Overview
Updated Jun 27, 2026
Australian sovereign SOCaaS and MDR from Macquarie Government, built for Commonwealth and state government agencies that need onshore 24x7 monitoring by NV1-cleared specialists. The service overlays MDR and XDR specialists across agency workstations, infrastructure, networks, cloud and gateways, with Splunk-based SIEMaaS, cyber threat intelligence, SASE integration, customized playbooks and incident management. Public pages publish strong government-sovereignty and monitoring detail, but not prices, contractual MTTD/MTTR, service-credit SLAs or the exact default response authority for every customer environment.
Buyer fit
Good fit when
- ✓Australian Commonwealth and state agencies that require sovereign onshore SOCaaS and MDR
- ✓Government teams that want Splunk-based SIEMaaS, SASE and secure gateway operations from one provider
- ✓Agencies prioritizing NV1-cleared local analysts, Essential 8 alignment and Australian government threat intelligence
Watch out when
- ×Private-sector or non-Australian buyers that do not need a government-specific sovereign provider
- ×Organizations that require public MDR pricing or contractual MTTD/MTTR before engaging sales
- ×Teams that want a pure endpoint MDR package without SIEM, SASE, gateway or sovereign hosting dependencies
Coverage
3 of 6 attack surfaces in the base price; the rest are separately priced.
EDR
SIEM
Cloud
Additional capabilities
Incident response
Pricing
Custom government subscription and procurement model.
How pricing works+−
SOCaaS, SIEMaaS and SASE pricing is not published.
Not published
Cost caveats
- –The service is explicitly built for Australian Commonwealth and state government agencies, so private-sector and non-Australian buyers may not be eligible or may not fit the operating model.
- –Public pages do not publish prices, minimum terms, MTTD/MTTR, service credits or formal MDR SLAs.
- –SOCaaS is closely tied to Macquarie Government SIEMaaS, Splunk, sovereign hosting, SASE and gateway services; model migration work if replacing the service later.
2 more+−
- –Buyers should document which automated response actions are allowed by default and which require agency approval.
- –Log retention, ingestion, secure cloud, SASE and CTI options can materially change the total contract scope.
What costs extra (5)+−
- –SIEM ingestion and Splunk billing depend on log volume and optimization scope
- –SASE, SIGNET, secure web gateway, ZTNA, CASB and Virtual Services Gateway are adjacent services that may be quoted separately
- –Cyber Threat Intelligence, premium CTI, dark web monitoring and breached-credential monitoring may be separate scope
- –Long-term SIEM retention and data export terms require contract review
- –Incident response retainers, hands-on remediation and customer-environment containment authority require confirmation
Warranty conditions+−
No public breach warranty found for Macquarie Government SOCaaS or MDR.
Team and access
Certifications
Reputation
Macquarie Government has strong vendor-controlled evidence for Australian government sovereignty, 24x7 SOC operations, SIEMaaS, threat intelligence and SASE integration, but little independent MDR-specific buyer-review signal in public communities. Government buyers should use procurement references to validate analyst quality, response authority, onboarding effort and Splunk/log-volume cost exposure.
What customers praise
- ✓Clear Australian sovereign delivery and government specialization
- ✓24x7 local SOC staffed by NV1-cleared specialists
- ✓Broad adjacent stack across SIEMaaS, CTI, SASE, secure gateway and secure cloud
Common complaints
- ×No public pricing or formal MDR response SLA
- ×Response authority and hands-on remediation scope require contract confirmation
- ×Limited independent MDR-specific review signal
No meaningful Reddit signal found for Macquarie Government SOCaaS or MDR specifically.
Questions to ask
- 1.
Is our agency eligible for SOCaaS, SIEMaaS, SASE and CTI services, and which procurement vehicles apply?
- 2.
Which logs, endpoints, cloud accounts, gateways and SIEM sources are included in the base SOCaaS scope?
- 3.
Which response actions can Macquarie Government execute directly, and which require agency approval?
- 4.
What contractual SLA applies to high-severity triage, notification, containment and escalation?
- 5.
How is Splunk ingestion priced and optimized, and what retention is included by default?
- 6.
Which playbooks are included at onboarding, and how often are they reviewed with our security team?
- 7.
What CTI sources and customer-specific advisories are included versus premium add-ons?
- 8.
What dashboards, reports, raw logs, detections, playbooks and SIEM data can we export during offboarding?
Evidence
Sources reviewed
Main public source used for the provider profile.
Official SOC page used to verify 24x7 Australian SOC positioning, risk-based alerting, AI, automated response, guided remediation, threat hunting, log ingestion optimization, reporting and customer logo context.
Official cyber security page used to verify MDR/XDR language, 24x7 SOC monitoring, over 3,000 playbooks, false-positive triage, 270+ government-cleared staff, 42% Commonwealth Government language and related services.
Official SIEMaaS page used to verify Splunk Enterprise, sovereign local hosting, advanced threat detection, anomaly correlation, dashboards, forensics, automated blocking language and up-to-seven-year event storage language.
Official CTI page used to verify Australian government-only focus, dark web and forum hunting, 250B monthly government event logs, AGSVA-cleared analysts, IPS-block mitigation examples, sovereign delivery, ASX-listed language and DISP/Strategic data-centre claims.
Official SASE page used to verify SASE for government positioning, Essential 8 Maturity Level 2 language, Protected-level security operations, MDR for SASE, NV1-cleared SOC operation and customized playbooks.
Official VSG page used to verify AWS and Azure context, IRAP standards language, SOC monitoring, managed SIEM dashboards, firewall, IPS, WAF, load balancing and related 24x7 threat detection and remediation support language.
Official homepage used to verify sovereign Australian government positioning, 90+ SOCs, 30 years of experience language, 270+ cleared engineers, secure data centres and the official logo asset.
Public-data caveats
- –No public contractual response-time SLA is recorded for this profile.
- –No public fixed price is recorded; compare only after a scoped quote.
- –No public breach warranty is recorded.
- –Response authority may depend on pre-approval and contract scope.
- –MDR analyst headcount or analyst-to-customer ratio is not public.
Also consider
Further reading
Independent research. Verify details directly with the provider before making decisions.
