IN Brief:
- Secure State Consultants and Safran have signed an agreement covering Australian cyber security and secure ICT capability.
- Work includes infrastructure supporting sensitive and classified information used by Safran’s local engineering and operational teams.
- The partnership links Safran with a South Australian cyber specialist that is owned by First Nations people.
Secure State Consultants will support Safran in strengthening cyber security around its Australian defence and engineering operations under an agreement covering secure ICT environments and infrastructure for sensitive and classified information. The work is intended to combine the controls required for defence information with the computing and collaboration capabilities Safran’s local engineers need to perform design, integration and support activity.
By signing the memorandum of understanding with Safran during Land Forces 2026 in Perth, Secure State Consultants is bringing its cyber and managed IT experience into an environment where conventional corporate security has to coexist with engineering systems and defence requirements.
Because engineers may need specialist software, large technical data sets and controlled collaboration with teams elsewhere in the world, securing that environment is more complicated than applying a standard office configuration. Restricting access too aggressively can obstruct legitimate work, while insufficient separation can expose sensitive material, so identity, data movement and network architecture have to be designed around the engineering process itself.
Safran’s activities across aircraft propulsion, navigation, surveillance and other aerospace and defence technologies make that balance especially demanding because technical documentation and development tools have to remain available to approved users while sensitive information stays inside the boundaries imposed by customers, contracts and government.
Identity controls determine who can reach individual systems, while network segmentation can limit movement between different environments and encryption protects information in storage and transmission. Monitoring then provides evidence of abnormal activity, but those controls still have to reflect the behaviour of engineering systems rather than assume every device can be treated like a conventional corporate computer.
Operational technology and specialist equipment make that constraint more pronounced because some devices use fixed software versions, unusual communications protocols or hardware unable to run standard security tools. Protecting those systems may therefore rely on compensating controls around the device as well as controls installed directly on it.
Those controls also have to remain usable through normal engineering change because software versions, connected equipment and project teams do not remain static for the life of a programme. Access rights need to change as staff move between tasks, new devices have to be assessed before they join secure networks and configuration records have to show which controls applied when a particular system was used.
Secure State and Safran have not identified the individual systems, classifications or network configurations involved, so those details cannot be inferred from the agreement. What is established is the need to support sensitive and classified activity while tailoring the environment to Safran’s Australian engineering requirements.
Secure State brings experience across managed IT, penetration testing, governance, risk and compliance and cyber security consulting, operating from the Tonsley Innovation District in Adelaide and working with defence and critical infrastructure organisations. Its ownership by First Nations people also adds a South Australian supplier to work that could determine how much sensitive engineering activity can be supported locally.
The Australian Government awarded Secure State A$100,000 in January to improve cyber controls against Defence security requirements, and applying that capability within Safran creates an additional integration problem because local environments have to operate alongside the systems and standards of a multinational aerospace group rather than inside a completely separate network.
International collaboration consequently makes data movement one of the most sensitive aspects of the design. Australian engineers may need to work with overseas teams while technical information remains subject to contractual, national security or export control restrictions, so the system has to permit authorised collaboration without allowing uncontrolled copying or transfer.
Monitoring has to account for the same engineering context because large technical files, remote access, specialist protocols and unusual software can produce traffic patterns unlike ordinary office use. Security tools configured without understanding those workflows can either miss genuine threats or generate enough false alerts to weaken the usefulness of the monitoring itself.
Auditability sits alongside detection because a secure engineering environment also needs records showing who accessed sensitive systems, when changes were made and how information moved between approved locations. Those records support investigation and compliance work while giving administrators a way to confirm that access and configuration controls continue to operate as intended.
Because no contract value, implementation timetable or individual Safran programme has been disclosed, the scope of the eventual deployment remains open. Its practical effect will depend on whether the resulting infrastructure allows more sensitive engineering, integration and support work to be conducted in Australia while still satisfying the security controls attached to defence information.


