Red Piranha assists clients with identifying applicable programs, preparing applications, and delivering the security outcomes the funding supports. Contact the team to understand what current programs may apply to your situation.

Start your DISP journey with
​​​​​​​Red Piranha.

Whether scoping eligibility for the first time, mid-application, or already a member preparing for your next ASR - the conversation starts with 30 minutes and a specialist who has run the DISP cycle from inside.

Book your free assessment.