DOW   |   A

Location
Sector

Over the past year, Downer has strengthened cyber security by simplifying core technology foundations, uplifting workforce awareness, and modernising key security capabilities.

 This work has focused on reducing complexity, improving governance, and creating a more sustainable digital environment that can respond to evolving threats while supporting safe, reliable service delivery.  

Cyber has become more than a technical function, it is a strategic enabler of trust, resilience and responsible growth. By improving how people, platforms and controls work together, the organisation is building a stronger long-term foundation for digital operations, customer confidence and licence to operate.

Challenge

As the technology environment became more complex, inconsistent controls, fragmented business processes and varied maturity across platforms increased operational overhead and cyber risk. Internal review highlighted the need to simplify the technology landscape, strengthen governance, improve accountability, and manage cyber risk as a business risk rather than an IT issue alone.

At the same time, the external threat landscape continued to evolve, including phishing, identity-based attacks and growing concern around emerging AI-enabled risks. This required a more sustainable approach that combined technology uplift with practical workforce capability and clearer governance across the organisation.

Solution

Downer responded with a coordinated uplift across people, platforms and controls. Cyber awareness pathways were expanded through mandatory induction, quarterly hot-topic learning, phishing simulations and more targeted behavioural reporting. Learning was moved to a central platform with real-time reporting, phishing activity was integrated with workforce data to support continuous campaigns and richer insights, and a dedicated cyber awareness site was launched to provide practical guidance and employee Q&A, including guidance on safe AI use.

In parallel, identity and access management and the broader technology environment were simplified and standardised to reduce duplication, strengthen access controls and improve resilience. Security tooling and services were also further integrated to improve detection, response, information protection and governance, while maturity continued to progress against recognised frameworks such as the Essential Eight and ISO 27001.

Outcomes

This work has delivered stronger governance, lower complexity and a more sustainable long-term cyber capability. Awareness reporting now goes beyond completion rates to include behavioural indicators such as open, click and reporting patterns, helping focus effort on higher-risk cohorts rather than relying on lag indicators alone. The uplift also improved operational efficiency by reducing manual administration and providing more timely visibility of user risk and learning outcomes.

The awareness program’s average completion rate across induction and hot-topic campaigns is above targets, while reporting and phishing analysis now provide a clearer view of where risk is concentrated and where tailored interventions are needed. This strengthens resilience by improving employee behaviour, supporting more consistent controls, and enabling earlier action in response to emerging risks.

More broadly, the organisation now has a clearer foundation for secure digital transformation: simplified technology, more consistent controls, stronger accountability, and improved readiness for future challenges such as AI-enabled threats and a rapidly changing risk environment.

Discover more View all

Go to Top