Security and governance
Security and governance, built in
We are an ISO 27001 and ISO 9001 certified IT provider, audited externally by Compass Assurance Services. Every control we recommend to you is one we run on our own business first.
Your price in two minutes, no email needed. Or call 1300 787 429.

- ISO27001 and 9001 certified, externally audited
- 24/7Threat monitoring and response on SecureShield plans
- WAHosted workloads and primary backups stay onshore
- QuarterlyEssential Eight scoring for every managed client
Trusted by security conscious businesses across WA








01Why it matters
What our certifications mean for you
Certification is not a badge for the website. It means an independent auditor checks every year that we manage security and quality the way we say we do.
Easier supplier due diligence
When your clients, insurer or auditor ask how your IT provider manages security, you can point to an audited, certified system.
Ask us for copies of our certificatesConsistent service
Logging, triage, escalation and change follow documented processes, so quality does not depend on who picks up the ticket.
ISO 9001 quality managementSecurity that is managed, not assumed
Risks are assessed, controls are reviewed and incidents are handled against a documented plan.
ISO 27001 information security02Our own operations
The controls we run on our own business
You are trusting us with privileged access to your systems. This is how we protect that access.
Single sign on and MFA
Our core management platforms sit behind Microsoft Entra ID single sign on, with MFA enforced and passkeys on our most sensitive systems.
Microsoft Entra IDA separate management network
Administrative access to our hosted platforms runs through a VPN and jump host, kept apart from our corporate network.
VPN and jump hostGranular Microsoft 365 access
We manage client Microsoft 365 tenants through Microsoft GDAP, which gives engineers specific delegated roles rather than blanket access.
Microsoft GDAPImmutable backups
Our hosted platforms back up to object storage with 30 day immutability, so backups cannot be altered or deleted within that window.
30 day immutabilityLogging and change control
Critical systems and alerts are logged centrally, and high risk changes follow a documented approval process with peer review where needed.
Peer review for high risk workIncident response and insurance
A written incident response plan with named roles and an out of band way to coordinate, with cyber liability insurance behind it.
Named roles, out of band contact03Data sovereignty
Your hosted data stays in Western Australia
AustinCloud, our private cloud, runs in Perth datacentres. Hosted workloads and their primary backups stay onshore in WA, close to your users and under Australian law.

- 01NextDC P1
Colocation for AustinCloud infrastructure.
- 02NextDC P2
Private cloud and our immutable backup repository.
- 03Vocus
Private cloud compute and storage.
- 04Microsoft 365
Data for Australian tenants is stored in Microsoft's Australian datacentres.
Run by a locally based, Australian owned business.
Cloud services



Want to know what working with us looks like?
Tell us how IT runs today. A technical consultant will scope it with you and send a fixed quote.
04Governance
Practical governance for growing organisations
Structure and evidence your leadership team can use, not a pile of documents nobody reads. These are the obligations we help clients prepare for most often.
| Obligation | What it asks of you | How we help |
|---|---|---|
| Privacy Act and Notifiable Data Breaches | Assess a suspected breach quickly, and notify the OAIC and affected people when it is eligible | Controls that reduce breach risk, plus the logs and evidence to work out what happened |
| Ransomware payment reporting | Businesses over $3 million turnover must report a ransomware payment to ASD within 72 hours under the Cyber Security Act 2024 | Built into your incident response plan, with the details you need to report |
| Cyber insurance | Accurate answers on MFA, backups, endpoint protection and patching | Answers backed by evidence from your own systems |
| Essential Eight | A maturity level your clients, insurer or a tender asks for | Assessment, uplift and a score every quarter |
| DISP | Governance, personnel, physical and cyber security for Defence work | The cyber controls and the evidence behind them |
| SMB1001 | A tiered certification written for small and medium businesses | Controls mapped to your tier through our SecureShield plans |
We handle the technical controls and evidence. For legal interpretation we work alongside your legal advisers.
We also set up the basics: clear roles between your team and ours, policies staff can read, a risk register and an incident response plan that says who does what.
Cyber security services05How we report it
Security you can watch improve
We score your environment against the Essential Eight when we start and show you how it moves every quarter. This is what the scorecard looks like.
| Mitigation strategy Sample | ML1Baseline | ML2Target | ML3Advanced |
|---|---|---|---|
| Patch applications | |||
| Patch operating systems | |||
| Multi factor authentication | |||
| Restrict administrative privileges | In progress | ||
| Application control | |||
| Restrict Microsoft Office macros | |||
| User application hardening | In progress | ||
| Regular backups |
Sample client for illustration. Your scorecard uses your own environment and is reviewed with you every quarter. How our Essential Eight service works.
06Results
Security work that stood up to scrutiny
Audits passed, client requirements met and contracts won on the back of it.
InterContinental Energy
Reached Essential Eight Maturity Level 1 using the Microsoft 365 licensing they already owned.
Read the case studyPowertech
Aligned to Essential Eight Maturity Level 2 and progressed towards DISP, which helped them win a defence grade client.
Read the case studyPalisades
Rebuilt a legacy setup around Intune, conditional access and the Essential Eight, helping them secure a new client partnership.
Read the case study07Questions
Security and compliance questions
What clients, insurers and auditors ask us. Anything else, call 1300 787 429.
01Is Austin Technology ISO 27001 certified?
Yes. We are certified to ISO/IEC 27001 for information security management and ISO 9001 for quality management. Both are audited externally by Compass Assurance Services, and we can share copies of our certificates for your supplier register.
02Where is our data stored?
Workloads we host in AustinCloud run in Perth datacentres, and so do their primary backups. Microsoft 365 data for Australian tenants sits in Microsoft's Australian datacentres.
03How do you protect your own access to our systems?
Our management platforms sit behind single sign on with MFA enforced, administrative access to hosted platforms runs through a separate management network, and we manage Microsoft 365 through GDAP so engineers get specific roles rather than blanket access.
04Can you help with our cyber insurance questionnaire?
Yes. We help you answer accurately and back each answer with evidence from your systems, which matters if you ever need to make a claim.
05What happens if we have a cyber incident?
We follow a documented incident response plan: contain the threat, restore critical systems, investigate the cause and close the gaps. We support any reporting you need to do, including notifiable data breaches and ransomware payment reports, and review the event with you afterwards.
06Do you hold cyber insurance?
Yes. We hold cyber liability insurance as part of how we manage our own risk.
08Security and governance
Check our security
before you trust us.
Ask for our certificates. Then tell us about your own security and a technical consultant will scope what you need and send a fixed quote.
Or call 1300 787 429