Airlock Digital Passes Australia's Toughest Government Security Check

The Australian application control firm has cleared an independent IRAP assessment at PROTECTED level, giving government and critical-infrastructure buyers one more piece of evidence for their due-diligence files.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Airlock Digital completed an IRAP (Information Security Registered Assessors Program) assessment at the PROTECTED classification level, the rating used for sensitive Australian Government data.
  • The assessment was conducted against the Australian Government Information Security Manual by an assessor endorsed by the Australian Signals Directorate, the country's national cyber spy agency.
  • The result is relevant to Australian government agencies, defence contractors and critical-infrastructure operators that must verify the security of every tool in their stack.
  • Airlock Digital's software controls which programs are allowed to run on an organisation's computers, blocking everything else by default.

What did Airlock Digital actually pass?

IRAP, which stands for Information Security Registered Assessors Program, is Australia's formal process for checking whether a technology product meets the security standards the government sets for handling sensitive information. An independent assessor, approved by the Australian Signals Directorate, reviewed Airlock Digital's controls and found they hold up at the PROTECTED level. PROTECTED is the classification below TOP SECRET, covering data whose release could cause serious damage to national interests.

In practice, clearing that bar means a government agency or a defence supplier can point to the assessment when their own security team asks whether the tool has been independently checked. That matters because vendor self-assessment, no matter how thorough, is not the same as a stranger with a checklist going through your controls.

Why does this matter to anyone outside Canberra?

For ordinary Australians, the ripple is indirect but real. The organisations most likely to use Airlock Digital's software include hospitals, energy providers, financial institutions and local councils, all of which handle personal data at scale.

Application control, the technology Airlock Digital sells, works by maintaining a list of approved programs and refusing to run anything that is not on it. Think of it as a nightclub bouncer who checks every piece of software against a guest list before letting it execute. Ransomware, which is malicious software that locks an organisation's files until a payment is made, almost always depends on running an unapproved program. A strict allowlist can stop that before it starts.

The Essential Eight, a set of baseline security controls published by the Australian Signals Directorate that the government recommends all organisations follow, places application control at the top of its list. The IRAP result gives buyers evidence that Airlock Digital's approach aligns with those expectations.

What should customers and staff take away?

If your employer uses Airlock Digital or is considering it, the IRAP assessment is background assurance, not a guarantee that nothing will go wrong. The failure mode here is complacency: teams see a compliance certificate and assume the hard work is done. Allowlisting still needs someone to maintain the approved list, review exceptions and catch the edge cases where a legitimate program gets blocked.

For individuals, the practical message is simpler. Organisations that invest in this kind of layered, preventative security are less likely to end up in a breach notification. That is the whole point of blocking software before it runs rather than hunting for it after the damage is done.

One thing the post-mortem will never say: "We had application control running and the ransomware executed anyway." The model works when it is maintained.

Operational takeaway: An IRAP certificate is a starting point for due diligence, not the end of it. Ask your vendor what the assessment scope actually covered.

© 2026 Threat Vectr