Downer Group is one of the largest integrated infrastructure services providers across Australia and New Zealand, with a workforce exceeding 26,000 people. The company operates in sectors where cyber-physical risk is concrete: rail signaling, water treatment, energy networks, airport operations, defence contracts, ports, and telecommunications infrastructure. That's the threat model - operational technology environments running alongside traditional IT, managing systems where a compromise doesn't just mean data loss, it means physical disruption to essential services.
The company's verticals span critical domains including defence, marine and ports, roads and bridges, and industrial resources. These are environments where ICS/SCADA security isn't theoretical, and where network segmentation, endpoint hardening, and incident response need to account for legacy protocols, remote assets, and safety-critical constraints. Securing a portfolio this broad means building capability across converged IT-OT environments at scale.
For cybersecurity practitioners, Downer presents a specific kind of challenge: protecting infrastructure that communities depend on daily, across jurisdictions with distinct regulatory frameworks. The company emphasizes structured governance and positions its workforce as central to its operations - a signal that security here is as much about process, policy, and cross-functional coordination as it is about tooling. This is infrastructure-grade cybersecurity, not perimeter defense for a SaaS shop.






