A Perth-led compliance practice, not a checklist template handed back at audit time.
Compliance for a WA SMB is not a deck you hand to the auditor once a year. It is a written baseline — Essential Eight maturity, ISO 27001 readiness, the controls around your data, the advisories you must interpret — kept current every month by a named Perth engineer who picks up the phone in AWST. We run that practice under one roof, against the Australian standards the regulator actually reads.
What the engagement covers
Four services, one written standard.
Each Compliance engagement delivers these four capabilities together — they are the floor, not a menu. Reduce any one of them and the rest stop holding up.
- Essential Eight maturity assessments + remediation
Your environment graded against the ACSC Essential Eight maturity model (Levels 0 to 3), strategy by strategy — application control, patching, macros, MFA, backups, admin privilege — then turned into a written remediation plan with named owners and audit-grade artefacts. The report is not a slide deck handed back at the end.
- Graded against ACSC Maturity Levels 0 to 3
- Remediation plan with named owners, not a hand-off
- No template report — written against your real estate
- ISO 27001 readiness + gap analysis
A gap analysis produced from your actual estate — Statement of Applicability, risk register, asset inventory, control owners, and the audit trail your external auditor reads on visit day. Built over the engagement, not pushed together the week before the audit window.
- Gap analysis produced, documented, and owned
- SoA + risk register written with control owners
- Internal audit rehearsal before the external visit
- ACSC guidance interpretation
New ACSC advisories and strategy publications decoded into operator-level actions for your stack within seven days of release — strategy mapped to ticket, advisory mapped to control, calendar tied to the ACSC publication cadence so nothing lands cold.
- New ACSC advisories decoded for your stack within seven days
- Operator-level actions mapped from strategy down to ticket
- Annual cadence tied to the ACSC publication calendar
- Ongoing compliance reporting
A monthly posture diff to leadership, a quarterly board report mapped to your auditor’s framework, and an evidence pack maintained continuously so audit week is review, not reconstruction. This is the named deliverable, not a footnote.
- Monthly posture diff to leadership
- Quarterly board report mapped to your auditor’s framework
- Evidence pack maintained continuously, audit-ready
How we run the engagement
Honest baseline first, then the 90-day plan.
- 01
Baseline maturity assessment
We grade Essential Eight maturity strategy by strategy against your real estate, and we run the ISO 27001 gap analysis against your actual controls — both before a plan is written, so the plan is grounded in evidence, not assumptions.
- 02
Remediation plan + SoA build
Every gap becomes a quarterly objective with a named owner and audit-grade artefacts. The ISO 27001 Statement of Applicability is written up over weeks, alongside the risk register, not rushed for the audit week.
- 03
Monthly posture review + ongoing reporting
The named monthly cadence delivers ongoing compliance reporting — same maturity grades, same evidence, the diff written down and shipped to leadership on the first Tuesday of every month, board-ready each quarter.
- 04
Quarterly ACSC advisory debrief
We interpret every ACSC advisory that has landed since the last quarter and map it into your controls, tickets and roadmap — the cycle that keeps the Perth-led practice current with what the regulator is publishing right now.
Next step
Want the baseline mapped against your real estate?
Book a free 30-minute security assessment with a Perth engineer. We will grade Essential Eight maturity, scope the ISO 27001 gap analysis, and hand you a written snapshot — under NDA, at no cost, even if you never sign with us.