Security Engineering · Advisory
Available now · Three fixed-scope engagements

The analysis your engineers and your lawyers each only half own.

Australian defence-adjacent technology firms rarely lose work for technical reasons. They lose it at an evidentiary gate — a DISP application held at the wrong level, an export classification nobody checked against the bill of materials, a sovereignty claim that survives marketing but not procurement. Those failures live in the gap between the people who build the system and the people who read the regulation. JEGASEC works in that gap, and returns a written determination you can put in front of a board, a prime, or a Commonwealth buyer.

This is JEGASEC's professional-services capability. It is distinct from the company's product mission, led by Continuity, and it is intended to help fund continued product development.

Engagements are document-based, not meeting-based.

Every engagement is fixed in scope, fixed in fee, and delivered as a written instrument. There are no discovery calls, standing check-ins, workshops or live support components. This is a methodology, not a limitation: the analysis is worth what it costs because it is produced in uninterrupted depth against a complete evidence set, rather than assembled between meetings.

01

Scope confirmation

You receive the engagement scope, the input manifest, and three available start dates. Nothing is negotiated by call. A written intake instrument replaces the discovery meeting entirely.

Written · 2 business days
02

Evidence upload and data freeze

You upload the complete input manifest to a per-engagement encrypted workspace before the agreed freeze date. From that date the evidence set and the scope are fixed, and the delivery clock starts.

Client-side · Deadline-driven
03

Analysis

Uninterrupted analytical work against the frozen evidence set. You may submit up to three consolidated written query bundles during this window. Responses are within two business days.

20 to 30 business days
04

Written determination

You receive the bound deliverable, plus two rounds of consolidated written comments for correction and clarification within the agreed scope. Where a walkthrough is useful, it is provided as a recorded briefing.

Deliverable · Two revision rounds
What this model excludes JEGASEC does not access, configure, test or operate client systems under these engagements. The analysis is performed on documentary evidence you supply. That boundary is deliberate — it is what makes a fixed fee, a fixed timeline and a clean liability position possible for all three parties involved: you, us, and whoever you hand the deliverable to.

Three engagements.

Each is a single written artifact addressing a single evidentiary gate. Fees are fixed and stated in full below, exclusive of GST, payable 50% on commencement and 50% on delivery.

Engagement A · Cyber & ICT firms
$16,500ex GST · 20 business days

Defence Readiness Determination — the DISP level you can actually substantiate, and what stands between you and the one you need.

Engagement B · Autonomous systems
$29,500ex GST · 30 business days

Sovereign Autonomy Compliance Architecture — export classification, component provenance and autonomy assurance, reconciled in one document.

Engagement C · Hosting & infrastructure
$24,000ex GST · 25 business days

Sovereign Control Attestation Pack — what you can truthfully claim about sovereignty, evidenced, plus the extract you hand to buyers.

Engagement A · $16,500 ex GST

Defence Readiness Determination

For mid-tier cyber and ICT firms pursuing Commonwealth panels or prime subcontracts. DISP assesses membership across four separate domains — security governance, personnel, physical and ICT — and governance is pinned to the highest level sought in any other domain. One weak domain therefore caps the entire membership, and firms routinely discover this after committing a bid cycle to an application that was never going to clear at the level lodged.

This engagement returns a reasoned determination of the level your evidence currently supports, domain by domain, and the specific artifacts that stand between that position and the one your target contracts require.

What you upload
  • Corporate structure and beneficial ownership
  • Security policy suite and governance charter
  • Screening procedures and current clearance holdings
  • Site plans, access control and facility arrangements
  • Network architecture and Essential Eight self-assessment
  • The contracts or panels you are pursuing
What you receive
  • Written determination, stated by domain
  • Evidentiary basis for each assessed position
  • Tabulated gap register with dependency order
  • Phased remediation sequence and critical path
  • Submission evidence-pack index
  • Annexure: flow-down clause analysis
Engagement B · $29,500 ex GST

Sovereign Autonomy Compliance Architecture

For uncrewed and autonomous systems manufacturers moving from prototype into Defence programs or export markets. A platform is simultaneously a controlled good under the Defence Trade Controls Act and the Defence and Strategic Goods List, a supply-chain sovereignty question determined by component provenance, and an assurance object whose autonomy behaviour must be defensible in writing. Those three domains are usually owned by three people who never co-author a single document — which is where programs stall, at the export or due-diligence gate, after the capital is already spent.

This engagement reconciles all three into one architecture document: where the platform sits against the control lists, which components disqualify it from which programs, and whether the autonomy argument holds.

What you upload
  • Full performance envelope and published claims
  • Complete BOM with country of design and manufacture
  • Autonomy architecture, failsafe and lost-link behaviour
  • Cryptographic and datalink design
  • Prior export permits, decisions or classification advice
  • Target programs, primes and export destinations
What you receive
  • Written control-classification position
  • Provenance ledger graded by sovereignty risk
  • Named substitution candidates for blocking components
  • Structured autonomy assurance argument
  • Program eligibility matrix with blocking conditions
  • Annexure: marketing-claim escalation register
Engagement C · $24,000 ex GST

Sovereign Control Attestation Pack

For hosting, cloud and managed-infrastructure providers selling to Commonwealth, state and critical-infrastructure customers. Sovereignty is now an evidentiary claim rather than a marketing one. Under the Hosting Certification Framework the distinction between certification tiers turns on ownership and control, not technology. Under the Security of Critical Infrastructure regime, your customers carry risk-management-program obligations — including independent assurance and contractual management of supply-chain dependencies — that flow down onto you in writing, and that they will ask you to evidence.

This engagement returns the attestation you put in front of those buyers, and an honest internal statement of what you can and cannot currently claim.

What you upload
  • Ownership, control rights and board composition
  • Facility register with ownership and operator status
  • Topology and cross-jurisdictional data flows
  • Privileged access roles, locations and clearances
  • Existing assessment reports and certification scope
  • Customer contracts and flow-down obligations
What you receive
  • Evidence-referenced sovereignty position statement
  • Control and influence analysis against tier conditions
  • Jurisdictional exposure map, including support paths
  • Flow-down analysis of customer CIRMP obligations
  • Certification pathway with the concessions each tier requires
  • Annexure: customer-facing attestation extract, cleared for release

Why this analysis, from here.

The work sits at an uncommon intersection: defence engineering practice, cyber security grounding, and the regulatory literacy to read a flow-down clause and a network architecture diagram as the same document. JEGASEC is independent and founder-led, and sells rigour and operator credibility rather than certifications it does not hold.

  • Former RAAF electronics engineering officer — Defence capability work, electronic-warfare simulation exposure, sensitive technical data governance
  • Bachelor of Computing and Cyber Security, UNSW Canberra
  • Juris Doctor, Monash University — commenced May 2026, studied alongside ongoing cyber security and technology work
  • Frameworks applied: ACSC Essential Eight, OWASP, MITRE ATT&CK, Defence Security Principles Framework, DSGL, Hosting Certification Framework, SOCI

Advisory independence is a standing principle here: this practice is not a sales channel for JEGASEC's own products, and "you don't need this" is a legitimate finding. Read more about the founder.

Before you enquire.

These engagements suit a specific kind of client, and are a poor fit for others. Rather than discover that on a call neither of us wanted, here is the filter in full.

A good fit if

  • Budget is approved, or approvable against a scope document
  • You prefer a written determination to a series of meetings
  • You can assemble the input manifest within two to six weeks
  • Someone identifiable can authorise release of those documents
  • There is a specific gate this needs to clear, with a date attached

A poor fit if

  • You need regular check-ins or a named contact for live questions
  • You are looking for someone to work alongside your team day to day
  • You need help producing the underlying evidence, not analysing it
  • You are collecting comparative quotes against hourly proposals
  • You need hands-on testing of a live environment

If the second column describes you, say so in your enquiry and we will point you to a firm better suited to it. That referral costs us a sale and saves you a quarter.

Scope, boundaries and what JEGASEC does not claim JEGASEC holds no ISO 27001, IRAP, DISP, SOC 2 or Essential Eight maturity certification, and does not represent authority to accredit or assess against any standard. These engagements are independent technical and structural analysis. They complement accredited assessors and Commonwealth decision-makers; they do not replace them, and no determination in a JEGASEC deliverable binds any regulator, assessor or delegate.

JEGASEC is not an Australian legal practice and does not provide legal services, legal advice or legal opinions. Where a deliverable addresses legislation, control lists, standards or contractual provisions, it does so as technical and structural analysis of the requirements those instruments impose on systems, evidence and organisational design. Obtain independent advice from an admitted legal practitioner before acting on any matter bearing on your legal position.

No warranty is given that any engagement will result in a certification, membership, permit, clearance, panel position or approval being granted — those determinations rest entirely with the relevant decision-maker. Analysis states a position as at the evidence-freeze date and is prepared for the client named in the engagement, on the evidence that client supplies.

JEGASEC is an independent business and is not endorsed by, affiliated with or representing the Australian Defence Force or the Australian Government. Do not send classified, protected or operationally sensitive material to JEGASEC without a separate written agreement and appropriate handling arrangements in place.