The compliance capability inside our Fractional CIO practice. We stand up an ISMS you can actually operate, close gaps against Annex A, and get you through Stage 1 and Stage 2 audits without the theatre.
Sydney operating base · On-site across NSW · Remote across Australia
Structured review against ISO/IEC 27001:2022 clauses and Annex A. Output: a prioritised gap list with effort, owner and target date.
The full artefact set an assessor expects — scope, policy suite, risk methodology, SoA, procedures — sized to your organisation.
A repeatable risk methodology that maps to real business risks, not a spreadsheet nobody reads. Includes treatment plans with owners.
Practical implementation of the 93 Annex A controls at the depth your risk appetite justifies — no over-engineering.
A rolling internal audit calendar, competency-appropriate auditors, and management review cadence that actually surfaces issues.
Certification body selection guidance, Stage 1 readiness, Stage 2 support and non-conformance response — through to certificate.

Not another consulting firm. Former enterprise CIOs bringing operator-grade cyber and AI leadership to Australian SMEs.
Cyber strategy, compliance and AI sit with one operator who has led technology inside banking, healthcare, higher education and government.
ISO 42001 practitioners. We secure the enterprise for AI before spinning up flashy tools. Frameworks first, tooling second.
Cybersecurity strategy, ISO 27001 and ISO 42001 compliance, and AI consulting delivered as one plan with shared evidence and a single audit cycle.
Sydney-based, delivering across NSW. On-site when it matters, remote-first when it does not.
Every engagement includes FORTE/CYBERx platform access. Our consultants use it live in your board meetings — you keep using it after we leave.
Share the decision or constraint. A senior operator replies within one business day — no sales pod, no scripted discovery.
Run two full decision analyses free, compare practical paths and create a Decision Record and Tactical Plan.
For a mid-sized SME with no prior ISMS, budget six to nine months from kickoff to Stage 2 audit. Faster is possible with an experienced internal team; slower is common when a business tries to do it in the background of everything else.
Annex A was restructured from 114 controls into 93 across four themes (Organisational, People, Physical, Technological), and 11 controls are net new — including threat intelligence, cloud services, data leakage prevention and secure coding.
No. The Statement of Applicability is where you justify which controls apply and why. A good SoA is defensible, not maximalist.
Yes, and it should. We run joint 27001 + 42001 programmes so shared evidence, controls and audit cycles reduce total overhead by 25–40 percent versus running them sequentially.
JAS-ANZ accredited CBs across Australia. We’ll match you to a CB whose auditors know your sector and whose commercial position fits your budget and timeline.
Very common. We’ll shape the scope to the specific client requirement and design the ISMS so it can grow if commercial pressure demands wider coverage later — without a rebuild.
Tell us the decision, constraint or opportunity. A senior operator responds within one business day.