Security governance, risk and compliance, done properly.
We help Australian organisations get certified, meet APRA's expectations and build security programs that hold up to scrutiny, from customers, auditors and regulators.
Security questions are now business questions.
Customers want ISO 27001 certification before they sign. Banks, insurers and super funds are pushing CPS 230 and CPS 234 requirements down to their suppliers. Boards and insurers are asking about Essential Eight maturity. Cyber Systems HQ helps you answer those questions with confidence, through practical controls, clear evidence and a program your team can actually maintain.
What we do
ISO 27001 Certification
From gap assessment to certification audit, we build an information security management system around how your organisation really works. Learn more →
APRA CPS 234 & CPS 230
For APRA-regulated entities and the service providers that support them: information security and operational resilience that meet APRA's expectations. Learn more →
Essential Eight & ASD Essentials
An honest assessment of your maturity against ASD's baseline, plus a roadmap ready for the transition to the new Essentials series. Learn more →
vCISO & Ongoing GRC Support
Senior security leadership for a fixed monthly fee, tied to agreed outcomes rather than hours. Learn more →
Penetration Testing & Red Teaming
Testing by OSCP- and OSCE-certified specialists, connected back to your risk register and compliance obligations. Learn more →
Built for organisations under scrutiny
Suppliers to banks, insurers and super funds facing CPS 230 and CPS 234 due diligence
Technology and SaaS companies asked for ISO 27001 in tenders and security questionnaires
APRA-regulated entities strengthening information security and operational resilience
Growing organisations that need security leadership without a full-time CISO
Why Cyber Systems HQ
Built to last
Experience that's been through the audit. Our ISO 27001 practice is led by Dan Goldberg, who has guided more than 20 organisations to certification.
Recognised risk expertise. Gavin Oh holds ISACA's CISM and CRISC certifications.
Right-sized, not over-engineered. Controls and documentation proportionate to your size and risk, written so your team can maintain them.
One program, not five. We map ISO 27001, APRA, Essential Eight and customer requirements together, so you maintain one set of controls.
Not sure where to start?
Most clients begin with a gap assessment: a clear picture of where you stand and a prioritised path forward.