Daniel Hood

Director (Security Engineering)
Daniel brings deep security architecture and CISO experience across Government, Critical Infrastructure and Financial Services, having led strategy, risk and compliance outcomes for organisations transacting billions of dollars annually.
Talk to an expert
Highlights

Career highlights

Architect for a three-year project to improve cybersecurity capabilities for the governments of five Pacific Island Nations. As part of the project, created an Enterprise Security Architecture that identified capabilities (People, processes, technology) for the governments’ CERT teams, including a threat intelligence and centralised log management platform.

Developed and implemented a three-year cyber security strategy for an Australian critical infrastructure provider. The strategy included assisting the organisation with meeting their obligations under the SOCI act, treating high priority risks that were being actively abused by threat actors and was aligned to the business and technology strategies.  

Provided security architecture and advisory support to a project building a financial market for an Australian critical infrastructure industry. The platform was used to transact over $5b in transactions annually. The project included performing risk assessments of processes and technology (for example, Azure infrastructure, serverless architecture and DevOps processes), along with developing blueprints, security patterns and designing new security controls.

Acted as the interim CISO for one of Australia’s largest payment gateways for 18 months. This included managing the existing team that had only recently joined the organisation, passing multiple ISO27001 and PCI-DSS audits, and eventually leading the process to identify a replacement.

Cyber security news

Latest advisories

Stay ahead of emerging threats with our expert blog posts, research, and industry updates.
Silverstripe - Host Header Injection
Silverstripe CMS is affected by a Host Header Injection flaw, which can be exploited to manipulate password reset workflows, potentially redirecting or compromising user data.
FarCry Core Framework - Multiple Issues
FarCry Core contains multiple vulnerabilities that could let unauthenticated users upload arbitrary files and execute remote code on the hosting server.
Silverstripe – Cross-Site Scripting (XSS) Vulnerability
With local organisation admin credentials, an attacker can exploit the API to create, delete, or revert virtual machine snapshots in other organisations’ Virtual Data Centres (VDCs), breaching isolation boundaries.
Discover our services

We have the tools to pinpoint risks

Whether it’s hidden vulnerabilities or patterns you might miss, we help you stay one step ahead and make confident, informed decisions. Understand how our services can help your business uncover critical risks

Talk to an expert
Employee Cyber Training & Awareness
Your people are your first line of defence. Our cyber training builds awareness sharpens instincts and turns everyday staff into assets.
Advisory
When clarity is critical and stakes are high, our advisory services deliver strategic, executive-level security expertise that empowers decision-making and resilient operations.