Skip to main content

/ About Aegentra

The company that builds the system, not the report about it.

Aegentra is an Australian cybersecurity, governance and professional-training company. Govern implements and independently evaluates management systems under separate scopes; Harden improves Microsoft 365 security; Aegentra Academy delivers official PECB training; and Aegentra Labs develops separate software and exam-preparation products.

/ Founder

Harry Sidhu

Director and Principal Consultant

ISO 27001 Lead Implementer · PECB certificate no. 9303577-2026-05 · 10 years in cybersecurity · AGSVA NV1 security cleared

Harry founded Aegentra to close a gap he kept meeting from both sides of an audit: organisations were buying compliance documentation and discovering, at Stage 2, that nobody had built the system underneath it.

He leads the Govern practice—ISO 27001 and ISO 42001 implementation and internal audit, SOC 2 readiness, and SOX ITGC. As principal consultant, he is accountable for engagement scoping and delivery oversight. The proposal confirms the consultants assigned to the work and their responsibilities.

Across 10 years in cybersecurity engineering and consulting, Harry has implemented ISO 27001 information security management systems and ISO 42001 artificial intelligence management systems end to end for medium and large organisations. His government work includes ISMS and Essential Eight implementation, with experience applying OAIC and OVIC guidance in Australian privacy and information-security contexts.

He writes and reviews Aegentra’s own technical guides, supplementary learning resources and certification guidance published on this site. These Aegentra-authored resources are separate from official PECB course materials. Course and examination descriptions should be read alongside the applicable PECB candidate requirements.

His credential is independently verifiable: use Harry Sidhu and certificate number 9303577-2026-05 in PECB’s certificate verification tool. That is a deliberate choice — a name on a page proves nothing, and a number that can be checked is the only version worth publishing.

Connect on LinkedIn

/ Delivery capability

Our team

Experienced and qualified for complex assurance work

Aegentra’s delivery team combines senior experience across IT audit, cybersecurity governance, enterprise risk, internal controls and management systems.

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Team qualifications and credentials

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Personnel security clearance

NV1 Security Clearance

NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.

Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

Aegentra’s delivery team brings more than two decades of professional experience across IT audit, cybersecurity governance, enterprise risk and internal controls. Across their professional careers, team members have delivered 2,000+ hours of ISO, ASD ISM and GRC audit work across 70+ organisations in government, finance, healthcare, defence, manufacturing, technology, not-for-profit and logistics.

Read more about our team

/ What sets us apart

Three things you cannot buy from a platform or a binder.

We configure, we do not recommend

A consultancy may stop at a gap report, while a platform can collect evidence without designing the operating system around it. Aegentra combines scoped advice with hands-on implementation and leaves the organisation with named owners and reproducible evidence.

Implementation and audit kept separate

Aegentra distinguishes implementation, Clause 9.2 internal audit and certification. Internal-audit work is accepted only after objectivity, impartiality and prior involvement are checked; an independent accredited certification body makes the certification decision.

Evidence that stays alive

Controls and records need to keep pace with changes to your people, suppliers and systems. Where included in the agreed scope, Aeges helps collect and organise supported Microsoft 365 configuration evidence. That evidence sits alongside policies, interviews, operating records and management review; a tenant snapshot alone does not establish ISO 27001 conformity.

/ Depth of practice

Four practices, with every public claim tied to a defined scope or source.

Aegentra is a registered business name of HansDivisionGroup Pty Ltd, an Australian private company with an active ABN and GST registration since 24 June 2024. Aegentra is based in Melbourne, Victoria and delivers scoped ISO 27001, ISO 42001, SOC 2, SOX ITGC and Microsoft 365 security work across Australia, New Zealand and the wider Asia Pacific region. Each scope identifies the named lead and any additional delivery roles.

Aegentra publishes selected engagement summaries that explain the agreed scope, approach, evidence reviewed and reported findings. Client identities and confidential working papers are not disclosed without permission. Illustrative case studies are labelled separately and do not represent completed client engagements. See the specific ISO 27001 Clause 9.2 internal audit reference.

Aegentra’s method is built around auditable evidence — requirements, risks, control owners, operating records and findings that can be traced — and Australian context, where they implemented ISO 27001 and the Essential Eight under real scrutiny rather than as a commercial exercise.

That matters for one practical reason. Someone who has sat on the auditor’s side of the table knows which evidence survives a Stage 2 audit and which collapses under a single follow-up question. It is the difference between a system built to pass and a system built to hold.

Experience behind Aegentra

Independent audit discipline

Audit criteria, sampling, working papers, findings and conflict checks kept distinct from the implementation scope.

Government and regulated sectors

ISO 27001 and Essential Eight implementation where the scrutiny is statutory rather than commercial.

Microsoft 365 and Azure security engineering

Entra ID, Defender, Purview and Intune configured as controls that produce evidence, not as a licence checklist.

Enterprise and large-scale environments

Management systems that hold across thousands of identities and multiple jurisdictions, not just a single-office scope.

Audit and implementation across Asia Pacific

Both sides of the engagement — building systems and assessing them — across the region Aegentra serves.

/ Services

All four sit together on the solutions overview. Alongside them, Aegentra Academy is an official PECB authorised training partner running 45 certification courses across 11 ISO management system standards — for organisations that want their own people credentialed rather than the work outsourced.

/ Company updates

Partnership and product announcements.

18 September 2026

Aegentra Vanta Partnership | Compliance & Partner Quotes

The partnership combines Vanta’s compliance platform with Aegentra’s implementation support. Australian organisations can enquire about partner pricing and practical help with audit readiness.

Read announcement

7 September 2026

Aegentra Joins Microsoft Partner Programme

Aegentra joined the Microsoft AI Cloud Partner Program in June 2026, supporting its focus on Microsoft 365 security and IT services in Australia.

Read announcement

7 September 2026

Aegentra Announces CompTIA Membership

Aegentra's CompTIA membership began in July 2026. The company is planning additional learning options, with course details to be published when available.

Read announcement

7 September 2026

Aegentra Announces Pax8 Cloud Partnership

Aegentra's Pax8 partnership began in August 2026, connecting cloud marketplace access with its focus on security and IT support for Australian businesses.

Read announcement

7 September 2026

Aegentra Announces Drata Partnership

Aegentra's Drata partnership began in September 2026, connecting its governance practice with a platform for compliance workflows and evidence management.

Read announcement

11 May 2026

Aegentra is now an official PECB authorised training partner

Aegentra has signed as an official PECB authorised training partner and launched Aegentra Academy with published online self-paced pathways across ISO 27001, ISO 42001 (AI), ISO 27701 (privacy), ISO 31000 and SOC 2. Instructor-led delivery for organisations is scoped on request and published only when confirmed.

Read announcement

10 May 2026

Aegentra renames its tenant risk engine as Aeges

Aegentra has renamed its in-tenant risk engine from "Aegentra Core" to Aeges, separating the product from the parent brand and signalling its own roadmap for Microsoft 365 security telemetry.

Read announcement

10 April 2026

Aegentra launches its Microsoft 365 tenant risk engine

Aegentra has released its Microsoft 365 risk engine, surfacing identity, configuration, and exposure issues across a tenant — with findings delivered through the Aegentra Dashboard.

Read announcement
View all press releases

/ How we work

Four commitments we are willing to be audited against.

Implemented, not advised

A management system has to operate, not just exist as documentation. Aegentra works inside the agreed environment, configures the selected controls and organises evidence that can be reproduced and reviewed.

Named accountability

Every engagement begins with a written scope, a named lead, identified delivery roles, responsibilities and exclusions. Additional roles are disclosed in the scope instead of being implied by a generic team claim.

Evidence over assertion

Every claim we make about your posture is traceable to a configuration state, a log, or a record. That is the standard an auditor applies, and applying it to ourselves first is the only way an audit stops being an event to survive.

Australian context, not a translated framework

The Essential Eight, the Privacy Act and the APPs, APRA CPS 234 and CPS 230, and JAS-ANZ accreditation are the ground our clients operate on. We map international standards onto that ground rather than the reverse.

/ Careers

Senior people, doing the work.

Aegentra is deliberately senior-led. The named engagement lead, delivery responsibilities and any supporting roles are confirmed in the written scope before work begins. The delivery model explains how roles, competence evidence and independence checks are disclosed before an engagement is accepted.

/ Company

Trading name
Aegentra
Legal entity
HansDivisionGroup Pty Ltd
ABN
84 678 444 463
ACN
678 444 463
Company registration
ABN and GST active since 24 June 2024
Delivery model
Named lead and scoped roles
Based in
Melbourne, Victoria
Service area
Asia Pacific
Academy
Official PECB authorised training partner
Contact
Contact@aegentra.com.au

Aegentra operates as a service-area business without a public office address. Engagements are delivered remotely across the Asia Pacific, with on-site attendance available by arrangement. For Academy enrolments and consolidated invoicing, reach the Academy team at Academy@aegentra.com.au. For local business projects, see our Melbourne ISO 27001 consulting services.

Talk to the person who would do the work.

Scoping conversations are with the principal consultant, not a salesperson.