About ThreatCanary

Built by people who have attacked systems, secured public platforms and scaled enterprise technology.

ThreatCanary exists because attackers do not work from disconnected scanner queues. They follow relationships across exposed assets, APIs, identities and trust boundaries. We built one governed system that can do the same—and prove every conclusion with evidence.

What this covers

Security products should earn trust with evidence—not adjectives.

ThreatCanary was shaped by three disciplines that rarely meet in one product team: offensive research, high-assurance security engineering and enterprise technology delivery.

01

The problem we refused to accept

  • Conventional scanners are valuable for hygiene, but a known check and a severity score do not explain whether an attacker can reach what matters.
  • Point-in-time penetration tests provide depth, then begin ageing the moment the engagement ends.
  • Attackers combine small weaknesses across systems. Defenders deserve a platform that reasons across the same connected environment.
02

Research that becomes capability

  • ThreatCanary follows emerging techniques across languages, ecosystems and practitioner communities instead of waiting for them to become commodity signatures.
  • Candidate methods are interpreted and reproduced under controlled conditions before they are trusted.
  • Validated research becomes governed, reusable capability with provenance, scope and operating constraints attached.
03

Autonomy with hard boundaries

  • AI can decide what to investigate next inside authorised scope; it cannot turn an unproven hypothesis into a customer finding.
  • Scope, approvals, evidence capture and reproducibility are product architecture—not policy text added afterwards.
  • The result is a smaller set of defensible findings with clear impact, ownership and remediation priority.
04

Built for real operating environments

  • The team has led security work across government, financial services, cloud-native platforms, assurance and enterprise technology delivery.
  • Findings must make sense to the analyst reproducing them, the engineer fixing them and the executive accountable for the risk.
  • Every layer is designed to move from discovery to validated action without losing context or control.
Leadership

Three co-founders behind one operating model.

ThreatCanary’s co-founders combine original offensive research, security leadership in high-consequence environments and the experience required to deliver technology at enterprise scale.

Matt Flannery, Co-founder and Chief Executive Officer of ThreatCanary
Co-founder and Chief Executive Officer · Security engineering and assurance

Matt Flannery

Matt is ThreatCanary’s Co-founder and Chief Executive Officer. He is a hands-on security leader who has built offensive security, threat intelligence, application-security and DevSecOps functions across NSW Government and Big Four consulting. Before ThreatCanary, he founded and exited a DevSecOps consultancy, led EY’s Oceania DevSecOps practice and served as an elected technical lead in CNCF TAG Security. He turns attacker reality into security systems that engineers can operate and executives can defend.

  • Built Service NSW’s Red Team and Threat Intelligence function, leading offensive security, adversary simulation, vulnerability management and exposure-management programs.
  • Established EY’s Oceania DevSecOps practice and delivered security architecture, secure-software and cloud programs across government, banking and critical infrastructure.
  • Founded and exited Ayenem, founded Kubernetes Community Days Australia and was elected Technical Lead of CNCF TAG Security.
Andrew Horton, Co-founder and Chief Technology Officer of ThreatCanary
Co-founder and Chief Technology Officer · Offensive research and product engineering

Andrew Horton

Andrew is ThreatCanary’s Co-founder and Chief Technology Officer. He is a security researcher and engineering leader with nearly two decades of experience turning attacker techniques into useful tools. He leads ThreatCanary’s offensive methodology, research automation and technical product direction.

  • Created open-source security tools including WhatWeb and URLCrazy, distributed through Kali Linux and used by practitioners globally.
  • Led security and engineering work across banking, cryptocurrency payments and large-scale internet platforms.
  • Co-authors ThreatCanary research into prompt injection, AI sandbox security and novel attack techniques.
Marco Delgado, Co-founder and Chairman of ThreatCanary
Co-founder and Chairman · Enterprise technology, governance and commercialisation

Marco Delgado

Marco is ThreatCanary’s Co-founder and Chairman, bringing nearly 35 years of experience across enterprise technology and advanced product manufacturing. His career spans electronics, enterprise networking and wireless, cyber security, managed services, data centre and cloud, collaboration systems, IoT, digital twins, enterprise asset management and agentic AI. He brings the governance, customer, delivery and commercialisation perspective required to turn ambitious security technology into a scalable enterprise platform.

  • Founded Outcomex in 2012 and scaled its enterprise networking, cyber security, data centre, cloud and collaboration capabilities.
  • Founded Farmdeck in 2017 and 365Mesh, building IoT, AI, hardware, software and SaaS solutions for agriculture, healthcare, utilities, transport, education, government and critical infrastructure.
  • Co-founded Lucendus and contributes enterprise asset management, CMMS, inventory, compliance and field-service expertise alongside experience leading multidisciplinary technology teams.
Read Marco’s full profile

Marco Delgado is Co-founder and Chairman of ThreatCanary, bringing nearly 35 years of distinguished experience across enterprise technology, cyber security, enterprise networking and wireless, managed services, data centre and cloud, voice, video and collaboration systems, IoT, digital twins, asset management and agentic AI.

An accomplished technology entrepreneur and business leader, Marco has built, scaled and led multiple technology businesses across Australia and international markets. His career combines deep technical expertise with strategic leadership, governance, commercialisation and customer delivery. He has a proven ability to transform emerging and complex technologies into practical, scalable enterprise solutions that deliver measurable business outcomes.

Marco began his career in electronics and networking technologies and has subsequently led advanced technology teams across a broad range of disciplines, industries and organisational environments. His experience encompasses technology strategy, product development, systems integration, cyber security, IoT, cloud and data centre technologies, AI, enterprise platforms and the manufacturing of advanced technology products.

Entrepreneurial leadership and technology ventures

Outcomex

In 2012, Marco founded and scaled Outcomex into a highly capable systems integration business specialising in enterprise networking, cyber security, data centre and cloud technologies, as well as voice and video collaboration solutions. Through strong technical leadership and a customer-focused approach, the business established significant capability in delivering complex enterprise technology environments.

Farmdeck

In 2017, Marco founded Farmdeck, an agritech technology company applying IoT, advanced AI and SaaS technologies across the global agricultural sector. The platform integrates IoT sensors and intelligent technology supporting livestock, dairy, cropping, horticulture, ranching, farming and feedlot operations.

365Mesh

Marco founded 365Mesh, an advanced IoT and agentic AI systems integration, technology manufacturing and SaaS business with an international reseller network. It develops and delivers hardware, software and SaaS solutions across healthcare, aged care, utilities, transport, education, government, critical infrastructure and enterprise environments.

Lucendus

As Co-founder of Lucendus, Marco contributes to enterprise asset management solutions incorporating EAM, CMMS, inventory management, compliance and field-service capabilities. The platform helps organisations improve asset visibility, operational efficiency, compliance and lifecycle management using native advanced AI technologies.

Leadership, governance and commercialisation

Throughout his career, Marco has led multidisciplinary technology and executive teams, consistently combining strategic vision with strong operational and technical execution. He has been repeatedly recognised for delivering outcomes in cyber security, technology innovation and enterprise transformation.

As Co-founder and Chairman of ThreatCanary, Marco provides the governance, strategic, customer, delivery and commercialisation expertise required to translate ambitious cyber security technology into a scalable enterprise platform. His ability to connect product strategy with channel delivery, customer requirements, operational execution and measurable commercial outcomes is a defining strength of his leadership.

Marco’s career demonstrates a rare combination of technical depth, entrepreneurial capability, strategic leadership, commercial acumen and hands-on experience building and scaling technology businesses. His breadth of expertise enables him to bridge emerging technology innovation and real-world enterprise adoption, creating solutions that are both technically advanced and commercially valuable.