How much does ISO 27001 certification cost in Australia and how long does it take? A 2026 breakdown of consultant fees, certification body audit costs and timeframes. Typically $15,000-$30,000 and 3-6 months for a small to medium business.
Tag: #iso27001
Your Supplier Lost the Data. The Notification Is Still Yours.
The Quest Apartment Hotels breach shows why outsourcing customer data does not outsource responsibility, and what ISO 27001 expects from third-party risk management.
Your Visitor Policy Says No Cameras. Your Visitors Are Wearing Them.
The Privacy Commissioner has put surveillance wearables on the record. Your visitor rules assume the camera is a phone, and ISO 27001 Annex A 7.6 assumes you can see it.
What Your Data Breach Response Plan Has to Prove, and the 72-Hour Clock Coming With It
Some organisations have a data breach response plan. Few can show it has ever been tested. The privacy exposure draft released on 31 August 2026 would make that gap explicit, and add a 72-hour clock to the existing 30-day one.
Securing Personal Information Under APP 11.3: Where ISO 27001 and ISO 42001 Fit
Australia’s new APP 11.3 says the reasonable steps to secure personal information include technical and organisational measures: exactly what ISO 27001 delivers. Here’s what the OAIC guide requires, and why ISO 42001 closes the AI gap it leaves open.
Origin Says the Breach Is “Potential”. That Word Starts a 30-Day Clock.
Origin Energy said on 22 July that it is “currently investigating a potential security incident which may involve unauthorised access to some customers’ data”. It added that it does not believe the affected data includes credit card or bank details, and that it has notified the Australian Cyber Security Centre and the Australian Federal Police. […]
Cyber Security Awareness Training: What Clause 7.3 Requires (and the Best Free Resources)
Awareness is a certifiable requirement: clause 7.3 of both ISO 27001 and ISO 42001. How cyber threats have evolved beyond the office, and two free resources (KnowBe4 CAPY and cyber.gov.au) that build a security-aware team at work and at home.
The ACSC Just Handed Your IT Provider a Question. Do You Know How to Ask It?
There is a line in the alert ASD’s Australian Cyber Security Centre published today that most people will skim past. It says the alert “is intended for a technical audience”. A few lines on: “Small to medium business should engage with their MSP or Enterprise IT provider to understand if they use the N-able N-central […]
The Logins You Forgot to Turn Off
ASD and the AICD have told boards that AI agents need minimum access. Most access reviews only list people. What to check, and a free checklist.
The Pen Test Found It in 2020. The Regulator Found It in 2026.
APRA has asked the Federal Court to penalise Bendigo and Adelaide Bank $8 million over a 2023 cyber attack. Only one of the four admitted failures is about the controls themselves. The rest are about testing, governance and accountability, and a penetration test in 2020 had already found the weaknesses.
- 1
- 2
- 3
- 4
- Next Page »












