
CASE STUDY
Detecting Insider Risk in a Defence Prime. During the Proof of Value
The Challenge
Penske Australia & New Zealand is a major enterprise, over 1,300 employees, a subsidiary of Penske Automotive Group (Fortune 500, NYSE-listed), and a leading supplier of heavy-duty trucks, diesel engines, and power systems across Australia and New Zealand. They operate across commercial, mining, energy, marine, and rail sectors.
What fewer people know is that Penske ANZ also holds a defence arm that contracts directly with the Australian Government. Though smaller in headcount, this division services critical naval assets and handles significant intellectual property. The combination of sensitive defence work, a large commercial workforce, and high-value IP created an environment where insider risk was a real and present concern, not a theoretical one.
Bobby Stojceski, then CISO and now Chief Security Officer, was looking for a way to better manage how data moved across the organisation. Penske ANZ needed visibility, not just at the perimeter, but across endpoints, removable media, and user behaviour. They needed to know what data was leaving, where it was going, and who was moving it.
The Solution
GuardWare proposed a free assessment: deploy GuardWare INSIGHT, let it run, and show what it found. What happened next made the case faster than any sales pitch could.
During the assessment, GuardWare detected and prevented two separate data dumps to USB drives by staff. In an organisation of this size and sensitivity, that kind of finding isn’t a minor flag. It’s proof of exactly the risk that security leaders fear but rarely catch in time.
Within months, Penske ANZ moved from trial to full deployment. GuardWare INSIGHT became an integral part of how the organisation manages data security, monitors information movement, and maintains compliance, across both its commercial and defence operations.
Given the sensitivity of the defence work, Penske ANZ runs its own on-premise instance rather than using GuardWare’s cloud. This level of deployment flexibility was essential for an organisation operating under strict sovereign security requirements.
The Outcome
GuardWare is now embedded in Penske ANZ’s security operations. The platform provides continuous monitoring across the organisation, giving the security team granular visibility into data movement and user behaviour.
The relationship has also evolved well beyond a standard vendor arrangement. Penske ANZ’s security team, who are highly technical experts in their field, actively contributes to product development, recommending new capabilities such as VPN connection monitoring and visibility over remote workers. The partnership has become a genuine feedback loop, with Penske ANZ helping shape a platform built for the realities of mid-market Australian enterprise security.
Penske ANZ is currently trialling GuardWare’s DISCOVER product to extend their capabilities further.
"We now have complete visibility of data across our assets. In the very first week of monitoring, we detected and prevented two data dumps to USB drives by staff. It is easy to use and has helped us improve our overall security and compliance requirements."

Bobby Stojceski
Chief Security Officer, Penske ANZThe Takeaway
For CISOs and CSOs, Penske ANZ illustrates two things worth remembering. First, insider risk doesn’t announce itself, it surfaces when you finally have the visibility to see it. Penske found real data exfiltration attempts within a week of turning on monitoring.
Second, proof of value beats proof of concept. When the tool caught actual incidents during the trial, the business case wrote itself. If your organisation handles sensitive IP, government contracts, or defence work and you don’t yet have granular visibility over data movement, the question isn’t whether you have an insider risk problem, it’s whether you’d know if you did.

