T
Lumara in Action
Protecting $2B of Investor Trust at Income Asset Management
At Income Asset Management (ASX: IAM), trust is the product. For one of Australia's specialist fixed income houses, with more than 14 years in the market and over $2 billion in assets under administration, that means a cloud estate that needs eyes on it around the clock. IAM gives wholesale investors, advisers, government organisations, NFPs, and custodians direct access to bonds, syndicated loans, and managed discretionary accounts, and we're proud to be the team watching.
IAM runs a deliberately lean and senior internal technology team across a cloud-native AWS and Azure estate, supported by a strong managed service provider for day-to-day IT. When Nick May stepped into the CTO role, his first move was a full review of IAM's cybersecurity posture. AFSL obligations and cyber insurance renewals both required credible evidence of active monitoring and response, and there was no realistic path to a 24/7 in-house SOC. IAM came to Secure ISS for a dedicated security operations layer that would work alongside their MSP rather than over the top of it.
Inside the partnership
How Secure ISS designed and now runs 24/7 managed detection and response from our sovereign Australian SOC, with Lumara SecOps Cloud ingesting firewall and cloud telemetry from IAM's AWS and Azure estate and SentinelOne XDR running on every endpoint.
The joint MSP-SOC response model we co-designed with IAM and their MSP: shared severity matrix, agreed communications, and ownership locked in before something happens rather than negotiated mid-incident.
The governance rhythm we run for the board: monthly posture reviews that feed directly into board-ready reporting, sized CVE advisories scoped to what the team can act on, quarterly awareness training, and realistic phishing simulations.
How the joint response model held up when a live security event tested it in production: every party stayed calm, worked the agreed severity matrix, and brought it to a clean resolution.
The shift shows up inside IAM as well. Staff now flag suspicious activity in real time, often before alerting picks it up. AFSL cyber attestations are straightforward to evidence when regulators or auditors come asking, and cyber insurance renewals run cleanly end to end. In Nick's words, the result is "green ticks through the thing all the way to board approval."
"When the board asks me how I know our environment is secure, I can now point to a pattern of evidence rather than an opinion. That is the shift Secure ISS has made, and for a regulated fintech it changes what my job actually looks like."
Nick May, Chief Technology Officer, Income Asset Management
The full case study covers how the joint MSP-SOC model holds up day to day, what monthly posture reviews look like when they reach the board, how IAM's security culture has matured around continuous monitoring, and where the partnership is heading next across syndicated loans, managed discretionary accounts, and AI governance.
Read the full story: Protecting $2B of Investor Trust at Income Asset Management

