Obsidian Security, a leading SaaS security provider, has announced the successful completion of the Infosec Registered Assessors Program (IRAP) Assessment for its Australian sovereign instance of its SaaS Security Platform. The assessment was conducted by Australian cybersecurity experts at Securus Consulting Group.

IRAP, developed by the Australian Signals Directorate, provides independent evaluations of system security controls. Australian federal agencies rely on IRAP outcomes to determine whether a system meets their security requirements. By achieving IRAP certification, Obsidian Security gives public sector organizations increased confidence in deploying its platform to safeguard their SaaS identities, applications, and data.

Cyber Technology Insights : Bonfy.AI Boosts Microsoft 365 Security with Advanced AI-Powered Next-Gen DLP Solutions

As SaaS adoption continues to accelerate across both public and private sectors, these applications have become a primary target for cyberattacks. Obsidian Security enables Australian government agencies to implement comprehensive security strategies across their SaaS environments, covering configuration, identity protection, threat detection, and response. This is particularly timely as SaaS-related breaches have increased by 300% year over year, with identity-based attacks emerging as the most common tactic.

Obsidian has strong local connections through its Australian co-founder, Glenn Chisholm, as well as its long-standing ASX-listed customers. “The widespread use of SaaS applications creates numerous blind spots for security teams, particularly regarding identity management,” Chisholm said. “Cyber adversaries are increasingly exploiting these gaps. IRAP certification ensures we can defend government agencies against these sophisticated threats, just as we do for Australia’s largest telecommunications, banking, and healthcare organizations.”

Cyber Technology Insights : GreyNoise Intelligence Launches MCP Server to Power the Future of Agentic SOC

Chisholm further highlighted that many organizations place implicit trust in SaaS providers to configure applications securely, which can leave sensitive data exposed. “While SaaS providers maintain the security of their application infrastructure, users are responsible for implementing proper protections around human and non-human identities, such as multi-factor authentication and privilege controls,” he said. “Often, these applications are deployed outside the oversight of internal security teams. Obsidian provides a single platform that offers full visibility, control, and enforcement across an organization’s SaaS ecosystem.”

Cyber Technology Insights : CrowdStrike Delivers Unified Data Protection for the AI Era

To participate in our interviews, please write to our CyberTech Media Room at sudipto@intentamplify.com