Cyber security compliance in Perth
Compliance you can actually show someone.
The Privacy Act, the Essential Eight, ASIC expectations and cyber insurance forms all end up asking the same thing: can you prove it? We set your IT up properly, then write down the evidence, so the answer is yes.
- Every review Evidence refreshed, not written once and forgotten
- Plain English Policies your staff will actually read
- 0% Offshored. Data questions answered in Perth
ISO/IEC 27001:2022 certified by BSI Check BSI's register for certificate IS 840964
- MFA on every account
- Enforced
- Backups
- Validated
- Incident response plan
- Signed off
- Staff phishing training
- Logged
Proving compliance to insurers and clients
Same question. Very different week.
An insurer, a licensee or a big client asks how you protect their data. Here’s what that looks like with and without the groundwork done. Pick a situation.
Your cyber insurance renewal arrives with a long security questionnaire.
Scrambling for answers
- Forward it to ITThey reply with questions of their own.
- Guess the answers“Do we have MFA on everything?” Probably.
- Tick yes to be safeAnd hope nobody checks.
- Claim at riskA wrong answer can give the insurer grounds to decline.
Premium paid. Cover uncertain.
With CCP
- Send it to usWe answer from what’s actually configured.
- Evidence attachedReports and screenshots, not guesses.
- Gaps flagged plainlyIf an answer is no, we tell you, and how to fix it.
- Back within daysSigned off by you, with nothing to hide.
Every answer true.
A staff mailbox is compromised and client data may be exposed.
Scrambling for answers
- Noticed lateA client asks about a strange invoice email.
- No planWho do we call? What do we check?
- Unsure what leakedLogs weren’t kept long enough to tell.
- Guessing about the OAICIs it notifiable? Nobody knows.
Days of panic.
With CCP
- Contained quicklyAccount locked, sessions revoked, mail rules checked.
- Plan followedYour incident response plan says who does what.
- Scope confirmedSign-in and mailbox logs show what was accessed.
- Assessment documentedThe facts you need to decide on notifying the Office of the Australian Information Commissioner (OAIC) and clients.
Handled, and on record.
A major client sends a supplier security questionnaire.
Scrambling for answers
- Stuck in an inboxNobody’s sure who owns it.
- No policies to attachOr a template from 2017.
- Deadline slipsThe client starts asking questions.
- Work at riskSecurity becomes the reason you lose the contract.
Lost on paperwork.
With CCP
- We draft the answersFrom your documented setup and policies.
- Policies ready to attachCurrent, signed off and specific to you.
- You review and sendPlain English, no overclaiming.
- Kept for next timeAnswers filed in your evidence pack.
Sent on time, and true.
Your licensee asks for evidence of cyber risk controls.
Scrambling for answers
- Hunt for documentsOld policies in someone’s personal drive.
- Ask the IT providerThey send a server list. Not what was asked.
- Answers don’t matchThe policy says MFA. Half the accounts don’t have it.
- Findings to fixNow with a deadline.
Findings, and a deadline.
With CCP
- Evidence pack readyControls, policies and reports in one place.
- Matches realityBecause we configured it, and we check it.
- We attendAn engineer answers the technical questions.
- Improvements plannedAnything outstanding has an owner and a date.
Reviewed without drama.
Cyber security compliance standards in Australia
One set of controls. Every framework.
Most frameworks ask for the same things: multi-factor authentication (MFA), patching, backups, access control and a response plan. We build them once, then map them to each obligation that applies to you.
-
Privacy Act & Notifiable Data Breaches
Reasonable steps to protect personal information, and a tested process to assess and report an eligible data breach.
-
Essential Eight
The Australian Signals Directorate’s (ASD) baseline controls, assessed against the maturity model and uplifted in a practical order.
-
ASIC cyber resilience
Since ASIC v RI Advice (2022), Australian financial services licensees are expected to manage cyber risk adequately. We give you the controls and records to show it.
-
Tax practitioner obligations
ATO security requirements for online services, and the client-data handling expected of registered tax agents.
-
Cyber insurance
Questionnaires answered accurately from what’s configured, so a claim isn’t undone by a wrong tick.
-
Client & supplier due diligence
Security questionnaires from larger clients, answered with evidence rather than optimism.
What’s included in compliance and governance
Governance, without hiring a compliance department.
Practical, documented and kept current. The + Compliance and Complete plans include staff training, vendor reviews and, from 30 seats, the Technology Success Program. Policy and evidence work is quoted as a fixed fee after a free review.
-
Gap assessment
Where you stand against the obligations that apply to you, in plain English.
-
Policies written for you
Information security, acceptable use, access control and incident response. Specific to you, not templates.
-
Incident response plan
Who does what in the first hour, day and week, including data breach assessment steps.
-
Evidence pack
Reports and screenshots showing controls are in place, refreshed at every review.
-
Access reviews
Who can see what, checked regularly. Leavers removed the day they go.
-
Staff training records
Phishing simulations and awareness training, reported so you can show an auditor.
-
Compliance tracking
Obligations from your licensee, insurer and clients tracked in regular Technology Success meetings.
-
Questionnaire support
Insurance, licensee and client forms drafted from real configuration.
-
Partner & board reporting
A short, readable summary of your security posture for decision-makers.
-
Password & MFA hygiene
A managed password manager, and MFA on every account that supports it.
-
Vendor risk checks
Key software and cloud suppliers reviewed for how they handle your data.
-
Controls, not just paperwork
Policies only count if the settings match. Our security team does the technical work.
Client reviews of our compliance work
Law firms trust us with client confidentiality.
“Tim identified and rectified the issues straight away… I highly recommend CCP for their knowledge and prompt support.”
How a compliance gap assessment works
From “are we compliant?” to “here’s the proof.”
No 200-page report. A clear list of what to fix, in the order that matters.
-
Step 1 · Free
A compliance conversation
45 minutes on which obligations apply to you, and a light-touch check of the controls behind them.
-
Step 2 · Within a week
Gap report and fixed quote
What’s in place, what’s missing and what matters most, in priority order and plain English.
-
Step 3 · Ongoing
Build, evidence, review
We close the gaps, write it down and refresh your evidence at every review.
Cyber security compliance questions
Straight answers.
Does the Privacy Act apply to my business?
Do we need Essential Eight Maturity Level Three?
Can you guarantee we’re compliant?
Do you replace our compliance manager or lawyer?
How much does compliance support cost?
Know where you stand before someone asks.
Book a free 45-minute compliance review with a Perth engineer. You get a plain-English summary of which obligations apply, what’s in place and what’s missing. It’s yours to keep either way.
Or call (08) 9467 2269
We hold ISO/IEC 27001:2022 certification from BSI, certificate IS 840964.