About

Intelligence discipline, applied to cyber.

RIPOSTE brings adversary-informed, intelligence-led cyber-risk capability to those responsible for many organisations — regulators and peak bodies, insurers and large enterprises, and their supply chains — and to each organisation defending its own. Its mission is to help them get left of the bang: to anticipate and mitigate cyber risk before it materialises.

Leadership · Australia
CMPhoto

Cameron McCollum

Director & Founder · RIPOSTE AU

Two decades in the Australian Army, where Cameron served as an intelligence officer and rose to the rank of Major; he continues to serve as an officer in the Army Reserve. He was the Head of Intelligence on multiple operations across the Asia-Pacific, Afghanistan and domestically — directing the intelligence effort, leading multinational teams and delivering intelligence that shaped high-level decision-making. It is where the analytical discipline, investigative rigour and crisis leadership that define his approach to cyber risk were formed.

Moving to the private sector in 2018, he brought that tradecraft to cyber risk. At Lexon Insurance he built and led the company's cyber-risk program — developing it from concept to operations in a matter of months, and reducing cyber-related losses across the insured portfolio to a fraction of pre-program levels.

In 2022 he founded RIPOSTE to deliver that capability more broadly: intelligence-grade assessment and threat-and-risk intelligence across whole portfolios, memberships and supply chains, and authorised, hands-on assessment for the single organisation — for those accountable for cyber risk at scale.

Master of Cyber Security Operations (UNSW)Master of Business (UNSW)ISO/IEC 27001 Lead ImplementerGraduate, Royal Military College Duntroon
Mission & values

Why RIPOSTE exists.

RIPOSTE began in 2022 with a focused brief: to bring genuine cyber-security expertise to the organisations that most needed it and could least reach it — Australian law firms and small and medium businesses, where confidentiality is everything and a breach can be existential. The work was proactive rather than reactive: get ahead of the threat, not clean up after it.

What began there grew into something larger, carried by a single conviction — that high-end, intelligence-grade cyber-risk capability should not be the preserve of governments and the largest enterprises. That conviction carried RIPOSTE beyond the single firm to those responsible for many organisations at once — regulators and peak bodies, insurers and large enterprises — assessing the portfolios, memberships and supply chains they are accountable for. The mission held constant throughout — to help organisations get left of the bang, anticipating and mitigating cyber risk before it materialises — and so did the resolve to make that capability genuinely accessible, from one business to ten thousand.

How we work is as deliberate as what we deliver. We are intelligence-led and always human — AI works at machine scale, but an analyst judges every finding. We keep security proportionate to the threat, scaled to the adversary that would realistically target you. We are honest to a fault — coverage and limits stated, likelihood calibrated, never over-claimed. And we equip rather than take over: we reveal the pathways an adversary could use and give you what you need to close them — a partnership, not a report over the fence.

Our systems

Why we build our own systems.

We build our own tools because excellence demanded it. RIPOSTE's tooling began in frustration — with the noise and false positives of even the best off-the-shelf tooling, and the realisation that delivering what organisations genuinely need takes more than running someone else's scanner over them. Holding to that standard meant designing and innovating our own methods and instruments — and, in doing so, turning intelligence tradecraft into an algorithm: high-quality, repeatable and scalable, without losing the human judgement that makes it intelligence.

Most consultancies resell someone else's scanner and someone else's report. RIPOSTE builds its own — ForgeScore for portfolio risk, the DarkSuite for hands-on assessment of a single organisation, and DarkRose, the threat-and-risk intelligence fusion behind them all — spanning external posture assessment, attack-surface discovery, governed offensive testing and the fusion of live threat activity with real vulnerability. A judgement is only as good as the information and the method beneath it, and we will not stake our name on a black box we did not build.

That is the promise: Human-AI fusion — AI at scale, human judgement where it counts; information in, assessment out, read from the attacker's side, and delivered as a partnership rather than a report over the fence.

Work with us.

Whether you carry a portfolio of cyber risk or a single organisation's, the conversation starts the same way.

Start the conversation