Skip to main content

Know where your cybersecurity stands.

Then make decisions you can defend.

Cliffside helps Australian organisations make cybersecurity decisions that stand up to executive, customer, auditor and regulatory scrutiny, with senior advice, hands-on delivery and selected technology. Founded in Sydney in 2014. ISO/IEC 27001:2022 certified.

ISO/IEC 27001:2022 certified 2026 finalist, Benchmark Security Awards 5.0 out of 5 stars on Google

BSI Mark of Trust, ISO/IEC 27001 certified, certificate IS 834275BSI Mark of Trust, ISO/IEC 27001 certified, certificate IS 834275
  • Wesfarmers
  • AMP
  • Great Southern Bank
  • NSW Government
  • University of Western Australia
  • Hourigan

The problem

Cyber risk is often accepted without anyone deciding to accept it.

Requirements stay unclear. Vendor claims go unverified. Exceptions have no owner or expiry date. Projects proceed because deadlines are visible and residual risk is not.

Organisations should proceed when evidence exists, not when confidence merely feels high.

Brutal honesty makes the truth usable

What makes a cybersecurity decision defensible?

A defensible decision does not guarantee that nothing will go wrong. It shows the organisation considered the context, relied on appropriate evidence, understood the trade-offs and assigned accountability.

See how we work →
  1. Evidence

    Know what supports the decision. Verified evidence is kept apart from analysis, assumptions and matters still to confirm.

  2. Context

    Risk is weighed against your environment, obligations, priorities, capability and tolerance for disruption.

  3. Ownership

    Material risks, actions, exceptions and deadlines have named owners, and responsibility does not fall between you, us and your vendors.

  4. Action

    Each recommendation says what happens next, who does it and what evidence will show it is closed.

Start with the decision in front of you.

02 / 03 · In public

5.0 out of 5 stars on Google

  • “Because of their support and honest advice, our security posture is much better than what it was six months back.”

    Varun Pant · Google review
  • “…a report that was packed with actionable items and in priority order. This made it super clear to us what we needed to work on.”

    Allan Li · Google review
  • “Tested more than the default OWASP Top 10 / basic testing, created custom checks specifically for LLMs. Recommend without hesitation”

    Timothy Glover · Google review
Adri Leite presenting to two Cliffside consultants in the Sydney office
03 / 03 · The team

Meet the team

About Cliffside
  • Adri Leite CEO & Founder
  • Ajay Ambadan Senior Security Consultant
  • Juane Birck Operations Manager
  • Param Chopra Business Development Manager

The team

Our team holds these certifications.

Personal certifications held by individual Cliffside consultants, not certifications of Cliffside itself.

  • ISC2 CISSP badge
    CISSPISC2
  • ISC2 CCSP badge
    CCSPISC2
  • CREST Practitioner Security Analyst (CPSA) badge
    CPSACREST
  • CREST Registered Penetration Tester (CRT) badge
    CRTCREST
  • SABSA Chartered Architect, Foundation (SCF) badge
    SABSA FoundationThe SABSA Institute

Also heldOSCP, OSCE, OSWE and OSWP (OffSec) · ISO/IEC 27001 Lead Auditor and Lead Implementer, ISO/IEC 42001 Lead Implementer (BSI) · CISA (ISACA)

The outcome comes first. The solution may include technology.

A commercial relationship does not invalidate a recommendation. An unexplained recommendation does.

Where we recommend a product we sell or manage, we explain the requirement it addresses, validate its fit, name its limitations and the risks that remain, disclose our commercial role, and stay accountable for the services we deliver around it.

Clear before commitment: our eight commitments →

What makes a cybersecurity decision defensible?

It shows the organisation considered the relevant context, relied on appropriate evidence, understood the trade-offs and assigned accountability. It does not guarantee that nothing will go wrong.

What does Cliffside do?

Cliffside is a Sydney cybersecurity company that helps Australian organisations make decisions that stand up to executive, customer, auditor and regulatory scrutiny: strategy and architecture, compliance, security testing, cloud and Microsoft security, managed security and secure AI. Founded in 2014, ISO/IEC 27001:2022 certified.

How much does a penetration test or ISO 27001 cost?

Penetration testing packages start at $5,900 ex GST for 3 testing days. ISO 27001 certification readiness is $4,300 a month over 12 months, ex GST, for up to 50 people.

Do you sell products as well as advice?

Yes, selectively. When we recommend a product we sell or manage, we disclose our commercial role, its limitations and the risks that remain.

Bring us the decision you need to make.

You do not need to know which service to ask for. Tell us what you are trying to protect, prove, launch, fix or decide, and we will help establish the evidence, risks, ownership and practical next step.

Brutally Honest Cybersecurity. Defensible decisions.