ISO 27001 Certification
Get certified, win the contract, and build security that actually fits your business.
More and more, enterprise customers, government agencies and financial institutions won't sign until you can show ISO 27001 certification. We help you get there with an information security management system (ISMS) built around how your organisation really works, not a binder of templates nobody reads.
Who this is for
Technology and service providers selling to banks, insurers and super funds, who face security due diligence under APRA CPS 234 and CPS 230
SaaS and software companies being asked for certification in tenders and security questionnaires
Growing organisations that want a recognised framework for managing information security risk before a customer or regulator demands it
How we get you certified
1. Gap assessment
We review your current security practices against ISO/IEC 27001:2022 and give you a clear, prioritised report showing where you stand, what's missing and a realistic path to certification.
2. Scope and risk assessment
We help you define a sensible certification scope and run a risk assessment that identifies what actually matters to your business.
3. Build your ISMS
We develop the policies, procedures, risk treatment plan and Statement of Applicability you need. Everything is written in plain language and sized to your organisation, so you can maintain it yourself.
4. Implement controls
We work with your team to put the relevant Annex A controls in place, from access management and supplier security to incident response and business continuity.
5. Internal audit and management review
Before the certification body arrives, we help you run the internal audit and management review the standard requires, so there are no surprises.
6. Certification audit support
We prepare you for the Stage 1 and Stage 2 audits with an independent, accredited certification body, and support you through any findings.
7. Ongoing support (optional)
Certification is only the beginning. We can support your annual surveillance audits, keep your ISMS current, and act as your ongoing security and compliance partner.
Why Cyber Systems HQ
Led by someone who's done it many times. Our ISO 27001 practice is led by Dan Goldberg, who has guided more than 20 organisations through ISO 27001 certification. Dan brings three decades of experience leading security and technology transformation programs. He knows what auditors look for and how to get you there without wasted effort.
Recognised risk and governance expertise. Gavin Oh holds ISACA's CISM (Certified Information Security Manager) and CRISC (Certified in Risk and Information Systems Control) certifications, covering security program management and IT risk.
Financial services know-how. We understand APRA's expectations, so the ISMS we build for you also supports your CPS 234 and CPS 230 obligations and those of your customers.
Right-sized, not over-engineered. You get documentation and controls proportionate to your size and risk, not an enterprise framework squeezed onto a 30-person company.
You own it. We build your team's capability as we go, so you're not dependent on us to keep certified.
Start with a gap assessment
Not sure how far you are from certification? Our fixed-price ISO 27001 gap assessment gives you a clear picture in 2–4 weeks, including a prioritised roadmap and an effort estimate.
Frequently asked questions
How long does certification take?
It depends on your size, complexity and current maturity. Most organisations take several months from starting work to passing the Stage 2 audit. Your gap assessment will give you a realistic timeline.
Do you perform the certification audit?
No. Certification must be done by an independent, accredited certification body. We prepare you for the audit and support you through it, and we can recommend accredited bodies to approach.
What's the difference between ISO 27001 and SOC 2?
ISO 27001 is an international certification for your information security management system and is widely recognised in Australia, Europe and Asia. SOC 2 is a US attestation report produced by a licensed CPA firm. If most of your customers are in Australia, ISO 27001 is usually the stronger choice.
We already have some security policies. Do we start from scratch?
No. We build on what you already have and focus effort on the real gaps.