Security and governance

Security and governance, built in

We are an ISO 27001 and ISO 9001 certified IT provider, audited externally by Compass Assurance Services. Every control we recommend to you is one we run on our own business first.

Your price in two minutes, no email needed. Or call 1300 787 429.

Austin Technology engineer reviewing a client environment in the Subiaco office
ISO 27001 certifiedCompass Assurance Services
  • ISO27001 and 9001 certified, externally audited
  • 24/7Threat monitoring and response on SecureShield plans
  • WAHosted workloads and primary backups stay onshore
  • QuarterlyEssential Eight scoring for every managed client

Trusted by security conscious businesses across WA

thyssenkruppFLSmidthInterContinental EnergyAlliance NickelCarers WAAcclaim AccountingKoch SolutionsCallidus Process Solutions

01Why it matters

What our certifications mean for you

Certification is not a badge for the website. It means an independent auditor checks every year that we manage security and quality the way we say we do.

01

Easier supplier due diligence

When your clients, insurer or auditor ask how your IT provider manages security, you can point to an audited, certified system.

Ask us for copies of our certificates
02

Consistent service

Logging, triage, escalation and change follow documented processes, so quality does not depend on who picks up the ticket.

ISO 9001 quality management
03

Security that is managed, not assumed

Risks are assessed, controls are reviewed and incidents are handled against a documented plan.

ISO 27001 information security

02Our own operations

The controls we run on our own business

You are trusting us with privileged access to your systems. This is how we protect that access.

01

Single sign on and MFA

Our core management platforms sit behind Microsoft Entra ID single sign on, with MFA enforced and passkeys on our most sensitive systems.

Microsoft Entra ID
02

A separate management network

Administrative access to our hosted platforms runs through a VPN and jump host, kept apart from our corporate network.

VPN and jump host
03

Granular Microsoft 365 access

We manage client Microsoft 365 tenants through Microsoft GDAP, which gives engineers specific delegated roles rather than blanket access.

Microsoft GDAP
04

Immutable backups

Our hosted platforms back up to object storage with 30 day immutability, so backups cannot be altered or deleted within that window.

30 day immutability
05

Logging and change control

Critical systems and alerts are logged centrally, and high risk changes follow a documented approval process with peer review where needed.

Peer review for high risk work
06

Incident response and insurance

A written incident response plan with named roles and an out of band way to coordinate, with cyber liability insurance behind it.

Named roles, out of band contact

03Data sovereignty

Your hosted data stays in Western Australia

AustinCloud, our private cloud, runs in Perth datacentres. Hosted workloads and their primary backups stay onshore in WA, close to your users and under Australian law.

Austin Technology office building at 541 Hay Street, Subiaco
Our office, Level 2, 541 Hay Street, Subiaco
  1. 01
    NextDC P1

    Colocation for AustinCloud infrastructure.

  2. 02
    NextDC P2

    Private cloud and our immutable backup repository.

  3. 03
    Vocus

    Private cloud compute and storage.

  4. 04
    Microsoft 365

    Data for Australian tenants is stored in Microsoft's Australian datacentres.

Run by a locally based, Australian owned business.

Cloud services
Harman KaurKrishna MoothooJamie WebbGregory Ashley

Want to know what working with us looks like?

Tell us how IT runs today. A technical consultant will scope it with you and send a fixed quote.

04Governance

Practical governance for growing organisations

Structure and evidence your leadership team can use, not a pile of documents nobody reads. These are the obligations we help clients prepare for most often.

Obligations Austin Technology helps clients prepare for
ObligationWhat it asks of youHow we help
Privacy Act and Notifiable Data BreachesAssess a suspected breach quickly, and notify the OAIC and affected people when it is eligibleControls that reduce breach risk, plus the logs and evidence to work out what happened
Ransomware payment reportingBusinesses over $3 million turnover must report a ransomware payment to ASD within 72 hours under the Cyber Security Act 2024Built into your incident response plan, with the details you need to report
Cyber insuranceAccurate answers on MFA, backups, endpoint protection and patchingAnswers backed by evidence from your own systems
Essential EightA maturity level your clients, insurer or a tender asks forAssessment, uplift and a score every quarter
DISPGovernance, personnel, physical and cyber security for Defence workThe cyber controls and the evidence behind them
SMB1001A tiered certification written for small and medium businessesControls mapped to your tier through our SecureShield plans

We handle the technical controls and evidence. For legal interpretation we work alongside your legal advisers.

We also set up the basics: clear roles between your team and ours, policies staff can read, a risk register and an incident response plan that says who does what.

Cyber security services

05How we report it

Security you can watch improve

We score your environment against the Essential Eight when we start and show you how it moves every quarter. This is what the scorecard looks like.

Sample Essential Eight scorecard with illustrative maturity levels
Mitigation strategy SampleML1BaselineML2TargetML3Advanced
Patch applications
Patch operating systems
Multi factor authentication
Restrict administrative privilegesIn progress
Application control
Restrict Microsoft Office macros
User application hardeningIn progress
Regular backups

Sample client for illustration. Your scorecard uses your own environment and is reviewed with you every quarter. How our Essential Eight service works.

06Results

Security work that stood up to scrutiny

Audits passed, client requirements met and contracts won on the back of it.

01

InterContinental Energy

Reached Essential Eight Maturity Level 1 using the Microsoft 365 licensing they already owned.

Read the case study
02

Powertech

Aligned to Essential Eight Maturity Level 2 and progressed towards DISP, which helped them win a defence grade client.

Read the case study
03

Palisades

Rebuilt a legacy setup around Intune, conditional access and the Essential Eight, helping them secure a new client partnership.

Read the case study

07Questions

Security and compliance questions

What clients, insurers and auditors ask us. Anything else, call 1300 787 429.

01

Is Austin Technology ISO 27001 certified?

Yes. We are certified to ISO/IEC 27001 for information security management and ISO 9001 for quality management. Both are audited externally by Compass Assurance Services, and we can share copies of our certificates for your supplier register.

02

Where is our data stored?

Workloads we host in AustinCloud run in Perth datacentres, and so do their primary backups. Microsoft 365 data for Australian tenants sits in Microsoft's Australian datacentres.

03

How do you protect your own access to our systems?

Our management platforms sit behind single sign on with MFA enforced, administrative access to hosted platforms runs through a separate management network, and we manage Microsoft 365 through GDAP so engineers get specific roles rather than blanket access.

04

Can you help with our cyber insurance questionnaire?

Yes. We help you answer accurately and back each answer with evidence from your systems, which matters if you ever need to make a claim.

05

What happens if we have a cyber incident?

We follow a documented incident response plan: contain the threat, restore critical systems, investigate the cause and close the gaps. We support any reporting you need to do, including notifiable data breaches and ransomware payment reports, and review the event with you afterwards.

06

Do you hold cyber insurance?

Yes. We hold cyber liability insurance as part of how we manage our own risk.

08Security and governance

Check our security
before you trust us.

Ask for our certificates. Then tell us about your own security and a technical consultant will scope what you need and send a fixed quote.

Or call 1300 787 429

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.