A spinout from the University of Wollongong’s cyber safety program has begun selling vendor-risk scores tailored to council ERP migrations, with Wollongong City Council as the first customer as it extends its TechnologyOne OneCouncil SaaS contract.

What the product measures

The startup ingests vendor questionnaires, IRAP and ISO attestations, penetration-test summaries, and contract clauses, then outputs a weighted score aligned with NSW Office of Local Government cyber guidelines for third-party providers. Dashboards highlight gaps such as missing breach-notification timelines, absent break clauses, or patch SLAs slower than Digital NSW detailed requirements.

For ERP moves, the model adds modules specific to finance, assets, and rates data—datasets Wollongong migrated over multi-year phases with DataMC and TechnologyOne Ci Anywhere. Scores refresh when vendors publish new SOC reports or when council change boards approve integration plugins.

Why Wollongong piloted first

Council papers extending the OneCouncil agreement through 2032 cite six years of implementation sunk cost and strategic partnership with TechnologyOne across more than 180 local government tenants. Risk assessments from the original 2018 business case flagged sole-supplier dependence and SaaS data custody—issues the spinout now tracks continuously instead of during procurement events only.

Wollongong’s cloud-first program finished major Ci Anywhere rollouts during the pandemic, improving mobile workflows for assets and customer service. IT management redesigned around service delivery, but vendor assurance remained spreadsheet-heavy until the UOW lab commercialised its supply-chain monitoring research.

University lineage and council fit

UOW’s cyber safety office already tells staff to embed security requirements in third-party contracts and report supply-chain concerns to the central security team. The spinout founders participated in ISMS governance documentation covering vendor definitions and geopolitical procurement risks.

OLG’s 2026 local-government cyber guidelines expect inventories of ICT providers, incident-notification clauses, and monitoring through audits or assurance reports—exactly the artifacts the scoring engine parses. Councils without large security teams can use the scores in risk registers presented to audit committees.

Limits and competition

TechnologyOne markets its own SaaS+ security program, including IRAP assessments to PROTECTED and regular penetration tests. The spinout does not replace vendor attestations; it compares them against council policy thresholds and flags when insurance or data-sovereignty terms drift.

Other NSW councils on competing ERP suites could license the tool if they map control frameworks to the same OLG foundational requirements. The startup declined to name pipeline customers but said Illawarra neighbours asked for demos after Wollongong’s audit committee briefing.

Commercial terms and roadmap

Pricing is subscription-based per vendor with discounts for whole-of-council portfolios. Integrations export PDF summaries suitable for ordinary council meeting attachments, mirroring how Wollongong documented its contract extension.

Roadmap items include automated feeds from TechnologyOne release notes to patch-risk modules, addressing guideline expectations that critical vulnerabilities receive mitigations within 48 hours when exploits exist. For Wollongong, the near-term win is fewer surprises when integrators request new OAuth scopes during ERP optimisation work.

State associations said they will watch whether scored councils negotiate stronger break clauses in legacy SaaS deals that predate OLG’s 2026 guidance.

The founders pledged to keep intellectual property developed with public research open for academic audit, while commercial scores remain licensed to paying councils.

If the Wollongong deployment stabilises by year-end, the company plans a NSW Local Government conference launch targeting risk officers who currently rely on annual spreadsheet reviews.

Council auditors requested read-only access to historical score trends so they can test whether integration projects introduced new subprocessors without procurement review.

TechnologyOne said it will cooperate with customer-led assurance tools that consume public attestations, but warned councils not to treat third-party scores as substitutes for vendor penetration-test letters referenced in SaaS+ security documentation.

Wollongong’s information management unit plans to link vendor scores to its change-advisory board tickets, so ERP configuration requests from business units automatically surface overdue assurance documents before approvers sign off.

The spinout raised a seed round from Illawarra angel investors and UOW’s commercialisation fund, with board seats held by former council CIOs who managed the original OneCouncil procurement documented in 2018 council papers.