Defy IT Director & Principal Consultant

Cybersecurity · Digital forensics · Managed IT · Brisbane

Brandon
Strangman

Security work that has to hold up later — to an auditor, an insurer, or a court.

Brandon Strangman
Brisbane, QLD
Experience
19 years
Role
Managing Director, Defy IT
Also
Founder & CEO, Cyber Guys
Managed estate
500+ user seats
01

Profile

I'm the Managing Director of Defy IT, a Brisbane managed IT services and cybersecurity business supporting more than 500 user seats across legal, medical, accounting, professional services and trades. I'm also the founder of Cyber Guys, which handles the human side of security risk.

I treat the whole client base as a single risk portfolio rather than a set of unrelated businesses — comparing exposure across identities, devices and organisations, and directing effort at the most vulnerable environments first. Essential Eight maturity is mapped across the entire managed estate, so control gaps and remediation progress stay visible.

My background is a Master of Cyber Studies and Investigations sitting on top of a criminology, history and education degree. That combination shapes how I work: evidence first, documented as it goes, written so it survives scrutiny from someone who wasn't in the room.

Nearly two decades of frontline technical work sits underneath the executive side. I can talk to a board about risk exposure and investment priorities, and I can also tell you why the backup didn't restore.

02

What I do

Open a heading for the detail.

Security assessment & advisory
  • Microsoft Secure Score baseline assessment, remediation planning and staged uplift
  • ACSC Essential Eight maturity assessment and gap analysis
  • Security posture reviews for regulated and professional-services environments
  • Risk registers, remediation roadmaps and milestone-based uplift quoting
  • Third-party and vendor risk assessment
  • Vulnerability disclosure and vendor security escalation on behalf of clients
  • Cyber insurance questionnaire support and evidence preparation
  • Pre-acquisition and due diligence IT and security review
Digital forensics & investigations
  • Forensic acquisition and evidence handling aligned to ISO/IEC 27037
  • Chain of custody procedure design and execution
  • Email and account compromise investigation across Microsoft 365 and Entra ID
  • Insider threat, employee misconduct and IP exfiltration investigations
  • Endpoint and log timeline reconstruction
  • eDiscovery support and evidence production for legal matters
  • Forensic reporting written for a legal audience
  • Incident response planning, playbooks and tabletop exercises
Managed IT services
  • Contracted managed services under defined SLAs, per-user or per-device
  • Service desk, escalation and on-site attendance across South East Queensland
  • 24/7 monitoring across servers, endpoints and network infrastructure
  • Patch management and third-party application updating under enforced policy
  • Managed endpoint protection and EDR with alert triage and response
  • Managed email security, filtering and continuity
  • Asset, warranty and lifecycle management with planned refresh budgeting
  • Vendor, telco and line-of-business application liaison
  • Co-managed arrangements supporting internal IT staff rather than replacing them
Microsoft 365 & identity
  • Tenant design, migration and consolidation
  • Entra ID configuration, conditional access, MFA enforcement and legacy auth removal
  • Licensing review and optimisation
  • Intune device enrolment, compliance policy and application deployment
  • Defender for Office 365 and Defender for Endpoint configuration
  • SharePoint and OneDrive structure, permissions and data governance
  • Exchange Online mail flow, transport rules, DKIM/DMARC/SPF
  • Retention, litigation hold and audit log configuration
Infrastructure & networks
  • Windows Server design, build and migration, including Server 2025
  • Active Directory design, cleanup, migration and hybrid join
  • Terminal Server and RDS environments with secured remote access
  • Firewall, VLAN and network segmentation design
  • Site-to-site and remote access VPN (WireGuard, IPsec)
  • Wireless design, structured cabling and site fitout coordination
  • IDS/IPS alert triage and threat management tuning
  • Linux server builds and hardening; AWS and cloud-hosted workloads
  • Cloudflare DNS, proxy, WAF and tunnel configuration
Backup, continuity & recovery
  • Backup architecture across endpoint, server and Microsoft 365 workloads
  • Hosted and on-premises backup appliance deployment
  • Immutable and offsite retention strategy
  • Restore testing, documented recovery procedures and RTO/RPO definition
  • Business continuity and disaster recovery planning
Governance, policy & documentation
  • SOP libraries across service delivery, security, sales and HR
  • Information security policy sets, acceptable use and access control
  • Incident response plans and notifiable data breach procedures
  • Statements of work, service agreements, schedules and fee structures
  • Technical reporting written for non-technical executive audiences
  • Client-facing manuals, quick reference guides and training material
Regulatory & legal-adjacent
  • Privacy Act 1988 and Notifiable Data Breaches scheme obligations
  • Australian Consumer Law and the TCP Code as applied to IT and telco delivery
  • Spam Act 2003 compliance and response
  • Contract review support and demand correspondence in technology disputes
  • Technical explanation for legal and dispute contexts
03

Cyber Guys

My own security awareness program, built and delivered in-house. It covers the layer technical controls can't reach — staff behaviour. Most SME compromises start with a person, not a system, and structured training is increasingly a condition of cyber insurance rather than a nice-to-have.

  • Monthly modulesShort awareness modules delivered to staff, with completion tracked and reported.
  • Phishing simulationCampaigns reporting click rates, credential submission and repeat-risk users.
  • Annual seminarA live session on current threats specific to the client's sector.
  • Lunch and learnsMonthly sessions for teams who want a discussion rather than a course.
  • Role-targeted contentExtra material for finance, executive and client-facing staff exposed to invoice fraud and business email compromise.
  • Evidence for insurersReporting that stands up when an insurer, auditor or regulator asks what training was in place.

In developmentA guided security compliance platform that gives executives and IT staff one shared, plain-language view of where the organisation actually stands — closing the gap between technical detail and board-level accountability.

04

Selected work

Legal

Security posture assessment and Secure Score remediation for a Brisbane law firm — licensing uplift, managed endpoint protection and a staged roadmap delivered under ongoing management.

Healthcare

Security assessment and vendor vulnerability disclosure for a veterinary practice covering third-party API exposure in a clinical booking platform, plus risk and liability disclosure work for a medical practice.

Professional services

Design and deployment of a hosted AML compliance portal — Linux, reverse proxy, CDN and WAF, managed under RMM, with multi-site expansion planned.

Multi-site SMB

Network and server overhaul: Windows Server 2025, terminal services behind VPN, hosted backup appliance, and transition into ongoing managed support.

Ongoing

Contracted IT management across roughly 40 client environments — service desk, monitoring, patching, endpoint security, backup and vendor management.

05

Qualifications

In progress · exp. Jul 2027

Graduate Diploma in Information Technology — Artificial Intelligence

Queensland University of Technology

2019

Master of Cyber Studies and Investigations

Charles Sturt University

2018–2019

Graduate Certificate in Cyber Security

Charles Sturt University

2018

Bachelor of Arts — History, Criminology and Education

The University of Queensland

2018

Diploma of Arts — International and Global Studies

University of Southern Queensland

06

Career

2023 – now

Managing Director, Defy IT — Strategic, commercial and operational direction of an Australian managed IT, cybersecurity and technology advisory business. CIO-style advice to directors on security, infrastructure investment, cloud adoption, licensing and continuity. Leads technical staff and sets documentation and delivery standards.

2022 – now

Founder & CEO, Cyber Guys — A cybersecurity business built around SME needs: awareness programs, phishing simulation and practical process improvement, alongside assessments covering infrastructure, cloud platforms, access controls, endpoints and backups.

2008 – 2022

Senior Systems Technician & Administration Officer, Netech — Fifteen years spanning frontline and escalated support, systems administration, infrastructure planning, cybersecurity, digital forensics and data recovery, across metropolitan, remote and international environments.

2012 – 2013

Senior Sales & Customer Service Agent, Careers Australia — Led a sales and service team, coaching staff on customer engagement and performance while managing escalated matters.

Let's talk about the actual problem.

Whether it's a breach you're already in, a security posture you can't evidence, or an environment nobody has documented in years — get in touch and we'll work out whether I'm the right fit. Contact me for pricing and engagement options.

Email Brandon Call Defy IT