LevelBlue opens Sydney security centre for Australia
Thu, 27th Aug 2026 (Today)
LevelBlue has opened a Security Operations Centre in Sydney, backed by a multi-million-dollar investment.
The centre is aimed at Australian organisations, particularly owners and operators of critical infrastructure. It will provide onshore security analysts, local escalation pathways, and support aligned with the Australian regulatory environment, while linking into LevelBlue's broader 24/7 security network and threat intelligence.
The move comes as critical infrastructure operators face tighter scrutiny over cyber risk and incident response. Under the Security of Critical Infrastructure Act, some entities must report critical cyber incidents within 12 hours and other cyber incidents within 72 hours. Certain organisations must also maintain a written Critical Infrastructure Risk Management Program.
Demand for local cyber support has also been rising across Australia and New Zealand, driven by a shortage of cybersecurity workers, closer scrutiny of operational and third-party risk, and changing expectations around data handling.
For clients, the Sydney site forms part of LevelBlue's broader Five Eyes network. It is intended to give Australian organisations direct access to analysts in their own time zone while still drawing on threat data and expertise from the company's international operations.
The launch reflects a wider cybersecurity market trend, with global service providers expanding their local presence to meet regulatory requirements and customer demand for in-country support. In Australia, critical infrastructure and government-linked organisations have faced sustained pressure to demonstrate stronger preparedness, monitoring, and incident handling.
Jo Salisbury, Regional Director Growth & Performance - APAC, LevelBlue, linked the launch to those requirements.
"Australian organisations want a security partner that understands the local regulatory environment and can quickly escalate when an incident occurs," said Jo Salisbury, Regional Director Growth & Performance - APAC, LevelBlue. "Geopolitical tensions are intensifying the threat landscape, and our Sydney SOC gives Australian organisations access to local analysts and context, together with global threat intelligence and 24/7 coverage that critical infrastructure operators need to manage risk, support their SOCI obligations, and strengthen cyber resilience."
Local focus
The Sydney operation will support critical infrastructure, state and local government, regulated enterprises, and mid-market organisations. LevelBlue described the service as vendor-agnostic, meaning customers can use it across different security technology environments rather than being tied to a single supplier's tools.
The centre can also support organisations working on Essential Eight maturity alongside broader cyber risk programs. The Essential Eight is a baseline set of mitigation strategies widely used in Australia, although it does not replace obligations under the SOCI framework.
Allison Clelan, Senior Vice President, Managed Global Security Solutions, LevelBlue, said the investment was part of a broader commitment to the market.
"This investment reflects LevelBlue's commitment to the Australian market and the critical infrastructure sector," said Allison Clelan, Senior Vice President, Managed Global Security Solutions, LevelBlue. "As a vendor-agnostic MSSP, we bring local delivery and global scale together to help clients strengthen resilience while retaining greater choice and flexibility across their security environments."
Customer backing
Melbourne Airport has become the first organisation to move to the new Australian operation, according to LevelBlue. The airport's Chief Information Officer said the local set-up would improve access to domestic expertise and escalation while maintaining links to the company's global intelligence operation.
"As a LevelBlue customer for six years, we have consistently valued the strength and reliability of our partnership. We are proud to be the first organisation to transition to LevelBlue's Australian SOC, giving us greater access to local expertise and escalation backed by LevelBlue's global intelligence and expertise," said Anthony Tomai, Chief Information Officer, Melbourne Airport. "For Melbourne Airport, this local capability strengthens our ability to manage cyber risk and support our obligations under the Security of Critical Infrastructure Act. It is exactly the kind of investment Australian critical infrastructure needs from a trusted security partner."