Sovereign by design. Sector-aware by default.
xCIRT exists because Australian critical infrastructure deserves incident response that is built, staffed, and operated here — not adapted from elsewhere.
Why xCIRT exists
Australia's critical infrastructure operators are increasingly exposed where IT, OT, and IoT converge. Cloud-connected control systems, SCADA, PLCs, and field IoT widen the attack surface, while obligations under the SOCI Act and the Critical Infrastructure Risk Management Program raise the bar for response capability.
Most operators do not have a sovereign provider that can respond to incidents touching both cloud and the plant floor. Foreign primes carry data-residency questions. Generic Australian IT security firms rarely have native OT/IoT incident response depth. xCIRT is built for that gap.
We cover the full cloud-to-edge path — from hyperscaler workloads down to ICS, SCADA, PLCs, IIoT gateways, and connected field assets — delivered by Australian responders, with Australian data custody, under Australian law.
What guides every engagement.
Sovereignty
Australian-owned, Australian-staffed, onshore data — without compromise. Sovereignty is not a feature, it is the operating model.
Operational respect
Containment that respects safety-critical operations. No "pull the cable" reflexes on production OT. Decisions made jointly with your operations team.
Sector-aware delivery
Responders matched to your sector. Electricity, water, gas, ports, rail, aviation — the language and constraints differ, and so should the playbooks.
Who responds.
Matthew Gurr
Matt brings nearly three decades of cybersecurity leadership, spanning hands-on technical practice through to executive risk advisory. His career has been shaped by helping organisations across regulated and high-stakes industries — including financial services, government, defence, healthcare, and critical infrastructure — turn security from a cost centre into a source of operational resilience.
He has led security functions through periods of rapid growth, regulatory change, and large-scale incident response, working with boards, executives, and technical teams to translate complex risk into decisions the business can act on. He founded xCIRT to bring that depth to Australian critical infrastructure operators who need sovereign, OT-aware response capability.
GAICD · CISSP · CISM · SABSA SCF · AWS SA · CCSK
LinkedIn →Need an Australian responder, now?
Retainer engagements, scoped pilots, and SOCI-readiness packages. Talk to us about what your critical-infrastructure estate needs.