Comply
How do we get ready for the standard or the regulator?
Compliance fails when nobody owns it between audits. We run it as a managed programme, so the evidence exists on the day someone asks.
What we do, and what we do not do
Insicon Cyber prepares organisations for certification. An accredited certification body issues the certificate. Anyone offering both is describing a conflict of interest, and any auditor worth engaging will treat it as one.
We build the management system, implement the controls, produce the evidence, run the internal audit and sit with you through the certification audit. We do not grade our own work. Insicon Cyber is itself ISO 27001 certified, so we have been through what we are asking you to go through.
Start here if this sounds familiar
Compliance work usually starts because something external set the timeline.
- A tender, major customer or insurer has made ISO 27001 a condition of doing business.
- You are APRA regulated and CPS 230 has made your material service provider register a live problem.
- Artificial intelligence is going into production and you need a position that survives a regulator asking.
- You sell into Australian or New Zealand government and Essential Eight maturity or NZISM alignment is being asked for.
- You certified once and the management system has decayed since the last surveillance audit.
- You are in aged care, healthcare, financial services or legal and obligations tightened faster than your controls.
What sits under Comply
Run as a programme with a named Fractional CISO accountable for it, not a project that ends at the audit.
ISO 27001
Scope, risk methodology, statement of applicability, control implementation, evidence, internal audit and management review. We are with you at the certification audit. The certificate comes from an accredited body.
Managed ComplianceAI Security and Governance
Test it. Govern it. Maintain it. Adversarial testing of the models and agents you have deployed, a framework mapping to ISO 42001, and the maintenance that keeps it true.
AI Security and GovernanceEssential Eight
Maturity uplift against the Australian Signals Directorate model, to the level you are actually required to hold. Assessed on evidence, not self attestation.
Managed ComplianceNZISM and New Zealand obligations
Alignment to the New Zealand Information Security Manual and NCSC New Zealand guidance, with Privacy Act 2020 obligations. Same team as your Australian programme.
Managed ComplianceAPRA CPS 234 and CPS 230
Information security capability and operational risk management, including the material service provider register and the tolerances the board signs. Evidence produced continuously.
Managed ComplianceSector obligations
Aged Care Act 2024, SOCI Act, Cyber Security Act 2024, Privacy Act 1988 and the New Zealand Privacy Act 2020, mapped to controls you already hold.
Managed ComplianceHow a programme runs
Five stages. Most providers leave out the fifth, which is why certifications lapse.
Establish the gap
A readiness assessment against the specific standard, so you size the task before funding it.
Design the system
Scope, risk methodology, policies and control design built around how the business works, so it does not get routed around.
Implement and evidence
Controls operating, with artefacts captured as you go rather than reconstructed later.
Audit and certify
Internal audit, management review, then the certification audit with an accredited body. We are in the room.
Maintain it
Surveillance audits, control monitoring and board reporting between assessments. This is where programmes quietly fail.
Why run it with Insicon Cyber
01
Audited, not asserted
Insicon Cyber is ISO 27001 certified. We hold the standard we prepare you for.
02
We do not mark our own homework
Preparation and certification are separated deliberately. That separation is what makes the certificate worth holding.
03
One programme across both markets
Australian and New Zealand obligations run by the same team from North Sydney, with Australian data sovereignty.
04
Sector experience that is real
Financial services, aged care, healthcare, legal, retail and technology. Proof of range, not a list of who we accept.
Where this goes next
Assess, Comply and Operate group our work. They are not a sequence you have to walk. Start where the pressure is.
Find out how far off you are before you commit a budget.
The gap is rarely where organisations expect. Start with a readiness assessment against the standard you are actually held to.