About
Our Foundation and History
Founded on a commitment to quality and professionalism, CREST ANZ was created to address gaps in cybersecurity accreditation and certification. Our journey is rooted in values, expertise, and a drive for continuous improvement.
Origins
Founded in 2012, thanks to a generous one-off grant from Australia’s Attorney General’s Department, CREST ANZ is the original and pioneering cyber security membership organisation for Australia and New Zealand
As cyber threats became increasingly sophisticated, industry leaders, government stakeholders, and CREST ANZ representatives recognised the need for a trusted, independent body to assess and certify cybersecurity providers and professionals across Australasia.
Through a combination of technical rigour, ethics enforcement, and collaborative engagement with regulators and industry, CREST ANZ grew to become a recognised sovereign voice for assurance in cybersecurity. Since our inception, we have grown into a benchmark organisation for cyber security accreditation and training across Australia and New Zealand, aligning regional standards with global best practices.

CREST ANZ is Australia’s sovereign, not-for-profit cyber security accreditation body. It was established in partnership with the Australian Government and industry specifically to develop and operate Australian cyber security assurance schemes that align with Australia’s regulatory, legal and sovereign requirements. Our governance, assessment processes and technical standards are independently managed within Australia and are publicly available through our website.
2012 – CREST Australia established with Australian Government support
CREST ANZ traces its Australian origins to 2012, during the Government of Prime Minister Julia Gillard. CREST (Aust) Limited was registered as an Australian not-for-profit public company limited by guarantee on 15 February 2012, with its establishment supported by a one-off $150,000 grant from the Commonwealth Attorney-General’s Department. The organisation’s ABN became active on 1 May 2012. (ABN Lookup)
Then Attorney-General Nicola Roxon publicly announced the Australian Government’s support for the new organisation in March 2012. The Government’s objective was to strengthen confidence, professionalism and standards within Australia’s cyber security testing industry by establishing clear and agreed standards for security testing. Roxon said these standards would give businesses greater confidence that security testing was being undertaken with integrity, accountability and to agreed standards. The Government also committed its agencies to working cooperatively with CREST Australia, including participation alongside industry representatives on CREST sub-committees. (iTnews)
Former Australian Federal Police Australian High Tech Crime Centre Director Alastair MacGibbon was appointed CREST Australia’s founding CEO. The original seven-member Board brought together senior cyber security expertise from government and industry and comprised MacGibbon; Nigel Phair; Richard Byfield of Datacom; Glenn Chisholm of Telstra; Graham Ingram of AusCERT; Tim Scully of StratSec; and Wade Alcorn of NGS Secure Asia Pacific. Contemporary reporting described the organisation as affiliated with the established UK CREST model while creating an Australian capability suited to the needs of Australian government, critical infrastructure and major businesses. (iTnews)
New Zealand origins and the evolution to CREST ANZ
New Zealand’s involvement also had early roots. A CREST New Zealand working group had emerged from a taskforce established in late 2010 and included representatives from the Bank of New Zealand, Kiwibank, New Zealand Department of Internal Affairs, National Cyber Security Centre, Insomnia Security and Lateral Security. Contemporary reporting indicates that the New Zealand initiative was deliberately buyer-led, with significant participation from organisations purchasing penetration testing services as well as industry providers. (iTnews)
The Australian organisation subsequently expanded its formal remit across both countries. On 18 January 2016, CREST (Aust) Limited changed its registered company name to CREST Australia New Zealand Ltd, formally reflecting the organisation’s Australia and New Zealand role. (Aubiz)
2016 – Australian Government backs the expansion of CREST ANZ
Rather than establishing CREST ANZ, the Australian Government’s 2016 Cyber Security Strategy recognised the already-established organisation as an important component of Australia’s cyber security capability and committed to supporting its further expansion. Action 16 of the Strategy was specifically to “Support the Council of Registered Ethical Security Testers (CREST) Australia New Zealand to expand its range of cyber security services”, including growing the pool of CREST ANZ accredited companies to meet increasing business demand. (Parliament of Australia)
This commitment subsequently translated into substantial Commonwealth investment. In June 2017, the Australian Government provided CREST ANZ with $2.2 million in grant funding for the “Expansion of CREST ANZ Cyber Security Services and Capability for Small Business”, with the funded programme running from 23 June 2017 to 30 November 2020. (Industry.gov.au)
The chronology is therefore important: CREST ANZ was not created by the 2016 Cyber Security Strategy. Its Australian organisation was established in 2012 under Prime Minister Julia Gillard, with direct Commonwealth support through the Attorney-General’s Department and an initial $150,000 grant. The 2016 Strategy, under Prime Minister Malcolm Turnbull, represented a significant subsequent endorsement of CREST ANZ’s role and provided the policy foundation for expanding its services, reach and contribution to Australia’s cyber security ecosystem.




