Sovereign by design. Sector-aware by default.

xCIRT exists because Australian critical infrastructure deserves incident response that is built, staffed, and operated here — not adapted from elsewhere.

Why xCIRT exists

Australia's critical infrastructure operators are increasingly exposed where IT, OT, and IoT converge. Cloud-connected control systems, SCADA, PLCs, and field IoT widen the attack surface, while obligations under the SOCI Act and the Critical Infrastructure Risk Management Program raise the bar for response capability.

Most operators do not have a sovereign provider that can respond to incidents touching both cloud and the plant floor. Foreign primes carry data-residency questions. Generic Australian IT security firms rarely have native OT/IoT incident response depth. xCIRT is built for that gap.

We cover the full cloud-to-edge path — from hyperscaler workloads down to ICS, SCADA, PLCs, IIoT gateways, and connected field assets — delivered by Australian responders, with Australian data custody, under Australian law.

2hr Remote triage target
24/7 On-call coverage
100% Onshore handling
Our values

What guides every engagement.

Sovereignty

Australian-owned, Australian-staffed, onshore data — without compromise. Sovereignty is not a feature, it is the operating model.

Operational respect

Containment that respects safety-critical operations. No "pull the cable" reflexes on production OT. Decisions made jointly with your operations team.

Sector-aware delivery

Responders matched to your sector. Electricity, water, gas, ports, rail, aviation — the language and constraints differ, and so should the playbooks.

The team

Who responds.

Matthew Gurr
Co-founder

Matthew Gurr

Matt brings nearly three decades of cybersecurity leadership, spanning hands-on technical practice through to executive risk advisory. His career has been shaped by helping organisations across regulated and high-stakes industries — including financial services, government, defence, healthcare, and critical infrastructure — turn security from a cost centre into a source of operational resilience.

He has led security functions through periods of rapid growth, regulatory change, and large-scale incident response, working with boards, executives, and technical teams to translate complex risk into decisions the business can act on. He founded xCIRT to bring that depth to Australian critical infrastructure operators who need sovereign, OT-aware response capability.

GAICD · CISSP · CISM · SABSA SCF · AWS SA · CCSK

LinkedIn →
Frameworks & Standards
SOCI Act CIRMP AESCSF IEC 62443 ASD Essential Eight NIST SP 800-82

Need an Australian responder, now?

Retainer engagements, scoped pilots, and SOCI-readiness packages. Talk to us about what your critical-infrastructure estate needs.