Downer invests in security as contracts increasingly demand it
Downer Group is seeing specific cyber security requirements in tenders it bids for, leading it to invest in software to more tightly control application use and manage privileged access.
Image credit: Downer Group.
Head of security engineering and platforms Aidan Turner told the Gartner’s IT Symposium/Xpo that the company had invested in ThreatLocker endpoint security this year, following a proof of concept in 2025.
“There wasn’t any crazy incident that drove this adoption,” Turner said.
“For us, it’s just [about] compliance for our contracts and for risk with our local admin use cases.”
As an engineering contractor, Downer participates in both requests for information (RFIs) and tenders.
Turner said that meeting cyber security requirements is increasingly a requirement to bid for work.
“Five to10 years ago, our customers and our contracts didn’t even mention zero trust or cyber security. A couple of weeks ago, I had one of our commercial people reach out and say, ‘We do zero trust, right?’ I had to pinch myself and say, ‘I’m sorry, who taught you that word?’” Turner said.
“The point now is that the people who are winning and responding to RFIs in the business are now seeing this in customer sheets that have come through in the bids, so it forms a big part of our tender process and identifying where we can meet the needs of our customers and our regulators.”
Case in point, the investment in ThreatLocker was partially to meet the requirements of a new contract that Downer landed at the beginning of 2026.
Turner said that the contract included strict “maturity level two requirements” under the Essential Eight that necessitated the investment in application control.
As new personnel were onboarded and provisioned applications to work on the new contract, Turner said that ThreatLocker ensured they started work with all of the necessary security controls in place.
Aside from meeting requirements in contracts and work being bid for, the tool is also used to manage privileged access and reduce local administrator permissions across the company.
“I joined Downer five years ago when I was leading the identity practice, and I just didn’t like local admins – we had over 1000 at the time,” Turner said.
“Now we’re well under 100, since the introduction of ThreatLocker, in particular.”
The previous number of users with administrative rights was tied to the industrial lines of work that Downer is involved in.
“Our company does a lot of work with operational technology – a lot of proprietary, very old software and hardware,” Turner said.
“Often, when you have to interface with those bits of equipment, you need to have local admin on your device, [and] you need to have proprietary software on your device that you can’t control or you can’t touch.
“When it comes to giving those people full control over their device, that’s very uncomfortable but it’s something we had to live with.”
The company now uses an ‘elevation control’ module within ThreatLocker to manage this.
According to ThreatLocker, it “allows standard users to run specific applications with local admin privileges without ever having that unnecessary privilege as a user.”
This, Turner said, gave Downer “the opportunity to remove those local admin privileges” while still ensuring that users interacting with operational technology systems “are still able to do what they need to do.”
“When it came to what that meant for the individual user, of course, there were some arguments and butting of heads, but at the end of the day, risk always wins,” he said.
Aside from drastically reducing the number of users with administrative access rights, Downer has also been able to keep this number down.
For new requests placed by users, “rather than just assigning [privileged access] because people think they need it, there’s a proper analysis” of the requirement, Turner said.
Turner said that for every 50 people that request privileged access, “only one ends up getting it”, with the others either “rejected outright” or triggering the creation and implementation of “a ThreatLocker policy … to remove the need for standing local administrative privilege.”
“That is a transformation,” Turner said.
