GuardWare partner

GuardWare. Control your data, wherever it goes.

GuardWare binds encryption and usage policy to the data itself, so you can grant, limit or revoke access at any time and prove it. Vectra helps defence, utilities and critical infrastructure deploy it and lift Essential Eight maturity.

Protection that travels with the file.

GuardWare is a data-centric security platform. It finds and labels critical and regulated data across IT and OT, tracks how it moves inside the business and out to suppliers, and keeps it protected at rest, in transit and in use.

Teams can grant, limit or revoke access on demand, automate hardened baselines and produce tamper-evident evidence for audits and board reports. You keep provable control of key data, even outside your network.

  • Discover and classify

    Finds sensitive data in M365 and SharePoint, file shares, CAD/PLM, email and OT paths - automatically.

  • Persistent protection

    Encryption and usage policy go with the file, at rest, in transit and in use.

  • Control beyond your perimeter

    Share safely with suppliers and contractors, and revoke access at any time, with watermark, no-copy and no-print options.

  • Prove compliance

    Tamper-evident logs, drift detection and ready evidence for audits and board reports.

  • Hardened by design

    Supports Essential Eight uplift and configuration control to cut insider, ransomware and supply chain risk.

Four modules, one data-centric platform.

Visibility

GuardWare Discover

Finds sensitive data wherever it lives, fingerprints it and maps who can reach it and how it moves. The result is a clear exposure picture and a ranked hardening plan.

  • Auto-discovery and fingerprinting of crown-jewel data
  • Classification and labels such as PROTECTED or CONTROLLED
  • Exposure mapping of locations, permissions, shares and USB or cloud egress
  • Baseline reports, drift alerts and board-ready metrics
Rapid assessment

GuardWare Assessor

Measures how well you protect sensitive data today and what to fix first, benchmarked against the Essential Eight and your own policies.

  • Audit of encryption, sharing, DLP/IRM and endpoint controls
  • Review of access, data flows and risky egress
  • Maturity scores against the Essential Eight
  • Ranked fix plan with owners and dates
Live telemetry

GuardWare Insight

Tracks how sensitive files are accessed and moved, flags unusual behaviour and policy drift, and shows it in clear dashboards and alerts.

  • Real-time activity monitoring, including suppliers
  • Anomaly and drift detection
  • Events sent to Devo, Google SecOps or Microsoft, SOAR playbooks and ServiceNow or Jira tickets
  • Tamper-evident timelines and executive reports
Enforcement

GuardWare Protect

Binds encryption and usage policy to the data, so control stays with you wherever the file goes.

  • View-only, watermark and no copy, print or save-as
  • Offline grace, geo and time limits, and a kill-switch revoke
  • Control on unmanaged devices and third-party portals
  • Audit trails, key escrow and rotation, and Essential Eight policy templates

Developed with Australia’s defence ecosystem to protect official-sensitive data across the supply chain.

GuardWare is built to protect data end to end across primes, subcontractors and contractors. Through Defence Trailblazer, it works with UNSW to build sovereign capability. Recent Defence Trailblazer news highlights PROTECT’s data-in-use encryption and remote revoke, which keep designs and mission data under control, even off-network.

How Vectra delivers GuardWare.

We design and run rapid pilots, set up policy, harden configuration and deliver production deployments, with ongoing tuning and licensing support.

We track success with clear measures: fewer uncontrolled shares and copies, time to revoke, policy coverage and drift findings closed - mapped to the ASD Essential Eight and your governance goals.

  1. 01

    Pilot

    We start in monitor-only mode and use Discover and Assessor to baseline your exposure.

  2. 02

    Integrate

    We send Insight events to your SIEM and SOAR.

  3. 03

    Enforce

    We phase in Protect policy, from warn to enforce, where it won’t block the work.

  4. 04

    Tune

    We keep tuning policy and support your licensing.

Related Vectra services.

ASD Essential Eight

GuardWare supports Essential Eight uplift with measurable coverage and audit-ready evidence.

Data Loss Prevention

GuardWare adds protection that stays with the file after it leaves.

SIEM & Log Management

Stream GuardWare Insight events into your SIEM and SOAR.

Critical Infrastructure

Protect sensitive designs and data across critical infrastructure supply chains.

GuardWare questions.

How is GuardWare different from DLP or M365’s own controls?

DLP stops certain movements, but once a file leaves, control is mostly gone. GuardWare binds encryption and usage policy to the file, so you can enforce view-only, watermark, no copy or print, expiry or revoke, even off-network and on supplier devices. It adds to M365/IRM and CASB rather than replacing them.

Will this slow people down or break collaboration?

No. We start in monitor-only mode to map behaviour, then phase in policy where it won’t block the work. GuardWare works with M365 and SharePoint, file shares, email, CAD/PLM and common OT hand-offs, so teams keep their tools.

Does it work with suppliers, BYOD and offline use?

Yes. Controls travel with the file, not the network. You can set geo and time limits and offline grace windows, and revoke access at once if risk changes. Tamper-evident logs show who opened what, where and when.

How do encryption keys and data residency work?

GuardWare supports customer-managed keys in your own KMS or HSM, with separation of duties, or hosted key escrow in the region you choose. Keys can be rotated, revoked and audited. Telemetry is kept to what assurance needs, with in-region processing options for defence and critical infrastructure.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.