Governance and compliance · Australia-wide

IT Governance and Compliance
for Small and Medium Businesses

Insurers, clients and tender panels want evidence that your business is secure. We put the controls in place, write the policies and keep the evidence ready for the Essential Eight, SMB1001 and the Privacy Act.

  • SMB1001 Gold achieved
  • Plain-English policies
  • Evidence kept current
SEQ IT technician working through a laptop with two clients
Bronze to Gold

As a CyberCert Certification Partner, we take clients through SMB1001 Bronze, Silver and Gold.

SMB1001 Gold

Achieved through CyberCert

CyberCert

Certification Partner

20+ years

Team experience in IT and security

300+

Businesses supported

The reality

Compliance has become a commercial question

Compliance used to be a worry for big companies and government. Now the questions reach small businesses through insurance renewals, client contracts and tenders, and they assume you employ an IT security manager.

We work out which obligations apply to you, then do the work: controls, policies and evidence that hold up when someone checks.

Where the pressure comes from
  • An insurer questionnaire about MFA, EDR and tested backups
  • A client security questionnaire before a contract is signed
  • A tender that asks for a recognised certification
  • Privacy Act obligations if you hold health or personal information
  • An incident that showed how little was written down
IT policies

Policies your team will actually follow

Every framework and most insurers expect written policies. Without them you can’t show compliance, however good your technical controls are. We write them in plain English, match them to how your business works, back each one with the controls that enforce it and review them when things change.

  • Cyber security policy
  • Acceptable use policy
  • Password policy
  • Incident response plan
  • Backup and recovery policy
  • AI use policy
  • Data breach response plan
  • Remote work policy
  • Data classification policy
  • Supplier and third-party policy
SEQ IT technician helping a client with her laptop at her desk
What makes a policy work
  • Short enough that staff read it
  • Specific to your systems and people
  • Enforced by technical controls where possible
  • Approved by a director
  • Reviewed at least once a year

Find out where you stand

Our free cyber security assessment checks your controls against the frameworks that matter to your business and gives you a prioritised plan. Valued at $2,500, no obligation.

Where to start

Which framework fits your situation?

Not every business needs every framework. Here’s how the request usually maps to the work.

Your situation
What it usually means
Start with
Your insurer sent a security questionnaire

Controls such as MFA, EDR, patching and tested backups, with evidence

Cyber insurance readiness
A client or tender wants proof of security

A recognised certificate you can show

SMB1001 certification
You want a solid technical baseline

The ASD strategies at an agreed maturity level

Essential Eight alignment
You hold health records or other personal information

Privacy Act obligations and a plan for notifiable breaches

Privacy and NDB readiness
You are unsure how long you could trade without IT

Recovery targets and a tested plan

Business continuity planning
A client requires ISO 27001 or a formal risk programme

Specialist work beyond our scope

Referral to a GRC specialist

Not sure which row fits? Read what GRC means for a small business.

How it works

Our compliance process

01
Discover

Identify your obligations

We look at your industry, clients, insurer and the data you hold, and work out which frameworks actually apply.

02
Assess

Find the gaps

We check your environment against those frameworks and give you a prioritised action plan in plain English.

03
Implement

Fix and document

We implement the technical controls, write the policies and train your staff. Projects are quoted before work starts.

04
Maintain

Keep it current

We maintain the controls, refresh policies and keep evidence ready for renewals, questionnaires and certification.

Our scope

Where we stop and specialists take over

We deliver the operational and compliance foundations: technical controls, policies, documentation and the evidence insurers and frameworks ask for. That covers what most small and medium businesses actually face.

Formal frameworks such as ISO 27001, an outsourced chief information security officer (CISO) and enterprise risk management are specialist work. We refer that work to trusted Australian GRC specialists and keep running your day-to-day IT and security.

SEQ IT technician reviewing a laptop setup with a client

Do you need ISO 27001?

Most small businesses don’t. SMB1001 and the Essential Eight usually cover what clients and insurers ask for, and we’ll tell you honestly if you have outgrown them.

New to GRC?

Our plain-English guide explains governance, risk and compliance and the four stages most businesses move through.

Our credentials

Compliance we practise ourselves

SEQ IT achieved SMB1001 Gold through CyberCert and is a CyberCert Certification Partner, so the controls and evidence we prepare for you match what we maintain ourselves.

SMB1001 Gold certification badge

SMB1001 Gold

CyberCert logo

Certification Partner

Microsoft logo

Partner and Cloud Solution Provider (CSP)

Google Cloud logo

Google Cloud Partner

FAQ

Governance and compliance: common questions

Probably more than you think. The Privacy Act covers all health service providers regardless of turnover and other businesses with annual turnover over $3 million, plus some specific cases. Your cyber insurance policy likely expects certain controls, and clients may ask for proof of security before they sign.

That is outside our scope. ISO 27001 projects, formal GRC programmes and enterprise risk management are referred to trusted Australian GRC specialists, and we can keep running your IT and security alongside them. For many small businesses, SMB1001 covers what clients are actually asking for.

Yes, it’s one of the most common reasons businesses call us. We put in place the controls insurers ask about, such as multi-factor authentication, EDR, patching and tested backups, then help you answer the questionnaire accurately. Your insurer still decides on cover and premiums.

Most frameworks and insurers expect a cyber security policy, acceptable use policy, password policy, incident response plan and backup and recovery policy. If staff use tools like ChatGPT, Copilot or Gemini, add an AI use policy. Businesses holding personal information also need a data breach response plan.

Not directly. SMB1001 certification is issued through CyberCert, and we prepare and lodge your application as a Certification Partner. The Essential Eight has no certificate, only maturity levels. For the Privacy Act and insurance, we help you meet the requirements, but the regulator and insurer make their own decisions.

Projects are quoted on scope: which framework, how far you have to go and how big your environment is. For clients on our managed IT or managed security services, much of the technical work is already done. The first assessment is free, and there are no lock-in contracts.

Get started

Get a clear view of your obligations

Tell us who is asking: your insurer, a client, a tender panel or your own board. We’ll work out which frameworks apply and what it would take to meet them.

  • Which obligations actually apply to you
  • The gaps, in priority order
  • A quoted plan with no lock-in contract

Prefer to talk? Call 1300 619 750, Monday to Friday.

Talk to us

Tell us what you need. We’ll get back to you within one business day.