Compliance and risk
IT compliance support, with the evidence to back it
Insurers, clients, tenders and Defence all ask for security evidence, often against different frameworks. We work out which ones apply to you, close the gaps once and keep the evidence for all of them.
Your price in two minutes, no email needed. Or call 1300 787 429.
Not sure where you stand? Take the five minute scorecard.

- ISO27001 and 9001 certified ourselves, audited externally by Compass Assurance Services
- 5SMB1001 certification levels, from Bronze to Diamond
- 150+Organisations protected by Austin SecureShield
- $25SecureShield Core from $25 per person per month ex GST
Trusted by security conscious businesses across WA








01Where requests come from
Compliance usually arrives as someone else's deadline
Few small businesses choose a framework for its own sake. One of these usually starts the conversation.
- 01
Your insurer's proposal form got longer
Renewal forms ask about MFA, backups, endpoint protection and incident response. The answers need to match what is really in place.
FixAnswers checked against your real settings and gaps closed before the renewal date.
- 02
A client sent a security schedule
Enterprise and government clients pass their own obligations down to suppliers, often with a named framework and a deadline.
FixControls mapped to what the client asked for, with evidence you can attach to your reply.
- 03
A tender asks for SMB1001 or ISO 27001
A certificate can decide whether you make the shortlist, and preparing for one takes planning.
FixA realistic path to the level or certificate asked for and evidence you can use while you get there.
- 04
You want to work with Defence
Defence asks DISP members to meet or exceed Essential Eight Maturity Level 2 on the corporate systems they use to correspond with Defence.
FixDISP readiness that starts with the cyber controls, because they usually take the longest.
02Which framework fits
The frameworks you are asked to meet and how we help
Most of these ask for the same core controls in different language. We build the controls once and map the evidence to each framework you need.
| Framework | What it is | How we help |
|---|---|---|
| Essential Eight | ASD's eight mitigation strategies, measured in maturity levels. Often named by insurers, government and resources clients | Assessment and uplift to ML1 or ML2, then maintained through SecureShield |
| SMB1001 | A cybersecurity certification standard for small and medium businesses, with five levels from Bronze to Diamond | Control aligns to the Gold tier and Command to the Diamond tier. We prepare the evidence and an independent certifying body issues the certificate |
| ISO/IEC 27001 | The international standard for an information security management system, certified by an external auditor | Readiness work on controls, policies and evidence. We hold the certificate ourselves |
| DISP | Defence's security scheme for its supply chain, covering governance, personnel, physical and cyber security | The ICT and cyber controls to Essential Eight ML2 and the evidence behind them |
| Cyber insurance | Proposal forms that ask how you protect accounts, devices and backups | Answers checked against your settings and gaps closed before renewal |
| Incident reporting | Assess a suspected data breach within 30 days and notify eligible breaches, and report a ransomware payment to ASD within 72 hours if turnover is over $3 million | Logging and an incident response plan, so reports can be made on time |
We handle the technical controls and the evidence. Legal interpretation of any obligation sits with your advisers.
03How we help
From first review to audit day
Each part links to a deeper page if you already know what you need.
Find out where you stand
A security review of Microsoft 365, devices, email and backups, scored against the Essential Eight, so you know your starting point.
Cyber security audit / risk register / planReach an Essential Eight maturity level
The eight strategies explained and the path from where you are to ML1 or ML2, without stopping your team working.
Gap assessment / ML1 / ML2Get ready for DISP
ML2 on the systems you use with Defence, plus the documents and evidence your application needs.
Defence suppliers / ML2 / evidenceRun the controls every day
SecureShield keeps detection, application control and training running, with a quarterly review of your score.
Core / Control / CommandTrain your people
Short training and phishing simulations, with completion records you can show an auditor.
Training / phishing simulation / records



Not sure which level you need?
Tell us who is asking about your security. A technical consultant will scope it with you and send a fixed quote. Or take the scorecard to see where you stand first.
04How it works
One set of controls, mapped to what you need
You get a clear order of work and a fixed price before anything starts.
- Step 1
Gap review
We confirm which frameworks apply to you, what you already have and what is missing, including any insurer or client questionnaire.
- Step 2
Plan and fixed quote
Gaps in order of risk and deadline, with a fixed quote for project work and a monthly price for ongoing controls.
- Step 3
Controls and policies
Technical controls rolled out in stages, with policies written to match how your business works.
- Quarterly
Evidence and review
Evidence kept current for each framework and a quarterly review so nothing drifts before your next renewal or audit.
05Plans and frameworks
Which SecureShield plan supports which framework
Each plan builds on the one before, so you can start where you are and step up when a contract asks for more.
| Framework support | CoreSecurity operations | ControlVisibility and governance | CommandStrategy and vCISO |
|---|---|---|---|
| Essential Eight maturity level maintained | ML1 | ML2 | |
| SMB1001 alignment | Gold tier | Diamond tier | |
| Centralised security event logging (SIEM) | |||
| Incident response plan, tested yearly | |||
| Ongoing vCISO and board ready reviews | |||
| Price | $25 per person per month ex GST | $60 per person per month ex GST | $100 per person per month ex GST |
Swipe the table sideways to see every plan.
Every plan includes a quarterly security review and report.
Compare SecureShield plans06Proof
We hold ourselves to the same standard
We are audited externally too, so our advice comes from experience rather than a template.
Certified ourselves
Austin Technology is certified to ISO/IEC 27001 and ISO 9001, audited externally by Compass Assurance Services. We know what an auditor asks for because we answer it too.
Security and governancePalisades
Controls and governance documents aligned to Essential Eight ML1 met a prospective client's security requirements and won the partnership.
Read the case studyPowertech
Aligned to Essential Eight ML2 and progressed towards DISP and ISO 27001, then won a defence grade client.
Read the case studyRelated services and industries
07Recognised and certified
A top 50 MSP in Australia, three years running
Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.


ISO 27001
Information securityOur information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.
How we protect your data
ISO 9001
Quality managementSupport tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.
08Questions
IT compliance questions
What owners and IT managers ask when a framework lands on their desk. Anything else, call 1300 787 429.
01Should we start with the Essential Eight, SMB1001 or ISO 27001?
Start with whatever the person asking needs. If nobody has asked yet, Essential Eight ML1 is a sensible base because the other frameworks ask for many of the same controls. SMB1001 suits businesses that want a certificate sized for them. ISO 27001 is the biggest commitment and is often driven by enterprise or overseas clients.
02Does certification help with cyber insurance?
It helps you answer the proposal form accurately and show evidence for each answer. Whether it changes your premium or cover is a decision for your insurer and broker.
03How does SMB1001 certification work?
SMB1001 has five levels from Bronze to Diamond. You start at the level that fits your business rather than working through all five. We prepare the controls and evidence, and an independent certifying body issues the certificate after its own review. SecureShield Control aligns to the Gold tier and Command to the Diamond tier.
04How long does ISO 27001 readiness take?
It depends on your size and how much is already documented. After the gap review we give you a realistic timeline for controls, policies and the evidence an auditor will sample. We have been through certification ourselves, so the plan reflects what auditors ask for.
05What does compliance support cost?
SecureShield Core is $25 per person per month ex GST. Control is $60 and maintains Essential Eight ML1, and Command is $100 and maintains ML2. Project work such as policy writing or ISO readiness gets a fixed quote.
06We already have an IT person. What would Austin do?
Your IT person keeps running daily IT. We add the security controls, the evidence and the quarterly reviews. Who owns what is agreed in writing, so nothing is missed at audit time.
09Compliance and risk
Know what applies
before the next questionnaire.
Tell us which frameworks your clients, insurer or tenders ask for. A technical consultant will scope what you have and what is missing, then send a fixed quote.
Or call 1300 787 429