Est. 2013 · Australia

Designing, building, operating, and securing internet-facing and cloud-native systems for mission-critical sectors — government, finance, and beyond.

0
Years in Operation
0
Client Engagements
0
Core Frameworks
0
Uptime SLA
ZOAK + OSM Banner
Who We Are

Hands-on. Partner-focused. Long-term oriented.

ZOAK Pty Ltd (trading as ZOAK Solutions) is an Australian company operating since 2013, delivering secure, scalable, and resilient solutions to mission-critical sectors.

We serve Australian Government departments, internet regulators, ASX-listed firms, and global technology vendors — with deep specialisation in Information Security Management and compliance engineering.

  • Reducing operational overheads through automation and reusable frameworks
  • Bridging strategic objectives with operational execution
  • Security-first design, not security-as-an-afterthought
  • Supporting clients through every phase: design → build → secure → operate

Our Story

The ZOAK Journey

Since 2013, ZOAK Solutions has designed, built, operated, and secured mission-critical internet and cloud systems for government, regulators, and security-sensitive organisations. Our history is grounded in deep operational experience from Australia’s internet infrastructure sector and shaped by a practical belief: technology should be secure, resilient, fit for purpose, and aligned to real business outcomes.

ZOAK was originally formed as the consulting arm of AusRegistry Group to bring to market the expertise developed while building and operating large-scale registry and internet-facing systems, including the .au domain name registry. Over time, the business evolved into a specialist provider of cyber security services, cloud services, managed technology services, custom software development, CISO as a Service, and outsourced application hosting.

Today, ZOAK remains focused on securing and operating critical systems to demanding standards, including ISO 27001 and the Australian Government ASD Information Security Manual. Our approach is hands-on, agile, and outcome-driven — combining strategic guidance with engineering depth and operational accountability.

Since 2013

ZOAK Solutions has been operating since 2013, building on deep experience in designing, delivering, operating, and securing essential Australian digital infrastructure.

Mission Critical Systems

Our heritage includes work on the .au domain name registry, secure government platforms, and other high-availability services where resilience, integrity, and continuity are fundamental.

Security First

Security has always been central to how we work, shaping our approach across cyber security, cloud, managed services, and application delivery for regulated and security-sensitive clients.

Track Record

We bring a proven track record of supporting organisations that depend on strong governance, secure architecture, disciplined operations, and long-term technology partnerships.

What defines ZOAK

  • Deep experience in mission-critical internet and cloud systems
  • Strong alignment to ISO 27001 and ASD ISM security practices
  • Practical, fit-for-purpose engineering without unnecessary complexity
  • Ability to bridge strategy, compliance, engineering, and operations
  • Long-term partnerships with government, regulators, and technology-led organisations

Selected experience

Australian Communications and Media Authority (ACMA)

ZOAK designs, builds, operates, and secures the Numbering Management system that supports Australia’s telephone numbering framework. The platform enables allocation and management of telephone number blocks and smart numbers, maintains numbering registers, and supports regulated transaction processing in a high-assurance Commonwealth environment.

Connexion Mobility Ltd

ZOAK provides strategic and hands-on cyber security services to Connexion, combining outsourced security leadership with technical implementation. This work includes ISMS governance, audit and certification support, risk management, security operations, endpoint and control uplift, and broader security improvement activities for an ASX-listed technology business.

auDA and .au ecosystem experience

ZOAK has delivered advisory, monitoring, cloud, and security services in support of the .au domain name ecosystem, including registry transition support, DNS and DNSSEC-related advisory work, secure data environments, compliance uplift, and independent monitoring capabilities.

Whole-of-government DNS and other critical services

Across government and regulated sectors, ZOAK has contributed to secure DNS, operational resilience, cloud hosting, and cyber security outcomes where uptime, control assurance, and evidence-based governance are essential.

Tenders won

ZOAK has a strong record of winning and delivering public sector tenders involving regulated platforms, critical digital infrastructure, software delivery, cyber security, cloud operations, and managed services. These engagements reflect our ability to compete successfully for complex government work and then sustain those services over the long term.

Australian Communications and Media Authority (ACMA) Provision of Numbering Services · Open tender · 2014 – current

ZOAK won the tender to provide Australia’s Numbering Services capability for the Australian Communications and Media Authority. This remains one of ZOAK’s most significant and enduring government engagements.

  • Service: Provision of Numbering Services
  • Procurement method: Open tender
  • Initial start: 11 September 2014
  • Current published end date: 2 August 2027
  • Published contract value: AUD 14,075,880.30
  • Agency reference: CON/ACMA/14ACMA277/2

The engagement covers the design, build, operation, support, and ongoing governance of a regulator-grade numbering services platform used by ACMA to administer Australia’s telephone numbering framework. The service includes public-facing and carrier-facing systems, numbering registers, charge-processing support, reporting, security, governance, and operational continuity.

This work demonstrates ZOAK’s ability to deliver and sustain a high-assurance Commonwealth service involving statutory processes, public registers, transaction workflows, records management, privacy, security, and long-term operational support.

Clean Energy Regulator Renewable Energy Certificate (REC) Registry Rebuild, Hosting · Open tender · 2012 – 2017

ZOAK won and delivered the Renewable Energy Certificate Registry rebuild and hosting engagement for the Clean Energy Regulator. This was a major government platform delivery and operational services contract in a highly regulated environment.

  • Service: Renewable Energy Certificate (REC) Registry Rebuild, Hosting
  • Procurement method: Open tender
  • Initial start: 1 July 2012
  • Published end date: 31 May 2017
  • Published contract value: AUD 14,812,614.27
  • Agency reference: STD-000768-0
  • ATM reference: ORER 011/2012

The platform supported the allocation, management, and trading of renewable energy certificates in a government setting that required secure operation, strong transactional integrity, and reliable long-term service delivery.

This engagement is a strong example of ZOAK’s capability to deliver large, complex, business-critical digital systems where the platform itself is central to regulatory administration and market operations.

Department of Finance Digital services · Open tender · 2021 – 2023

ZOAK won a digital services engagement with the Department of Finance, providing software support and related digital delivery services in a Commonwealth environment.

  • Service: Digital services
  • Procurement method: Open tender
  • Initial start: 1 October 2021
  • Published end date: 3 July 2023
  • Published contract value: AUD 3,974,778.85
  • Agency reference: 4400051434
  • ATM reference: DTA-487 V4

This engagement reflects ZOAK’s capability to provide dependable digital service delivery in government contexts where supportability, responsiveness, and structured service management are essential.

Digital Transformation Agency (DTA) Domain Name Administration Portal · Open tender · 2019 – 2021

ZOAK won the tender to deliver the Domain Name Administration Portal for the Digital Transformation Agency, supporting secure Australian Government domain name administration workflows.

  • Service: Domain Name Administration Portal
  • Procurement method: Open tender
  • Initial start: 4 November 2019
  • Published end date: 3 October 2021
  • Published contract value: AUD 2,681,652.64
  • Agency reference: DTA-GEN-265
  • SON reference: SON3413842

This engagement demonstrates ZOAK’s ability to deliver secure digital platforms tied to government identity, naming, operational governance, and service continuity.

Digital Transformation Agency (DTA) Australian Government domain name management — security and software advice · Open tender · 2018 – 2019

ZOAK was engaged by the Digital Transformation Agency to provide security and software advice relating to Australian Government domain name management.

  • Service: Australian Government domain name management – security and software advice
  • Procurement method: Open tender
  • Initial start: 15 October 2018
  • Published end date: 18 March 2019
  • Published contract value: AUD 68,255.00
  • Agency reference: DTA-GEN-158
  • SON reference: SON3413842

Although smaller in value, this engagement is relevant because it highlights ZOAK’s recognised expertise in secure domain name administration, internet infrastructure, and advisory work in government settings.

Digital Transformation Agency (DTA) GovDNS architecture and viability advice · Open tender · 2019

ZOAK was engaged to provide advice on the potential architecture and viability of GovDNS, contributing specialist expertise in DNS, security, and government digital service design.

  • Service: Advice in relation to the potential architecture and viability of GovDNS
  • Procurement method: Open tender
  • Initial start: 14 June 2019
  • Published end date: 28 June 2019
  • Published contract value: AUD 16,610.00
  • Agency reference: DTA-GEN-243
  • SON reference: SON3413842

This engagement reinforces ZOAK’s long-standing specialisation in DNS, naming systems, internet infrastructure, and the secure operation of nationally significant digital services.

How we work

We believe strong outcomes come from combining technical depth with clear accountability. That means using lightweight and agile delivery methods where appropriate, maintaining disciplined risk and security practices, and staying close to client objectives from design through to operations.

ZOAK’s history is not defined by a single product or market. It is defined by repeatedly solving difficult technology, security, and operational problems for organisations that cannot afford failure.

What We Do

Our Capabilities

From compliance engineering to cloud-native infrastructure — we cover the full stack.

Security Engineering

Design and implementation of robust security controls across cloud-native and internet-facing systems. Threat modelling, secure architecture review, and penetration testing.

Zero Trust Threat Modelling Pen Testing

Compliance & GRC

ISO/IEC 27001:2022, ASD ISM, Essential Eight, SOC 2, and OSCAL-aligned compliance engineering. Automated SoA generation and gap analysis tooling.

ISO 27001 ASD ISM Essential 8 SOC 2

DevSecOps Pipelines

Secure CI/CD pipeline design and implementation. Branch protection, CodeQL scanning, signed commits, and secrets management built into every workflow.

GitHub Actions CodeQL Signed Commits

Infrastructure-as-Code

Provider optiomized IaaS for AWS / Azure / Google / Microsoft 365 / CloudFlare, Hardened baselines, PowerShell / Bash / Go / Python automation and integration into GRCosm [Governance, Risk and Compliance].

AWS Microsoft 365 + Azure CloudFlare Google

Organisational Service Management

Machine+LLM-readable definitions and relationships for assets, risks, treatments, controls, policies, and audits. Graph-based OSM schema with validation and data hygene for people and bots 🤖.

osm.dev JSON Schema GRCosm

ISMS & Audit Automation

ISMS artefact management, control evidence tracking, automated Statement of Applicability generation, and audit-ready reporting pipelines integrated with Atlassian and GitHub.

ISMS SoA Australian Signals Directorate - Information Security Manaul
Open Source

Public Repositories

Selected tooling and frameworks published from ZOAK Solutions, Organisation Service Management, and markz0r on GitHub.

Loading repositories…

Tools & Info

ZOAK Live

ZOAK HQ — Melbourne
--:--:--
Loading…
Australia/Melbourne (AEST/AEDT)
Platform Status
99.999%
↑ All Systems Operational
Last 90 days · No incidents recorded
GitHub Pages API Services osm.dev
Security Tip
Tip 1 of 8
Loading tip…
OSM Schema — osm.dev

Machine-readable organisational management schemas. Click any entity to explore.

Risks Assets Controls Treatments Policies Objectives Third-Parties Audits
Explore osm.dev →
Technology Stack
Handy Tools

Client-side Utility Bench

Run lightweight, browser-based checks to inspect domains, headers, and performance without leaving the page.

Whois · RDAP
Enter a domain to query RDAP records.
Powered by rdap.org.
DNS Dumpr
Resolve records via DNS-over-HTTPS.
Uses dns.google/resolve.
Tracepath
Run a quick network trace summary.
Queries Google DNS trace endpoints.
Mailheader Parser
Parsed headers will appear here.
Speedtestr
Estimate download speed from this page.
Local-only fetch test.
Aim Trainer

Tap each target before it vanishes — every hit speeds things up.

Score: 0 · Level 1 · Best 0
Click start to begin.
Get in Touch

Let's Build Something Secure

Whether you need a security review, compliance roadmap, or cloud-native build partner — ZOAK Solutions has the experience to deliver.

ZOAK Pty Ltd · ABN/ACN: 68 161 531 880
Australian Registered Company · Operating since 2013