Skip to main content
Aegentra

For Australian organisations

ISO consulting, internal audit and Microsoft 365 security.

Aegentra implements ISO 27001 and ISO 42001 management systems, conducts separately scoped internal audits, and strengthens Microsoft 365 security for Australian organisations. Our services also cover risk reviews, SOX ITGC testing, email and data protection, and ongoing IT support.

See an ISO 27001 internal-audit engagement

Internal audits are separately scoped where objectivity can be preserved. Certification decisions remain with an independent accredited certification body.

Melbourne & Sydney teams · Australia-wide delivery
Delivery arrangements confirmed for each service.

Implementation work follows the agreed scope, responsibilities and evidence plan.

/ Our Capabilities

Consulting, training and exam preparation.

Organisations engage Aegentra to build and audit management systems. Professionals use Aegentra Academy for official training. Exam candidates practise separately in Aegentra Labs.

Director-ledDirect senior oversight from scope through delivery
Case studySee a documented ISO 27001 internal-audit engagement

Internal audit and controls assurance

Independent internal audits across four ISO management systems.

We sample operating evidence, document findings and support corrective-action close-out. Certification and external attestation remain with the relevant independent external body.

  • Fixed scope
  • Australia-wide
  • Independent by design

Security and IT operations

Training and exam preparation

/ Case studies

See the evidence behind the work.

Engagement records and clearly labelled illustrative composites. Open a study to review its scope, method, evidence and delivery boundaries.

AegentraAugust 2026

ISO/IEC

42001:2023

Readiness

recovery

Certification under pressure: an eight-week AIMS recovery programme

Prepared by

Aegentra Information Security & Compliance Team

ISO/IEC 42001 · Certification readiness

Engagement record

ISO 42001 certification under pressure

Read case study

ISO/IEC 42001 · AI management system

Illustrative composite

The AI policy was signed by the board. The AI committee did not exist.

Read case study

Swipe, use a trackpad, arrow keys or the controls above.

View all case studies

/ The Aegentra Standard

Uncompromising security engineering for highly-regulated environments.

Three non-negotiables behind every Aegentra engagement.

Skyscrapers photographed from below

Identity

Zero Trust Architecture

Identity and device controls are selected, configured and verified against the agreed scope and available licences.

A row of server cabinets in a data centre

Evidence

Traceable evidence

Supported configuration evidence sits alongside operating records, interviews and accountable management review.

Two engineers reviewing code together

Accountability

Principal-led delivery

Principal-led delivery informed by ISO 27001 and Essential Eight implementation work in government and regulated environments.

/ Aegentra Academy

Master the standardsthat govern the industry.

Aegentra Academy delivers official PECB training for professionals worldwide across ISO 27001, ISO 42001, privacy, risk, SOC 2, AI governance and hands-on cybersecurity. PECB supplies the official material and examination, then awards the applicable professional credential when its requirements are met. Aegentra handles enrolment, delivery options and learner support as an official authorised training partner.

/ Insights

Written from delivery experience.

Practical Microsoft 365 security, ISO 27001 and IT-operations guidance for Australian SMEs — the same advice we give clients.

All insights
  • How long does ISO 27001 readiness take, and what does it cost?

    Aegentra may target an approximately 12-week implementation programme for an appropriately scoped, Microsoft 365-first organisation with sufficient leadership availability and no major remediation blockers. This is a planning assumption, not a guarantee. Timing depends on the ISMS boundary, starting maturity, technical complexity, evidence availability, client decisions, remediation, internal-audit arrangements and the certification body’s schedule. The written proposal records the actual delivery plan and dependencies.

  • We don’t have a Big-Four budget — but our internal IT can’t do this alone. Where do we fit?

    Organisations that need practical security or governance support can agree a scope suited to their existing team and systems. There is no universal minimum customer size: each service has its own eligibility, evidence and complexity assumptions. The proposal identifies the assigned people, responsibilities and fee.

  • How fast can our Microsoft 365 tenant actually be hardened?

    The scope and timetable are confirmed after assessing licences, permissions, current configuration, business dependencies and the changes approved by your team. Implementation uses agreed pilots, change approvals, rollback arrangements, verification and handover. An assessment or ongoing support contract does not automatically include every technical change.

  • After ISO 27001 readiness, who stops the controls from rotting?

    Controls can drift when ownership, review and evidence collection stop. Aegentra On-Demand IT can be scoped to support Microsoft 365 administration, incidents and recurring Aeges reviews, with response hours and responsibilities agreed in writing.

  • Does On-demand IT replace our internal team, or sit alongside it?

    Either. The service can be scoped as an outsourced Microsoft 365 support function or as named escalation support alongside an internal team. Coverage, responsibilities and exclusions are agreed before the month-to-month service begins.

  • Where does our data go during an Aeges scan?

    Assessment reads supported Microsoft 365 configuration. Writing reports to an agreed SharePoint location is a separate permission and action; read-only assessment does not mean no report writes. Before access is approved, confirm the data categories, permissions, processing and storage locations, report destination and retention arrangements in the engagement scope.

  • Do you provide the certification audit yourselves?

    Aegentra does not issue ISO 27001 certificates. Your organisation arranges the Clause 9.2 internal audit using auditors who are objective and impartial. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. Stage 1, Stage 2, surveillance and recertification audits are performed by an independent accredited certification body.

  • Are you a Microsoft Solutions Partner?

    Aegentra’s current Microsoft partner status should be checked through the linked Microsoft directory. Credentials are attributed only to the named people who hold them; an engagement scope identifies the roles assigned to your work.

  • What are the contract terms — are we locked in?

    Project fees and milestones are agreed after scoping. On-Demand IT has an agreed monthly fee and month-to-month scope. Check the written proposal for notice, cancellation, exclusions and any separate software commitments before engaging.

  • Are you based in Australia?

    Aegentra is a registered business name of HansDivisionGroup Pty Ltd, an Australian private company with ABN 84 678 444 463 and ACN 678 444 463. Its ABN and GST registrations have been active since 24 June 2024. The company record can be verified through the Australian Government ABN Lookup.

Let's talk.

Schedule a high-level technical consultation with a senior engineer. We evaluate your current posture and define a precise, actionable roadmap.