Surprisingly Useful AI Article Enhancements
Cybersecurity vendor, Darktrace, has completed an assessment under the Information Security Registered Assessors Program (IRAP) against the Australian Government Information Security Manual’s PROTECTED-level controls for its Darktrace / NETWORK and Darktrace / OT platforms.
The assessment was conducted by an Australian Signals Directorate-endorsed IRAP assessor and provides Australian government agencies and regulated-industry organisations with independent evidence to support their evaluation of Darktrace’s products against relevant security, governance and risk-management requirements.
IRAP is the security compliance framework developed by the ASD and administered by the Australian Cyber Security Centre (ACSC). It provides Commonwealth government entities with a framework for assessing the security controls of ICT systems and cloud service providers against the ISM – the prescriptive cybersecurity control set for federal systems.
The assessment covers Darktrace’s network detection and response platform, Darktrace / NETWORK, and its operational technology security product, Darktrace / OT, which monitors traffic across industrial control systems and critical infrastructure.
Targeting government and defence adoption
Key Account Director at Darktrace, Kiranraj Govindaraj, framed the assessment in the context of the security challenges facing Australian government and defence organisations as they modernise their IT and OT environments.
“Australian Government and defence organisations are modernising quickly, but they cannot afford to create new security blind spots as their environments become more connected and complex,” Govindaraj explained. “Completing an IRAP assessment against the ISM’s PROTECTED-level helps Australian government and defence institutions to adopt Darktrace’s Adaptive AI capabilities with confidence.”
“Our unique behavioural security approach can enable them to understand normal behaviour across their operations, then identify and contain emerging threats before they disrupt critical services or operations, whether generated by human or AI actors,” he added.
What PROTECTED means in practice
The PROTECTED classification is the second-highest level in the Australian Government’s information security framework, sitting below SECRET and TOP SECRET but above OFFICIAL. Systems assessed at PROTECTED level handle information whose compromise could cause damage to the national interest, organisations or individuals.
For vendors seeking to sell into Australian government agencies, completing an IRAP assessment at PROTECTED level provides the independent assurance that agencies require before granting an Authority to Operate. The assessment is not a rubber stamp – it involves a detailed technical and procedural review of architecture, policies, technical controls and operational evidence against the ISM controls applicable to the target classification level.
Industry estimates put the cost of a complex PROTECTED-level IRAP assessment anywhere from $150,000 to more than $250,000, reflecting the depth and rigour of the evaluation process. The output is an IRAP Assessment Report that the sponsoring agency uses to decide whether to authorise the system for use in its environment.
A growing threat landscape
The timing of the assessment reflects the intensifying cyber threat environment facing Australian government and critical infrastructure organisations.
The ASD’s most recent Annual Cyber Threat Report recorded more than 84,700 cybercrime reports in the last financial year, roughly one every six minutes. The ACSC responded to more than 1,200 cybersecurity incidents, an 11 per cent increase on the prior period. Notifications to critical infrastructure entities about potentially malicious cyber activity rose to more than 190, representing a 111 per cent increase year-on-year.
State-sponsored cyber actors remain a persistent concern. The ASD has joined multi-country advisories warning of state-sponsored actors targeting critical infrastructure for the purposes of positioning for potential disruptive attacks. Groups including Salt Typhoon and Volt Typhoon, linked to the People’s Republic of China, have been observed targeting telecommunications providers and pre-positioning within Western critical infrastructure networks.
Australia’s 2026 National Defence Strategy reinforced the urgency, identifying cyber as a contested and continuous domain and directing between $27 billion and $38 billion toward cyber, space and electronic warfare capabilities over the coming decade. The ASD has also launched its Cyber Action Year 2026 program, a coordinated effort to deliver practical cybersecurity outcomes across government, industry and critical infrastructure, urging Australian organisations to adopt an “assumed breach” mindset.
The behavioural approach
Darktrace’s technology takes a behavioural approach to threat detection, using what the company calls Adaptive AI to continuously learn how an organisation’s people, devices and systems behave. Rather than relying on known attack signatures or previously observed threats, the system builds an understanding of normal behaviour and flags deviations that may indicate malicious activity.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
This approach is designed to detect threats that signature-based tools may miss, including novel attacks, insider threats and activity generated by AI-enabled adversaries. The system can detect, investigate and respond to suspicious activity autonomously.
A key factor for government and defence use cases is that Darktrace / NETWORK and Darktrace / OT run entirely on-appliance without dependency on cloud connectivity, signature feeds or external threat intelligence services. This means the platforms continue to operate when network links are severed, under emissions control (EMCON) conditions or in fully air-gapped deployments.
The announcement noted this capability provides data sovereignty by design for UK Ministry of Defence, NATO and AUKUS coalition operations – a relevant consideration for Australian agencies operating within the AUKUS framework.
Building on FedRAMP
The IRAP assessment builds on Darktrace’s progress in the United States, where the company’s federal division has achieved FedRAMP High Authorization – the highest baseline within the US Federal Risk and Authorization Management Program.
FedRAMP High is reserved for cloud systems where the loss of confidentiality, integrity or availability could have a severe or catastrophic effect on organisational operations, assets or individuals. Achieving both FedRAMP High and IRAP PROTECTED-level assessment positions Darktrace to serve government customers across multiple allied jurisdictions.
The company, which was founded in Cambridge in 2013 by mathematicians and cyber experts with backgrounds in government intelligence agencies, was acquired by private equity firm, Thoma Bravo, in October 2024 in an all-cash deal valued at approximately US$5.3 billion. It now operates as a Thoma Bravo portfolio company, with more than 2,400 employees and nearly 10,000 customers across major industries globally.
The convergence challenge
The assessment covers both Darktrace’s network and OT security platforms, reflecting the growing convergence of IT and operational technology environments across government and critical infrastructure.
As agencies adopt cloud services, connected operational technology, automation and AI across sensitive environments, the boundary between traditional IT networks and industrial control systems has blurred. This convergence creates new attack surfaces that security teams must manage, often across environments where legacy OT systems were never designed with cybersecurity in mind.
Darktrace / OT is designed to provide visibility across industrial control systems, SCADA environments, IoT and converged IT/OT networks. The platform uses passive network monitoring to identify assets and detect anomalies without disrupting operational processes – a critical requirement in environments where availability and safety take precedence over traditional IT security priorities.
The vendor’s own 2026 Annual Threat Report identified three trends shaping risk across critical national infrastructure: an intensification of attacks targeting national services linked to geopolitical conflict, an expansion of strategic access and pre-positioning by state-aligned groups beyond traditional espionage objectives and the growing use of AI by threat actors to accelerate and scale their operations.
The broader IRAP landscape
Darktrace is not the first cybersecurity vendor to pursue IRAP assessment at PROTECTED level. Other vendors including BeyondTrust, CyberArk, Skyhigh Security and F5 have completed similar assessments for their respective platforms, reflecting the growing demand from Australian government agencies for independently assessed security products.
The trend reflects a broader push by the Australian Government to ensure that the technologies it deploys across sensitive environments meet the standards set out in the ISM. Under the Security of Critical Infrastructure Act (SOCI Act), critical infrastructure entities face additional governance and reporting obligations, with IRAP assessments providing evidence that supports compliance with many of the required controls.
For Darktrace, the assessment opens up the Australian government and defence market for its network detection and OT security capabilities, complementing its existing commercial customer base. The company’s focus on on-premises, cloud-independent deployment aligns with the data sovereignty requirements that are increasingly central to government procurement decisions in Australia and across the Five Eyes alliance.
Last Updated on August 13, 2026 by Nick Ross



