What is DISP, and does your business need it to work with Defence?
DISP, the Defence Industry Security Program, is Defence's way of vetting the businesses in its supply chain. If you want defence work, directly or as a subcontractor, membership is increasingly the ticket to the table. It requires demonstrated security across governance, personnel, physical and cyber domains, and the cyber domain is where most businesses have the furthest to travel.
For South Australian businesses the question is not academic. Defence work runs through this state, from shipbuilding at Osborne to the manufacturers, engineers and logistics operators who supply the primes, and every prime is obliged to care about the security of its suppliers. Demanding standards in a supply chain work as market access: they separate the businesses that can bid from the businesses that cannot. DISP is exactly that kind of barrier, which means it is also exactly that kind of advantage. The barrier reads as cost until you are inside it, at which point it reads as a shortlist your competitors are not on. And because the requirements are published, the advantage is available to any business willing to start the work early.
What membership involves, in outline: DISP assesses a business across four security domains. Governance means someone accountable, with documented security practices rather than good intentions. Personnel security means knowing who you employ, with clearances where required. Physical security covers premises and the handling of protected material. And ICT and cyber security means demonstrating that your systems meet the standard Defence expects, with evidence, not assurances. Requirements vary by membership level, and Defence's current documentation is always the authority; treat any article, including this one, as orientation rather than gospel. The levels scale with the sensitivity of the work: the higher the classification of the information and assets involved, the more each domain must demonstrate.
The cyber domain is where most small and mid-sized suppliers start, for two reasons. It is usually the largest gap between current state and required state, and it is the most buyable: the backbone is the Essential Eight, implemented to a demonstrated maturity level with evidence an assessor can inspect. That work is a known quantity, it is what our managed plans deliver by tier, and unlike the paperwork domains it keeps paying for itself whether or not a tender ever lands. The same evidence also survives due diligence from every other direction, because banks, insurers and large private customers now ask strikingly similar questions.
It is not hypothetical. Energy Logistix runs 24/7 freight operations for mining, energy and defence customers, the kind of business where a security question from a customer is really a continuity question. Getting there meant one hundred per cent Essential Eight Maturity Level 1 across the business, SD-WAN connecting five sites, and 99.99 per cent uptime on AWS, and it culminated in DISP accreditation. The sequence is the lesson: the cyber foundation came first, and the accreditation stood on it. None of that was done for a certificate; the certificate recognised what the business had become.
Does your business need it? If defence work, direct or flowed down from a prime, is in your plans, then practically yes, and the time to start is before the tender rather than during it, because the evidence-gathering is the long part. If defence work is not in your future, you do not need DISP, and nobody should sell it to you; but note that the cyber uplift that anchors it, Essential Eight at a demonstrated maturity level, is worth having for its own sake, and leaves the door open. A sensible middle path exists: build the cyber maturity now, and make the membership decision when the first real tender appears.
Where we fit, stated plainly: we are DISP aligned ourselves, and we build and evidence the ICT and cyber domain, the controls, the maturity, the documentation an assessor wants. The governance and personnel domains are decisions only your business can make, with your own advisers; a provider who claims to deliver your entire DISP application is overreaching. What we can promise is that the cyber pillar arrives assessable.
If defence work is on your horizon, the free Essential Eight Cyber Security Scorecard will show you the size of the cyber gap before anyone writes an application, or call us on 1800 456 567.
Size the cyber gap before the tender
The cyber domain is the long part of a DISP application. The free Essential Eight Cyber Security Scorecard shows you where you stand before anyone writes a word.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business