Skip to the main content.

Comply

How do we get ready for the standard or the regulator?

Compliance fails when nobody owns it between audits. We run it as a managed programme, so the evidence exists on the day someone asks.

What we do, and what we do not do

Insicon Cyber prepares organisations for certification. An accredited certification body issues the certificate. Anyone offering both is describing a conflict of interest, and any auditor worth engaging will treat it as one.

We build the management system, implement the controls, produce the evidence, run the internal audit and sit with you through the certification audit. We do not grade our own work. Insicon Cyber is itself ISO 27001 certified, so we have been through what we are asking you to go through.

Start here if this sounds familiar

Compliance work usually starts because something external set the timeline.

  • A tender, major customer or insurer has made ISO 27001 a condition of doing business.
  • You are APRA regulated and CPS 230 has made your material service provider register a live problem.
  • Artificial intelligence is going into production and you need a position that survives a regulator asking.
  • You sell into Australian or New Zealand government and Essential Eight maturity or NZISM alignment is being asked for.
  • You certified once and the management system has decayed since the last surveillance audit.
  • You are in aged care, healthcare, financial services or legal and obligations tightened faster than your controls.

What sits under Comply

Run as a programme with a named Fractional CISO accountable for it, not a project that ends at the audit.

ISO 27001

Scope, risk methodology, statement of applicability, control implementation, evidence, internal audit and management review. We are with you at the certification audit. The certificate comes from an accredited body.

Managed Compliance

AI Security and Governance

Test it. Govern it. Maintain it. Adversarial testing of the models and agents you have deployed, a framework mapping to ISO 42001, and the maintenance that keeps it true.

AI Security and Governance

Essential Eight

Maturity uplift against the Australian Signals Directorate model, to the level you are actually required to hold. Assessed on evidence, not self attestation.

Managed Compliance

NZISM and New Zealand obligations

Alignment to the New Zealand Information Security Manual and NCSC New Zealand guidance, with Privacy Act 2020 obligations. Same team as your Australian programme.

Managed Compliance

APRA CPS 234 and CPS 230

Information security capability and operational risk management, including the material service provider register and the tolerances the board signs. Evidence produced continuously.

Managed Compliance

Sector obligations

Aged Care Act 2024, SOCI Act, Cyber Security Act 2024, Privacy Act 1988 and the New Zealand Privacy Act 2020, mapped to controls you already hold.

Managed Compliance

How a programme runs

Five stages. Most providers leave out the fifth, which is why certifications lapse.

1

Establish the gap

A readiness assessment against the specific standard, so you size the task before funding it.

2

Design the system

Scope, risk methodology, policies and control design built around how the business works, so it does not get routed around.

3

Implement and evidence

Controls operating, with artefacts captured as you go rather than reconstructed later.

4

Audit and certify

Internal audit, management review, then the certification audit with an accredited body. We are in the room.

5

Maintain it

Surveillance audits, control monitoring and board reporting between assessments. This is where programmes quietly fail.

Why run it with Insicon Cyber

01

Audited, not asserted

Insicon Cyber is ISO 27001 certified. We hold the standard we prepare you for.

02

We do not mark our own homework

Preparation and certification are separated deliberately. That separation is what makes the certificate worth holding.

03

One programme across both markets

Australian and New Zealand obligations run by the same team from North Sydney, with Australian data sovereignty.

04

Sector experience that is real

Financial services, aged care, healthcare, legal, retail and technology. Proof of range, not a list of who we accept.

Find out how far off you are before you commit a budget.

The gap is rarely where organisations expect. Start with a readiness assessment against the standard you are actually held to.