Australia – LevelBlue has opened a new Security Operations Centre (SOC) in Sydney, backing the facility with a multi-million-dollar investment aimed at strengthening cyber resilience across Australia’s critical infrastructure sector.
The managed security services provider, which describes itself as the world’s largest independent pure-play MSSP, said the Sydney SOC would give Australian organisations access to onshore analysts, local escalation pathways and specialist knowledge of the country’s regulatory environment.
That local presence will be backed by LevelBlue’s global security operations, which run around the clock and draw on worldwide threat intelligence.
The launch comes as Australian critical infrastructure operators face mounting pressure to manage cyber risk under the Security of Critical Infrastructure Act 2018 (SOCI Act).
Applicable entities may be required to report critical cyber incidents within 12 hours, while other cyber incidents must be reported within 72 hours.
Certain organisations covered by the Act must also adopt, maintain and comply with a written Critical Infrastructure Risk Management Program.
Alongside these regulatory obligations, businesses have been seeking greater access to local expertise, clearer escalation routes and security support aligned with Australian operating hours.
LevelBlue said its Sydney SOC was designed to meet that demand by pairing onshore analysts and market knowledge with the scale of its global operations.
In turn, the company said this model would help critical infrastructure organisations bolster their cyber resilience while supporting broader SOCI and Essential Eight initiatives.
“Australian organisations want a security partner that understands the local regulatory environment and can quickly escalate when an incident occurs”, said Jo Salisbury, Regional Director Growth & Performance – APAC, LevelBlue.
“Geopolitical tensions are intensifying the threat landscape, and our Sydney SOC gives Australian organisations access to local analysts and context, together with global threat intelligence and 24/7 coverage that critical infrastructure operators need to manage risk, support their SOCI obligations, and strengthen cyber resilience”, Salisbury added.
The new facility also extends LevelBlue’s security operations footprint within the Five Eyes intelligence-sharing region.
As a result, the company said it would be better placed to deliver locally based services informed by global threat intelligence, telemetry and expertise.
“This investment reflects LevelBlue’s commitment to the Australian market and the critical infrastructure sector”, said Allison Clelan, Senior Vice President, Managed Global Security Solutions, LevelBlue.
“As a vendor-agnostic MSSP, we bring local delivery and global scale together to help clients strengthen resilience while retaining greater choice and flexibility across their security environments”, Clelan continued.
According to LevelBlue, the Sydney SOC will provide Australia-based operations staffed by local analysts, alongside seamless 24/7 coverage through the company’s global SOC network.
It will also offer local contacts and clearly defined escalation pathways, together with threat intelligence applied by both local and global security teams.
Beyond this, the facility is intended to provide broader threat visibility drawn from LevelBlue’s global telemetry, as well as vendor-agnostic managed security services for critical infrastructure, state and local government, regulated enterprises and mid-market organisations.
Melbourne Airport has become the first organisation to transition to the new Australian SOC.
“As a LevelBlue customer for six years, we have consistently valued the strength and reliability of our partnership. We are proud to be the first organisation to transition to LevelBlue’s Australian SOC, giving us greater access to local expertise and escalation backed by LevelBlue’s global intelligence and expertise,” said Anthony Tomai, Melbourne Airport Chief Information Officer.
“For Melbourne Airport, this local capability strengthens our ability to manage cyber risk and support our obligations under the Security of Critical Infrastructure Act. It is exactly the kind of investment Australian critical infrastructure needs from a trusted security partner”, he further expressed.
Under the SOCI Act, applicable critical infrastructure entities are required to embed risk management, preparedness and resilience into their operations.
LevelBlue said it supports these efforts through continuous monitoring, local escalation, threat intelligence and incident response capabilities.
The company added that it can also help organisations strengthen their Essential Eight maturity as part of a wider cyber resilience strategy, noting that the Essential Eight complements, rather than replaces, an organisation’s SOCI obligations.

