Compliance and risk

IT compliance support, with the evidence to back it

Insurers, clients, tenders and Defence all ask for security evidence, often against different frameworks. We work out which ones apply to you, close the gaps once and keep the evidence for all of them.

Your price in two minutes, no email needed. Or call 1300 787 429.

Not sure where you stand? Take the five minute scorecard.

A group meeting around a table with a laptop and documents
ISO/IEC 27001 and ISO 9001Certified, audited by Compass Assurance Services
  • ISO27001 and 9001 certified ourselves, audited externally by Compass Assurance Services
  • 5SMB1001 certification levels, from Bronze to Diamond
  • 150+Organisations protected by Austin SecureShield
  • $25SecureShield Core from $25 per person per month ex GST

Trusted by security conscious businesses across WA

thyssenkruppFLSmidthInterContinental EnergyAlliance NickelCarers WAAcclaim AccountingKoch SolutionsCallidus Process Solutions

01Where requests come from

Compliance usually arrives as someone else's deadline

Few small businesses choose a framework for its own sake. One of these usually starts the conversation.

  1. Your insurer's proposal form got longer

    Renewal forms ask about MFA, backups, endpoint protection and incident response. The answers need to match what is really in place.

    FixAnswers checked against your real settings and gaps closed before the renewal date.

  2. A client sent a security schedule

    Enterprise and government clients pass their own obligations down to suppliers, often with a named framework and a deadline.

    FixControls mapped to what the client asked for, with evidence you can attach to your reply.

  3. A tender asks for SMB1001 or ISO 27001

    A certificate can decide whether you make the shortlist, and preparing for one takes planning.

    FixA realistic path to the level or certificate asked for and evidence you can use while you get there.

  4. You want to work with Defence

    Defence asks DISP members to meet or exceed Essential Eight Maturity Level 2 on the corporate systems they use to correspond with Defence.

    FixDISP readiness that starts with the cyber controls, because they usually take the longest.

02Which framework fits

The frameworks you are asked to meet and how we help

Most of these ask for the same core controls in different language. We build the controls once and map the evidence to each framework you need.

Compliance frameworks small and medium businesses meet and how Austin Technology helps
FrameworkWhat it isHow we help
Essential EightASD's eight mitigation strategies, measured in maturity levels. Often named by insurers, government and resources clientsAssessment and uplift to ML1 or ML2, then maintained through SecureShield
SMB1001A cybersecurity certification standard for small and medium businesses, with five levels from Bronze to DiamondControl aligns to the Gold tier and Command to the Diamond tier. We prepare the evidence and an independent certifying body issues the certificate
ISO/IEC 27001The international standard for an information security management system, certified by an external auditorReadiness work on controls, policies and evidence. We hold the certificate ourselves
DISPDefence's security scheme for its supply chain, covering governance, personnel, physical and cyber securityThe ICT and cyber controls to Essential Eight ML2 and the evidence behind them
Cyber insuranceProposal forms that ask how you protect accounts, devices and backupsAnswers checked against your settings and gaps closed before renewal
Incident reportingAssess a suspected data breach within 30 days and notify eligible breaches, and report a ransomware payment to ASD within 72 hours if turnover is over $3 millionLogging and an incident response plan, so reports can be made on time

We handle the technical controls and the evidence. Legal interpretation of any obligation sits with your advisers.

Harman KaurKrishna MoothooJamie WebbGregory Ashley

Not sure which level you need?

Tell us who is asking about your security. A technical consultant will scope it with you and send a fixed quote. Or take the scorecard to see where you stand first.

04How it works

One set of controls, mapped to what you need

You get a clear order of work and a fixed price before anything starts.

  1. Step 1

    Gap review

    We confirm which frameworks apply to you, what you already have and what is missing, including any insurer or client questionnaire.

  2. Step 2

    Plan and fixed quote

    Gaps in order of risk and deadline, with a fixed quote for project work and a monthly price for ongoing controls.

  3. Step 3

    Controls and policies

    Technical controls rolled out in stages, with policies written to match how your business works.

  4. Quarterly

    Evidence and review

    Evidence kept current for each framework and a quarterly review so nothing drifts before your next renewal or audit.

05Plans and frameworks

Which SecureShield plan supports which framework

Each plan builds on the one before, so you can start where you are and step up when a contract asks for more.

Austin SecureShield plans compared by framework support
Framework supportCoreSecurity operationsControlVisibility and governanceCommandStrategy and vCISO
Essential Eight maturity level maintainedML1ML2
SMB1001 alignmentGold tierDiamond tier
Centralised security event logging (SIEM)
Incident response plan, tested yearly
Ongoing vCISO and board ready reviews
Price$25 per person per month ex GST$60 per person per month ex GST$100 per person per month ex GST

Swipe the table sideways to see every plan.

Every plan includes a quarterly security review and report.

Compare SecureShield plans

06Proof

We hold ourselves to the same standard

We are audited externally too, so our advice comes from experience rather than a template.

01

Certified ourselves

Austin Technology is certified to ISO/IEC 27001 and ISO 9001, audited externally by Compass Assurance Services. We know what an auditor asks for because we answer it too.

Security and governance
02

Palisades

Controls and governance documents aligned to Essential Eight ML1 met a prospective client's security requirements and won the partnership.

Read the case study
03

Powertech

Aligned to Essential Eight ML2 and progressed towards DISP and ISO 27001, then won a defence grade client.

Read the case study

Related services and industries

07Recognised and certified

A top 50 MSP in Australia, three years running

Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.

Cloudtango Top 50 MSP in Australia 2026, 2025 and 2024
Top 50 MSP in Australia Cloudtango, 2024, 2025 and 2026. Assessed on client satisfaction, growth and the depth of our security, support and infrastructure services. Read our client reviews on Cloudtango
An Austin Technology engineer working through alerts at his desk
ISO 27001 certified by Compass Assurance Services

ISO 27001

Information security

Our information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.

How we protect your data
ISO 9001 certified by Compass Assurance Services

ISO 9001

Quality management

Support tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.

08Questions

IT compliance questions

What owners and IT managers ask when a framework lands on their desk. Anything else, call 1300 787 429.

01

Should we start with the Essential Eight, SMB1001 or ISO 27001?

Start with whatever the person asking needs. If nobody has asked yet, Essential Eight ML1 is a sensible base because the other frameworks ask for many of the same controls. SMB1001 suits businesses that want a certificate sized for them. ISO 27001 is the biggest commitment and is often driven by enterprise or overseas clients.

02

Does certification help with cyber insurance?

It helps you answer the proposal form accurately and show evidence for each answer. Whether it changes your premium or cover is a decision for your insurer and broker.

03

How does SMB1001 certification work?

SMB1001 has five levels from Bronze to Diamond. You start at the level that fits your business rather than working through all five. We prepare the controls and evidence, and an independent certifying body issues the certificate after its own review. SecureShield Control aligns to the Gold tier and Command to the Diamond tier.

04

How long does ISO 27001 readiness take?

It depends on your size and how much is already documented. After the gap review we give you a realistic timeline for controls, policies and the evidence an auditor will sample. We have been through certification ourselves, so the plan reflects what auditors ask for.

05

What does compliance support cost?

SecureShield Core is $25 per person per month ex GST. Control is $60 and maintains Essential Eight ML1, and Command is $100 and maintains ML2. Project work such as policy writing or ISO readiness gets a fixed quote.

06

We already have an IT person. What would Austin do?

Your IT person keeps running daily IT. We add the security controls, the evidence and the quarterly reviews. Who owns what is agreed in writing, so nothing is missed at audit time.

09Compliance and risk

Know what applies
before the next questionnaire.

Tell us which frameworks your clients, insurer or tenders ask for. A technical consultant will scope what you have and what is missing, then send a fixed quote.

Or call 1300 787 429

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.