IT Governance and Compliance
for Small and Medium Businesses
Insurers, clients and tender panels want evidence that your business is secure. We put the controls in place, write the policies and keep the evidence ready for the Essential Eight, SMB1001 and the Privacy Act.
- SMB1001 Gold achieved
- Plain-English policies
- Evidence kept current

As a CyberCert Certification Partner, we take clients through SMB1001 Bronze, Silver and Gold.
Achieved through CyberCert
Certification Partner
Team experience in IT and security
Businesses supported
Compliance has become a commercial question
Compliance used to be a worry for big companies and government. Now the questions reach small businesses through insurance renewals, client contracts and tenders, and they assume you employ an IT security manager.
We work out which obligations apply to you, then do the work: controls, policies and evidence that hold up when someone checks.
- An insurer questionnaire about MFA, EDR and tested backups
- A client security questionnaire before a contract is signed
- A tender that asks for a recognised certification
- Privacy Act obligations if you hold health or personal information
- An incident that showed how little was written down
Compliance foundations, done properly
Each piece stands on its own. Most clients start with one and add the rest over time.
Essential Eight alignment
We assess your maturity against the ASD’s eight mitigation strategies, implement the controls and agree a realistic target, usually Maturity Level 1 or 2.
SMB1001 certification
As a CyberCert Certification Partner that achieved Gold itself, we take you through Bronze, Silver and Gold, from gap analysis to submission.
Privacy Act and NDB readiness
Controls around personal information, plus a data breach response plan, so you can assess a breach quickly and meet the Notifiable Data Breaches scheme if it applies.
Cyber insurance readiness
We put the controls insurers ask about in place and help you answer the questionnaire accurately, with evidence behind each answer.
Business continuity
A business impact analysis, recovery targets and a written plan your team can follow, tested before you need it.
Evidence and documentation
Configuration reports, training records and policy versions, kept in one place and ready when an insurer, client or certifier asks.
Policies your team will actually follow
Every framework and most insurers expect written policies. Without them you can’t show compliance, however good your technical controls are. We write them in plain English, match them to how your business works, back each one with the controls that enforce it and review them when things change.
- Cyber security policy
- Acceptable use policy
- Password policy
- Incident response plan
- Backup and recovery policy
- AI use policy
- Data breach response plan
- Remote work policy
- Data classification policy
- Supplier and third-party policy

- Short enough that staff read it
- Specific to your systems and people
- Enforced by technical controls where possible
- Approved by a director
- Reviewed at least once a year
Find out where you stand
Our free cyber security assessment checks your controls against the frameworks that matter to your business and gives you a prioritised plan. Valued at $2,500, no obligation.
Which framework fits your situation?
Not every business needs every framework. Here’s how the request usually maps to the work.
Controls such as MFA, EDR, patching and tested backups, with evidence
A recognised certificate you can show
The ASD strategies at an agreed maturity level
Privacy Act obligations and a plan for notifiable breaches
Recovery targets and a tested plan
Specialist work beyond our scope
Not sure which row fits? Read what GRC means for a small business.
Our compliance process
Identify your obligations
We look at your industry, clients, insurer and the data you hold, and work out which frameworks actually apply.
Find the gaps
We check your environment against those frameworks and give you a prioritised action plan in plain English.
Fix and document
We implement the technical controls, write the policies and train your staff. Projects are quoted before work starts.
Keep it current
We maintain the controls, refresh policies and keep evidence ready for renewals, questionnaires and certification.
Where we stop and specialists take over
We deliver the operational and compliance foundations: technical controls, policies, documentation and the evidence insurers and frameworks ask for. That covers what most small and medium businesses actually face.
Formal frameworks such as ISO 27001, an outsourced chief information security officer (CISO) and enterprise risk management are specialist work. We refer that work to trusted Australian GRC specialists and keep running your day-to-day IT and security.

Do you need ISO 27001?
Most small businesses don’t. SMB1001 and the Essential Eight usually cover what clients and insurers ask for, and we’ll tell you honestly if you have outgrown them.
New to GRC?
Our plain-English guide explains governance, risk and compliance and the four stages most businesses move through.
Compliance we practise ourselves
SEQ IT achieved SMB1001 Gold through CyberCert and is a CyberCert Certification Partner, so the controls and evidence we prepare for you match what we maintain ourselves.

SMB1001 Gold

Certification Partner

Partner and Cloud Solution Provider (CSP)

Google Cloud Partner
Governance and compliance: common questions
Does my small business have to comply with anything?
Probably more than you think. The Privacy Act covers all health service providers regardless of turnover and other businesses with annual turnover over $3 million, plus some specific cases. Your cyber insurance policy likely expects certain controls, and clients may ask for proof of security before they sign.
Can you help us get ISO 27001 certified?
That is outside our scope. ISO 27001 projects, formal GRC programmes and enterprise risk management are referred to trusted Australian GRC specialists, and we can keep running your IT and security alongside them. For many small businesses, SMB1001 covers what clients are actually asking for.
Our insurer is asking about our security controls. Can you help?
Yes, it’s one of the most common reasons businesses call us. We put in place the controls insurers ask about, such as multi-factor authentication, EDR, patching and tested backups, then help you answer the questionnaire accurately. Your insurer still decides on cover and premiums.
What IT policies does a small business need?
Most frameworks and insurers expect a cyber security policy, acceptable use policy, password policy, incident response plan and backup and recovery policy. If staff use tools like ChatGPT, Copilot or Gemini, add an AI use policy. Businesses holding personal information also need a data breach response plan.
Can you certify us as compliant?
Not directly. SMB1001 certification is issued through CyberCert, and we prepare and lodge your application as a Certification Partner. The Essential Eight has no certificate, only maturity levels. For the Privacy Act and insurance, we help you meet the requirements, but the regulator and insurer make their own decisions.
How much does compliance work cost?
Projects are quoted on scope: which framework, how far you have to go and how big your environment is. For clients on our managed IT or managed security services, much of the technical work is already done. The first assessment is free, and there are no lock-in contracts.
Explore governance and compliance
What is GRC?
Governance, risk and compliance explained for small businesses.
Essential Eight
Where you sit on the ASD maturity model.
SMB1001 certification
Bronze, Silver and Gold with a CyberCert Certification Partner.
Cyber insurance readiness
Controls and evidence for your insurer’s questionnaire.
Business continuity planning
Recovery targets and a plan your team has tested.
Data backup and recovery
Monitored, test-restored backups for cloud, devices and servers.
Get a clear view of your obligations
Tell us who is asking: your insurer, a client, a tender panel or your own board. We’ll work out which frameworks apply and what it would take to meet them.
- Which obligations actually apply to you
- The gaps, in priority order
- A quoted plan with no lock-in contract
Prefer to talk? Call 1300 619 750, Monday to Friday.
Tell us what you need. We’ll get back to you within one business day.
