Open-plan Australian office with a person working at a desk
About

A security practice built for Australian Defence suppliers.

We help organisations win and hold the right to supply to Australian Defence, from first DISP certification to ongoing compliance.

A SecureSupply adviser and client working through security requirements together.
The practice

Our mission is to protect the Defence Industrial Base.

SecureSupply helps small and medium enterprises participate in the Defence supply chain. We also help international firms, already certified to NIST or CMMC in the United States, become DISP members so they can supply to Australia.

The security expected of Defence suppliers keeps rising. We exist to carry that load: to assess accurately, advise plainly, and keep organisations compliant in a way that is sensible and cost-effective.

The team

Experience you can put in front of Defence.

Deepayan Chanda

Deepayan Chanda

Executive Security Advisor

MBA (IT) GCIA CHFI CEH PGP-AIML AdvDipSoftEng DipMechEng

Deepayan Chanda is an Executive Security Advisor with over 28 years’ experience in cyber security strategy, enterprise architecture and governance.

Deepayan advises across all four Defence Industry Security Program (DISP) security domains—governance, personnel, physical and Information and Communications Technology (ICT)/cyber security—aligning members with the Defence Security Principles Framework (DSPF), Protective Security Policy Framework (PSPF) and Information Security Manual (ISM). He guides organisations through DISP entry-level assessment, security officer appointments, including Chief Security Officer (CSO) and Security Officer (SO) roles, and the controls needed to meet ongoing obligations and complete the Annual Security Report.

With a proven record of building Secure-by-Design architectures, Security Operations Centres (SOCs), threat and vulnerability management functions and maturity-assessment frameworks, he helps members progress from initial readiness to membership-ready, audit-ready security postures—reducing risk while keeping business and Defence contract requirements firmly in balance.

An armed forces veteran, Deepayan combines a disciplined Defence background with commercial experience gained across organisations including National Australia Bank, Standard Chartered Bank, Microsoft, Cisco and the New South Wales Government in Australia and across Asia.

Daryl Hartwell

Daryl Hartwell

Defence Industry Adviser

MBA GradCertCyberSec PMP ITIL v3

Daryl Hartwell is a Defence Industry Adviser with experience in project and program management, management control assurance, enterprise systems and cyber security. He helps organisations establish themselves within the Defence supply chain and integrate Defence Industry Security Program (DISP) obligations into project, sustainment and operational delivery.

Daryl has led acquisition and sustainment management control assurance reviews across Maritime, Air Force and Joint Systems Division environments, including assurance programs supporting major acquisition projects such as SEA 5000, the Hunter Class Frigate Program. He has also worked with Defence Major Service Providers (MSPs) and advised Land equipment System Program Offices on asset management, performance measurement and operational decision-making.

His approach aligns security, governance and project delivery with recognised standards and frameworks, including the International Organization for Standardization (ISO) and the Project Management Body of Knowledge (PMBOK). Earlier leadership roles with global Enterprise Resource Planning providers gave him extensive advisory experience in manufacturing, asset management and supply-chain systems across Australia and New Zealand.

Daryl Hartwell and Deepayan Chanda of SecureSupply at the Hunter Defence Conference, Rydges Resort Hunter Valley, August 2026.
In the Defence community

Close to the industry we advise.

Daryl Hartwell and Deepayan Chanda at the Hunter Defence Conference, held at Rydges Resort Hunter Valley. Hunter Defence connects government, Defence primes and small and medium suppliers across the Hunter region of New South Wales.

Staying close to industry is how advice stays current. Security requirements move, and what a prime asks of its supply chain this year is rarely what it asked last year.

How we work

Scoped, substantiated, and sensible.

Fully scoped and substantiated

We scope every engagement clearly and substantiate the cost, so it holds up in your bidding and estimation.

Economical by design

We help you meet Maturity Level 2 in a minimum-viable way, so you invest wisely rather than over-build.

Senior expertise and service

A team of experts committed to your success, with a real commitment to service throughout.

From readiness to beyond

We stay with you from first certification through ongoing membership, so nothing falls between providers.

Why SecureSupply

Why organisations select SecureSupply.

Executive and technical capability in one team

We work with directors and senior executives on business risk, governance and investment decisions, while also engaging with internal IT teams, cyber security specialists and managed service providers on the underlying controls.

Advice grounded in operating reality

We do not begin with templates. We examine how the organisation actually works, where Defence information may be handled, who is accountable, which systems and facilities are involved, and what evidence is available.

Experience in complex and regulated environments

Our experience spans Defence, government, financial services and supply chain focused technology organisations. These environments require disciplined governance, defensible evidence, clear accountability and security controls that can withstand scrutiny.

Practical support for SMEs

We recognise that SMEs do not have unlimited personnel, time or budget. Our approach is proportionate and prioritised. We help clients focus first on the requirements that present the greatest risk to DISP readiness and Defence opportunity.

Clear communication for decision-makers

DISP requirements can quickly become technical and difficult to navigate. We translate them into clear business decisions, accountabilities, risks and actions so executives understand what is required and why.

Support beyond the DISP application

Our focus is not simply to help complete an application. We help clients establish security arrangements that can be operated, evidenced and maintained after DISP membership is achieved. We then work with you to maintain membership for the longer term.

A more complete approach

Defence assurance and deep cyber security capability, together.

SecureSupply combines Defence assurance experience with deep cyber security capability. This allows us to help clients connect:

  • Defence opportunity with security requirements
  • Executive accountability with operational responsibility
  • Cyber controls with credible evidence
  • Policies with actual business practice
  • DISP application activity with ongoing compliance
Precision CNC machining of a metal component in an advanced-manufacturing workshop.
Frameworks we work across

The standards that govern Defence-industry security.

  • Defence Industry Security Program (DISP)
  • Essential Eight Maturity Level 2
  • Protective Security Policy Framework (PSPF)
  • Information Security Manual (ISM)
  • Infosec Registered Assessors Program (IRAP)
  • NIST and CMMC, for international suppliers crossing to Australia
Speak with us

Discuss your DISP, IRAP or security obligations.

We move from first conversation to active engagement in two to three weeks.