LevelBlue has opened a new security operations center in Sydney, expanding its onshore cybersecurity capabilities as Australian critical infrastructure operators face rising threats and growing obligations under the Security of Critical Infrastructure Act.
The multi-million-dollar investment gives organizations access to local analysts and escalation pathways backed by LevelBlue’s global threat intelligence and 24/7 security operations, while addressing increasing demand for regional expertise, data sovereignty and continuous compliance support.
Australian critical infrastructure faces compounding cyber pressures
Speaking with Channel Insider, Jo Salisbury, regional director of growth and performance for APAC at LevelBlue, described Australian critical infrastructure organizations as facing multiple cyber, operational, and regulatory pressures simultaneously.
Australian critical infrastructure environments increasingly combine legacy operational technology, modern IT systems, and third-party platforms. According to Salisbury, that convergence is expanding the attack surface while making vulnerabilities more difficult to remediate.
“As Australian critical infrastructure faces concurrent, compounding threats, with limited resources, owners and operators need localized intelligence and cyber teams that can manage risk in real time and align with compliance requirements,” Salisbury said.
LevelBlue is positioning its new Sydney SOC around that need, providing Australian organizations with onshore security analysts and local escalation while drawing on the company’s wider global security operations.
Sydney SOC pairs local response with global threat intelligence
According to LevelBlue, the Sydney SOC provides:
- Australia-based security operations staffed by local analysts
- 24/7 coverage through LevelBlue’s global SOC network
- Local contacts and defined escalation pathways
- Threat intelligence and broader visibility drawn from LevelBlue’s global security teams and telemetry
Salisbury said the broader SOC network provides continuous monitoring, threat visibility, and around-the-clock support, while the Sydney team adds knowledge of Australia’s regulatory environment and customers’ local operating requirements.
“If an incident occurs, customers have a clear local point of contact who can apply that context, coordinate the response, and draw on LevelBlue’s wider network when additional intelligence or expertise is needed,” Salisbury said.
The onshore model also gives customers access to local analysts and escalation pathways without requiring them to build and staff every security capability internally, an important consideration amid Australia’s persistent cybersecurity skills shortage.
LevelBlue positions SOC services around SOCI requirements
According to LevelBlue, the Sydney SOC can help critical infrastructure operators operationalize parts of their SOCI obligations through continuous monitoring, local escalation, threat intelligence, and incident response.
“These capabilities help teams establish when an incident occurred, understand its potential impact, preserve relevant information, and quickly involve the stakeholders responsible for response and reporting,” Salisbury said.
LevelBlue said the SOC can also support broader Essential Eight initiatives through improved visibility, vulnerability identification, access monitoring, and incident response. However, the company emphasized that the Essential Eight complements rather than replaces an organization’s SOCI obligations.
Compliance and data sovereignty reshape the MSSP opportunity
Beyond the Sydney SOC launch, Salisbury discussed a broader shift in how MSSPs may need to support customers across Australia and the wider ANZ region as regulatory expectations and cyber risks increase.
“As compliance expectations increase, MSSPs need to help customers treat compliance as an outcome of effective security operations rather than a separate, point-in-time exercise,” Salisbury said.
Salisbury added that evidential reporting should be generated through day-to-day security operations rather than reconstructed when an audit occurs, or a regulator requests it.
LevelBlue’s announcement also cited geopolitical tensions as intensifying the threat landscape for Australian organizations.
Salisbury said these pressures are increasing the focus on data sovereignty, regional threats, and the resilience of critical services.
As a result, Salisbury argued MSSPs will need to provide onshore delivery options, threat intelligence tailored to Australia and the wider ANZ region, and greater clarity around where customer data resides and who can access it.
“Regional threat intelligence will also be essential, particularly intelligence that reflects the adversaries, industries, infrastructure, and geopolitical risks affecting Australia and the broader ANZ market,” Salisbury said.
Earlier this year, LevelBlue introduced its Resilience Retainer solution, providing rapid access to more than 300 incident response experts. Read more about the offering and its approach to cyber resilience.





