- Market services
-
Compliance audits & reviews
Our audit team undertakes the complete range of audits required of Australian accounting laws to help you to help you meet obligations or fulfil best practice procedures.
-
Audit quality
We are fiercely dedicated to quality, use proven and globally tested audit methodologies, and invest in technology and innovation.
-
Financial reporting advisory
Our financial reporting advisory team helps you understand changes in accounting standards, develop strategies and communicate with your stakeholders.
-
Audit advisory
Grant Thornton’s audit advisory team works alongside our clients, providing a full range of reviews and audits required of your business.
-
Corporate tax & advisory
We provide comprehensive corporate tax and advisory service across the full spectrum of the corporate tax process.
-
Private business tax & advisory
We work with private businesses and their leaders on all their business tax and advisory needs.
-
Tax compliance
We work alongside clients to manage all tax compliance needs and identify potential compliance or tax risk issues.
-
Employment tax
We help clients understand and address their employment tax obligations to ensure compliance and optimal tax positioning for their business and employees.
-
International tax
We understand what it means to manage tax issues across multiple jurisdictions, and create effective strategies to address complex challenges.
-
GST, stamp duty & indirect tax
Our deep technical knowledge and practical experience means we can help you manage and minimise the impact of GST and indirect tax, like stamp duty.
-
Tax law
Our team – which includes tax lawyers – helps you understand and implement regulatory requirements for your business.
-
Innovation Incentives
Our national team has extensive experience navigating all aspects of the government grants and research and development tax incentives.
-
Transfer pricing
Transfer pricing is one of the most challenging tax issues. We help clients with all their transfer pricing requirements.
-
Tax digital consulting
We analyse high-volume and unstructured data from multiple sources from our clients to give them actionable insights for complex business problems.
-
Corporate simplification
We provide corporate simplification and managed wind-down advice to help streamline and further improve your business.
-
Superannuation and SMSF
Increasingly, Australians are seeing the benefits, advantages and flexibility of taking control of their own superannuation and retirement planning.
-
Payroll consulting & Award compliance
Many organisations are grappling with a myriad of employee agreements and obligations, resulting in a wide variety of payments to their people.
-
Cyber resilience
The spectrum of cyber risks and threats is now so significant that simply addressing cybersecurity on its own isn’t enough.
-
Internal audit
We provide independent oversight and review of your organisation's control environments to manage key risks, inform good decision-making and improve performance.
-
Financial crime
Our team helps clients navigate and meet their obligations to mitigate crime as well as develop and implement their risk management strategies.
-
Consumer Data Right
Consumer Data Right (CDR) aims to provide Australians with more control over how their data is used and disclosed.
-
Risk management
We enable our clients to achieve their strategic objectives, fulfil their purpose and live their values supported by effective and appropriate risk management.
-
Controls assurance
In Australia, as with other developed economies, regulatory and market expectations regarding corporate transparency continue to increase.
-
Governance
Through fit for purpose governance we enable our clients to make the appropriate decisions on a timely basis.
-
Regulatory compliance
We enable our clients to navigate and meet their regulatory and compliance obligations.
-
Forensic accounting and dispute advisory
Our team advises at all stages of a litigation dispute, taking an independent view while gathering and reviewing evidence and contributing to expert reports.
-
Investigations
Our licensed forensic investigators with domestic and international experience deliver high quality results in the jurisdictions in which you operate.
-
Asset tracing investigations
Our team of specialist forensic accountants and investigators have extensive experience in tracing assets and the flow of funds.
-
Mergers and acquisitions
Our mergers and acquisitions specialists guide you through the whole process to get the deal done and lay the groundwork for long-term success.
-
Acquisition search & strategy
We help clients identify, finance, perform due diligence and execute acquisitions to maximise the growth opportunities of your business.
-
Selling a business
Our M&A team works with clients to achieve a full or partial sale of their business, to ensure achievement of strategic ambitions and optimal outcomes for stakeholders.
-
Operational deal services
Our operational deal services team helps to ensure the greatest possible outcome and value is gained through post merger integration or post acquisition integration.
-
Transaction advisory
Our transaction advisory services support our clients to make informed investment decisions through robust financial due diligence.
-
ESG Due Diligence
As environmental, social, and governance (ESG) considerations become increasingly pivotal for dealmakers in Australia, it is important for investors to feel confident in assessing transactions through an ESG lens.
-
Business valuations
We use our expertise and unique and in-depth methodology to undertake business valuations to help clients meet strategic goals.
-
Tax in mergers & acquisition
We provide expert advice for all M&A taxation aspects to ensure you meet all obligations and are optimally positioned.
-
Corporate finance
We provide effective and strategic corporate finance services across all stages of investments and transactions so clients can better manage costs and maximise returns.
-
Debt advisory
We work closely with clients and lenders to provide holistic debt advisory services so you can raise or manage existing debt to meet your strategic goals.
-
Working capital optimisation
Our proven methodology identifies opportunities to improve your processes and optimise working capital, and we work with to implement changes and monitor their effectiveness.
-
Capital markets
Our team has significant experience in capital markets and helps across every phase of the IPO process.
-
Debt and project finance raising
Backed by our experience accessing full range of available funding types, we work with clients to develop and implement capital raising strategies.
-
Private equity
We provide advice in accessing private equity capital.
-
Financial modelling
Our financial modelling advisory team provides strategic, economic, financial and valuation advice for project types and sizes.
-
Payments advisory
We provide merchants-focused payments advice on all aspects of payment processes and technologies.
-
Voluntary administration & DOCA
We help businesses considering or in voluntary administration to achieve best possible outcomes.
-
Corporate insolvency & liquidation
We help clients facing corporate insolvency to undertake the liquidation process to achieve a fair and orderly company wind up.
-
Complex and international insolvency
As corporate finance specialists, Grant Thornton can help you with raising equity, listings, corporate structuring and compliance.
-
Safe Harbour advisory
Our Safe Harbour Advisory helps directors address requirements for Safe Harbour protection and business turnaround.
-
Bankruptcy and personal insolvency
We help clients make informed choices around bankruptcy and personal insolvency to ensure the best personal and stakeholder outcome.
-
Creditor advisory services
Our credit advisory services team works provides clients with credit management assistance and credit advice to recapture otherwise lost value.
-
Small business restructuring process
We provide expert advice and guidance for businesses that may need to enter or are currently in small business restructuring process.
-
Asset tracing investigations
Our team of specialist forensic accountants and investigators have extensive experience in tracing assets and the flow of funds.
-
Independent business reviews
Does your company need a health check? Grant Thornton’s expert team can help you get to the heart of your issues to drive sustainable growth.
-
Commercial performance
We help clients improve commercial performance, profitability and address challenges after internal or external triggers require a major business model shift.
-
Safe Harbour advisory
Our Safe Harbour advisory helps directors address requirements for Safe Harbour protection and business turnaround.
-
Corporate simplification
We provide corporate simplification and managed wind-down advice to help streamline and further improve your business.
-
Director advisory services
We provide strategic director advisory services in times of business distress to help directors navigate issues and protect their company and themselves from liability.
-
Debt advisory
We work closely with clients and lenders to provide holistic debt advisory services so you can raise or manage existing debt to meet your strategic goals.
-
Business planning & strategy
Our clients can access business planning and strategy advice through our value add business strategy sessions.
-
Private business company secretarial services
We provide company secretarial services and expert advice for private businesses on all company secretarial matters.
-
Outsourced accounting services
We act as a third-party partner to international businesses looking to invest in Australia on your day-to-day finance and accounting needs.
-
Superannuation and SMSF
We provide SMSF advisory services across all aspects of superannuation and associated tax laws to help you protect and grow your wealth.
-
Management reporting
We help you build comprehensive management reporting so that you have key insights as your business grows and changes.
-
Financial reporting
We help with all financial reporting needs, including set up, scaling up, spotting issues and improving efficiency.
-
Forecasting & budgeting
We help you build and maintain a business forecasting and budgeting model for ongoing insights about your business.
-
ATO audit support
Our team of experts provide ATO audit support across the whole process to ensure ATO requirements are met.
-
Family business consulting
Our family business consulting team works with family businesses on running their businesses for continued future success.
-
Private business taxation and structuring
We help private business leaders efficiently structure their organisation for optimal operation and tax compliance.
-
Outsourced CFO services
Our outsourced CFO services provide a full suite of CFO, tax and finance services and advice to help clients manage risk, optimise operations and grow.
-
ESG & sustainability reporting
There is a growing demand for organisations to provide transparency on their commitment to sustainability and disclosure of the nonfinancial impacts of their business activities. Commonly, the responsibility for sustainability and ESG reporting is landing with CFOs and finance teams, requiring a reassessment of a range of reporting processes and controls.
-
ESG & sustainability advisory
With the ESG and sustainability landscape continuing to evolve, we are focussed on helping your business to understand what ESG and sustainability represents and the opportunities and challenges it can provide.
-
ESG, sustainability and climate reporting assurance
As the demand for organisations to prepare information in relation to ESG & sustainability continues to increase, through changes in regulatory requirements or stakeholder expectations, there is a growing need for assurance over the information prepared.
-
ESG Due Diligence
As environmental, social, and governance (ESG) considerations become increasingly pivotal for dealmakers in Australia, it is important for investors to feel confident in assessing transactions through an ESG lens.
-
Management consulting
Our management consulting services team helps you to plan and implement the right strategy to deliver sustainable growth.
-
Financial consulting
We provide financial consulting services to keep your business running so you focus on your clients and reaching strategic goals.
-
China practice
The investment opportunities between Australia and China are well established yet, in recent years, have also diversified.
-
Japan practice
The trading partnership between Japan and Australia is long-standing and increasingly important to both countries’ economies.
-
India practice
It’s an exciting time for Indian and Australian businesses looking to each jurisdiction as part of their growth ambitions.
-
Singapore practice
Our Singapore Practice works alongside Singaporean companies to achieve growth through investment and market expansion into Australia.
-
Vietnam practice
Investment and business opportunities in Vietnam are expanding rapidly, driven by new markets, diverse industries, and Vietnam's growing role in export manufacturing, foreign investment, and strong domestic demand.
-
Client Alert Government Grants in FY25As we embark on a new financial year, it’s crucial to take a strategic approach to understanding the government grants landscape.
-
Client Alert Consultation on foreign resident CGT rules commencesTreasury is taking steps to ensure fairer tax treatment for foreign resident investors by tightening Australia's foreign resident Capital Gains Tax (CGT) regime. Proposed changes aim to broaden the CGT base and enhance integrity, impacting infrastructure, energy, agriculture, and more.
-
Insight Australian wine export strategies post-China tariff removalFollowing the recent removal of tariffs on Australian wine by China, the industry is keen to rebuild relations and explore the right export markets. This presents Australian wine producers with a chance to reassess their position in the global market.
-
Insight Cultivating innovation: A guide to claiming the R&D Tax Incentive in the Agribusiness sectorTo facilitate continued innovation in the Agribusiness sector, the Federal Government’s Research and Development Tax Incentive supports companies to undertake research and development activities that meet the eligibility criteria.
-
Renewable Energy
Transformation through energy transition
-
Flexibility & benefits
The compelling client experience we’re passionate about creating at Grant Thornton can only be achieved through our people. We’ll encourage you to influence how, when and where you work, and take control of your time.
-
Your career development
At Grant Thornton, we strive to create a culture of continuous learning and growth. Throughout every stage of your career, you’ll to be encouraged and supported to seize opportunities and reach your full potential.
-
Diversity & inclusion
To be able to reach your remarkable, we understand that you need to feel connected and respected as your authentic self – so we listen and strive for deeper understanding of what belonging means.
-
In the community
We’re passionate about making a difference in our communities. Through our sustainability and community engagement initiatives, we aim to contribute to society by creating lasting benefits that empower others to thrive.
-
Graduate opportunities
As a new graduate, we aim to provide you more than just your ‘traditional’ graduate program; instead we kick start your career as an Associate and support you to turn theory into practice.
-
Vacation program
Our vacation experience program will give you the opportunity to begin your career well before you finish your degree.
-
The application process
Applying is simple! Find out more about each stage of the recruitment process here.
-
FAQs
Got questions about applying? Explore frequently asked questions about our early careers programs.
-
Our services lines
Learn about our services at Grant Thornton
-
Current opportunities
Current opportunities
-
Remarkable people
Our team members share their remarkable career journeys and experiences of working at Grant Thornton.
-
Working at Grant Thornton
Explore our culture, benefits and ways we support you in your career.
-
Current opportunities
Positions available.
-
Contact us
Get in touch
Technology companies must adopt a new approach to digital risk
Jutting out into Austria’s skyline, emerging from the surrounding forest, lies an ancient medieval wonder – Hochosterwitz Castle. The thousands of tourists that flock here every year soon learn a surprising fact: it is one of only a very small number of castles around the world that has never been breached.
Its inhabitants thank Baron George Khevenhüller. He knew that holding the castle was strategically important to the region. Fearing an onslaught of marauding armies, he ordered the construction of a series of 14 fortified gates on its gentlest slope, the most likely avenue of attack. Each has a unique defence structure designed to flummox invaders. It worked. The most successful conqueror only reached the fourth gate.
Today’s technology companies can learn something from Khevenhüller. They may not fear foreign conquerors, but they do face attack from malicious actors that are set on stealing their IP or the personal data they hold.
Like Khevenhüller, they must identify the assets that are most important, consider the most likely lines of attack, and tailor a defensive strategy accordingly.
Of course, a holistic digital risk strategy (which should span cybersecurity and data privacy risk across the enterprise) must incorporate more than defending against cyberattack. Ever stricter data protection regulation, not to mention the public’s growing awareness of privacy, means technology companies must regularly reexamine privacy controls. Data asset categorisation is essential in this process too.
Technology companies are most vulnerable
The annual global cost of cybercrime is estimated to hit US$6tn in 2021, up from US$3tn in 2015. James Arthur, partner and head of cyber consulting at Grant Thornton UK agrees. “Technology companies are particularly impacted.”
“It is important for technology companies to develop a digital risk strategy based on their most strategically important data assets,” says James. “After all, they typically hold more data than non-tech companies and often lead the way in adopting new technologies, which can create cyber vulnerabilities.”
B2C technology companies also house and process huge volumes of sensitive, personal information. It is, therefore, no surprise that IT was the most targeted sector for web application cyber-attacks last year.
Added together, this means that technology companies are now more vulnerable to cyber attacks and customer data breaches than ever before. This not only exposes them to hefty regulatory fines but also business-crippling reputational damage.
Get ahead of regulators
In the last three years, technology companies made great efforts to comply with new data privacy and protection regulations, not least GDPR. Most large technology companies are now compliant, but they must remain vigilant. Data protection regulations are becoming stricter and the penalties for non-compliance are increasing. What’s more, customers are becoming more aware of privacy issues and are prepared to punish companies for not taking it seriously.
Technology companies must respond by going above and beyond the minimum required by the regulator on privacy. “Tech companies today need to go beyond the basics to ensure compliance because these companies service their clients in a regulated industry and are largely data controllers, while their clients may be data processors,” confirms Akshay Garkel, advisory partner at Grant Thornton India.
“Cloud service providers may be required to maintain 10 out of 20 (for example) data controls for minimum compliance. But they shouldn’t stop there. In the spirit of ensuring security and privacy they might want to go at least four or five notches above the minimum expected from the regulator because clients will demand it.”
The tightrope between privacy and analytics
But a careful balance must be struck. Customers will appreciate technology companies going the extra mile on privacy, but not if it restricts their ability to receive personalised offers or the development of products tailored to their individual needs.
Individual companies aside, overbearing privacy law prevents the use of data to drive positive societal outcomes, be that in relation to healthcare, disease monitoring or traffic accident reduction. So, governments and regulators must also be careful not to enact overly restrictive privacy laws.
“The balance between data protection and using data for the public good is a key debate for society,” says Nick Watson, partner and technology sector lead at Grant Thornton UK. “Germany has very strong privacy rules, but this has resulted in traffic accident data not being collected on particular stretches of roads. Therefore, they weren’t able to collect data that would have pinpointed a particular accident hotspot. You could take data privacy to a level where even non-personalised data is not collated on a group-wide, anonymous basis. In this case society would lose out.”
The middle-man in surveillance
Judging how far to go on privacy has become more complex because, like it or not, many technology companies are now surveillance intermediaries. Whether it be messages sent on social media, recordings from Echo devices or location data stored on smart phones, technology companies possess information that is useful for fighting crime.
There is no question that they must comply with the law regarding requests for information, but they have discretion over how swiftly they reply and the depth of information they provide.
Many now wonder whether law enforcement data requests should be processed without question, or heavily scrutinised in the interest of preserving privacy.
In the past, some technology companies resisted rather than cooperated with law enforcement. But as technology companies unwittingly accumulate more and more vital evidence, there is controversy in some markets about which data is shared, how much and for what purpose.
After all, being perceived as uncooperative with counter-terrorism forces is far more damaging than not adhering to the absolute strictest privacy standards.
Strengthen protection of digital assets
How should technology businesses respond to rising digital risk? First and foremost, they must classify, categorise and map out their digital assets to understand the specific risks and value associated with them.
Armed with this insight, they should develop and implement a nuanced, risk-based digital risk strategy that fortifies the digital crown jewels – those deemed most critical to the business and its customers.
Of course, one company’s most valuable data may be completely unimportant to another. For example, fintech companies highly value customers’ financial information, entertainment technology companies place high importance on consumer preference data and high-tech companies treasure their IP.
This approach sounds sensible. But a surprisingly large number of technology companies do not do this, and instead rely on an outdated one-size-fits-all approach to cyber security and data privacy based on perimeter security.
Orus Dearman, managing director of risk advisory services at Grant Thornton US, explains how this classification process can lead to practical change that reduces vulnerability.
“We assisted a technology company client in performing a data categorisation process to enable them to efficiently identify sensitive and personal information within their databases and networks as part of an overall data inventory. This allowed the company to deploy data protection resources where they are needed and would have the most impact,” he says. “Now, if anyone wants to change anything to do with this data or these systems, the privacy team is brought into the process as part of the workflow.”
Bin useless data
In contrast, data revealed to be not at all useful to the business and not required for regulatory and compliance purposes should be deleted or appropriately anonymised. This reduces the risk of it being compromised.
Naturally, technology companies can be reluctant to delete information due to concerns they might need it for an audit or that it is essential for something they are unaware of. Data mapping helps realise interdependencies, which can assist in deleting data.
But data asset categorising doesn’t just reduce risk. It also creates value. This exercise might identify a dataset or combination of datasets that can be used to improve the efficiency of internal operations or gain insight into customer preferences.
When strategy changes, so should data categorisation
Technology companies must remember two things when profiling data assets. First, it is not a one-off exercise. They must constantly map out their digital assets as the nature of the threat changes and as their business priorities evolve.
Second, this task cannot be left to the information security officer or head of IT. It is a critical business decision that must align to business objectives. Senior business leaders must be involved in the process.
Drive competitive advantage through trust
There is a real opportunity for B2B technology companies to market themselves around digital trust. Those that demonstrate readiness to respond to a cyber threat, responsibly handle customer data and empower customers to manage privacy controls stand to gain a competitive advantage.
To start building trust, technology companies must offer value-added cyber security solutions such as malware and ransomware screening that plugs vulnerabilities as part of their core offering. Customers will also be impressed with suppliers that conduct comprehensive cybersecurity audits and produce independent assurance reports.
“Reports that demonstrate capability, security, and a serious commitment to risk management (such as SOC2 or ISAE3402) are without question a way for technology companies to differentiate themselves from the competition,” says Matthew Green, technology advisory partner at Grant Thornton Australia. “The more astute clients are now starting to ask for the validation and the ongoing assurance that the organisation is maintaining an appropriate level of data security and are requesting those reports as a way of demonstrating it.”
There are a number of security standards that technology companies can use to demonstrate best practice digital resilience. But because every technology company is different, these merely provide a starting point. Technology companies should evaluate what their customers want when it comes to privacy and security and prioritise this.
Consumers value control
The jury is out on whether B2C technology can truly differentiate themselves through digital trust. Still, there is no harm in making it incredibly easy for customers to identify and delete data that is held about them and manage privacy settings.
B2C technology companies must also make privacy policies crystal clear. Today, most are displayed in tiny lettering across multiple pages, making them impossible to decipher.
“Privacy should be an enabler and not hinder innovation. Companies who have embraced good privacy practices should use that as a branding platform in the market,” confirms Orus.
“Clearly communicating privacy policies in a transparent way is essential. The general trend for technology companies is to develop a user hub that allows users to see what data is being held about them and allows them to opt in and out of various things."
"Privacy regulations such as the GDPR and upcoming California Consumer Privacy Act (CCPA) require clear and concise privacy notices for applicable data subjects. However, for those of us that don’t fall into the GDPR or CCPA buckets, many user agreements are over a hundred pages long, so they can still be made more user-friendly.”
Our five recommendations
Technology companies should implement the following recommendations to build and maintain digital trust:
- Categorise data assets according to their strategic importance. Those that will disrupt the business or customer experience or cause untold reputational damage if compromised should be heavily protected.
- Regularly review your data asset categorisation in collaboration with senior business leaders. This categorisation must align with business objectives, which may change over time.
- Don’t just think about the minimum required from the regulator when implementing data protection controls. Instead, consider what regulations may look like in the future.
- Collaborate fully with valid requests for data and information and know the extent to which data should be provided.
- Demonstrate your commitment to data protection by having your cyber risk practices tested regularly by an independent third-party. This will help to build trust.
When it comes to protecting your business to become immune to a cyber attack or data breach, one size does not fit all. However, technology companies can bolster their resilience by applying some or all of these recommendations so long as they tailor their actions to suit their unique position, and that of their clients.