How much does ISO 27001 certification cost in Australia and how long does it take? A 2026 breakdown of consultant fees, certification body audit costs and timeframes. Typically $15,000-$30,000 and 3-6 months for a small to medium business.
Tag: #informationsecurity
Your Supplier Lost the Data. The Notification Is Still Yours.
The Quest Apartment Hotels breach shows why outsourcing customer data does not outsource responsibility, and what ISO 27001 expects from third-party risk management.
Your Visitor Policy Says No Cameras. Your Visitors Are Wearing Them.
The Privacy Commissioner has put surveillance wearables on the record. Your visitor rules assume the camera is a phone, and ISO 27001 Annex A 7.6 assumes you can see it.
What Your Data Breach Response Plan Has to Prove, and the 72-Hour Clock Coming With It
Some organisations have a data breach response plan. Few can show it has ever been tested. The privacy exposure draft released on 31 August 2026 would make that gap explicit, and add a 72-hour clock to the existing 30-day one.
Securing Personal Information Under APP 11.3: Where ISO 27001 and ISO 42001 Fit
Australia’s new APP 11.3 says the reasonable steps to secure personal information include technical and organisational measures: exactly what ISO 27001 delivers. Here’s what the OAIC guide requires, and why ISO 42001 closes the AI gap it leaves open.
Origin Says the Breach Is “Potential”. That Word Starts a 30-Day Clock.
Origin Energy said on 22 July that it is “currently investigating a potential security incident which may involve unauthorised access to some customers’ data”. It added that it does not believe the affected data includes credit card or bank details, and that it has notified the Australian Cyber Security Centre and the Australian Federal Police. […]
Cyber Security Awareness Training: What Clause 7.3 Requires (and the Best Free Resources)
Awareness is a certifiable requirement: clause 7.3 of both ISO 27001 and ISO 42001. How cyber threats have evolved beyond the office, and two free resources (KnowBe4 CAPY and cyber.gov.au) that build a security-aware team at work and at home.
Which AI Tools Are ISO 42001 Certified, and How to Stop Them Training on Your Data
AI tools are now woven through everyday business: drafting emails, summarising documents, writing code. For anyone responsible for governance, two questions matter more than which model is “best”: is the provider certified to manage AI responsibly, and is your data being used to train their models? The answers vary a lot between tools, and between […]
The ACSC Just Handed Your IT Provider a Question. Do You Know How to Ask It?
There is a line in the alert ASD’s Australian Cyber Security Centre published today that most people will skim past. It says the alert “is intended for a technical audience”. A few lines on: “Small to medium business should engage with their MSP or Enterprise IT provider to understand if they use the N-able N-central […]
The Logins You Forgot to Turn Off
ASD and the AICD have told boards that AI agents need minimum access. Most access reviews only list people. What to check, and a free checklist.
- 1
- 2
- 3
- …
- 5
- Next Page »












