About Damocles Security

A cybersecurity company built to find exposure, operate controls and help customers finish the remediation.

Damocles brings together offensive security, application and cloud review, managed protection, security operations, network engineering and Guardian. The aim is practical: explain what is wrong, help the right people act and retain evidence that the risk was reduced.

Offensive security and assuranceManaged protection and security operationsNetwork, firewall and remediation engineeringGuardian platform and MSP delivery model
What Damocles is

The security company performs the work. Guardian keeps the work connected.

Damocles delivers security assessments, managed protection, security operations and engineering. Customers engage us to validate an attack path, review an application or cloud environment, operate a security control, investigate material activity, design a safer architecture or complete difficult remediation.

Guardian is the platform Damocles built to support that delivery. It connects customer posture, findings, risks, owners, actions, evidence and reporting. Guardian is an important part of the operating model, but Damocles is broader than the platform.

01

Assess the real environment

Use authorised testing and review to understand practical attack paths, control gaps and operational exposure.

02

Operate selected controls

Provide managed protection, source health, monitoring, triage, investigation, escalation and reporting where contracted.

03

Help complete the change

Support remediation, architecture, migration, configuration, retesting and evidence review rather than stopping at the finding.

What we do

Security capability across assessment, operation and remediation.

The customer can engage a focused service or combine Damocles services and Guardian products into a recurring operating model.

OS

Offensive security

External, internal, wireless, website and API penetration testing with attack-path validation, evidence and retesting.

Explore Penetration Testing →
AS

Application and cloud security

Secure code review, application testing, API testing and cloud security review focused on identity, data and trust boundaries.

Explore assessment services →
MP

Managed protection

Endpoint protection, managed patching, DNS protection and Svalinn managed web application firewall services.

Browse managed products →
SO

Security operations

Source onboarding, source health, alert triage, investigation, escalation, managed defence and customer reporting.

Explore Aegis →
NE

Network and security engineering

Segmentation, firewall policy, remote access, migrations, hardening, resilience and controlled implementation.

Explore Network Security →
IR

Incident readiness and remediation

Roles, playbooks, evidence, tabletop exercises, response preparation and specialist remediation support.

Explore Incident Readiness →
How Damocles works

Evidence first, responsibilities clear and closure reviewed.

The technical method changes by service, but the operating discipline remains consistent.

01

Understand the customer question

Confirm the environment, concern, business consequence and decision the work must support.

02

Define scope and authority

Agree systems, targets, users, credentials, service coverage, timing, contacts, exclusions and safety boundaries.

03

Collect and validate evidence

Use the authorised assessment, monitoring, engineering or operational method required for the service.

04

Explain what matters

Describe the affected scope, attack path, control failure, operational consequence and remediation priority.

05

Assign and complete the work

Make the required testing, patching, configuration, investigation, training or engineering action explicit.

06

Review the outcome

Use retesting, rescans, source state, configuration evidence or exercise results to assess completion.

What customers should expect

Practical security delivery without hiding uncertainty or responsibility.

SC

Clear scope

The customer knows what is included, what evidence is required, who is responsible and what remains outside the work.

TE

Technical evidence

Findings and operational conclusions contain enough context for the customer to understand and act.

BP

Business perspective

Leadership receives an explanation of material consequence, unresolved risk and decisions required.

OW

Visible ownership

Remediation is assigned to the person or team that can complete it, with timing and expected outcome.

VR

Verification before closure

Retesting, rescans, patch state, configuration evidence or operational review supports the closure decision.

HB

Honest boundaries

Damocles does not represent missing evidence, unsupported coverage or uncertain results as complete assurance.

Who we work with

Direct customers, internal teams and service providers need different operating models.

Damocles works with organisations that need specialist assessment, managed protection, security operations, engineering or a structured way to manage remediation. This includes businesses and NDIS providers using Guardian for staff and participant security outcomes.

MSPs and MSSPs can use Guardian’s provider-scoped customer workspaces, product entitlements and consolidated wholesale billing while retaining their own customer relationship, first-line support model and retail pricing.

01

Direct organisations

Select the Damocles services and Guardian products required for the customer environment and responsibilities.

02

Internal security and IT teams

Use Damocles for specialist validation, architecture, operational support and difficult remediation.

03

MSPs and MSSPs

Package approved products, operate authorised customers and use clear wholesale, support and escalation boundaries.

How Guardian came from the work

The recurring problem was not a lack of findings. It was the gap between finding, fixing and proving the outcome.

Security assessments, monitoring tools and managed products all produce useful evidence, but the information is often split across reports, consoles, spreadsheets and support queues. The people finding the issue, the people fixing it and the people accepting the risk frequently work from different records.

Guardian was created to keep the customer-safe finding, risk, owner, action, due date, evidence and review history together. It supports Damocles delivery and gives customers and providers a consistent way to manage the work that follows security evidence.

What we will not pretend

No absolute security promises, invented coverage or automatic conclusions.

Damocles explains what was observed, how the evidence was obtained, what the likely consequence is, what should change and which assumptions or limitations remain.

The website does not claim guaranteed detection, zero vulnerabilities, universal source coverage, automatic compliance, unverified accreditation, fixed response outcomes or data-residency commitments that have not been separately approved and documented.

Work with Damocles

Bring us the security problem that is difficult to see, operate or finish.

We will determine whether the right next step is assessment, engineering, managed protection, security operations, incident readiness or a Guardian product—and explain the scope before work begins.