Skip to main content
Aegentra
Frequently Asked Questions

Things buyers actually ask.

Straight answers to the questions we field every week from Australian SMBs sizing up ISO 27001, Microsoft 365 hardening, and on-demand IT. If yours isn't here, our team replies in under one business day.

  • How long does ISO 27001 readiness take, and what does it cost?

    Aegentra may target an approximately 12-week implementation programme for an appropriately scoped, Microsoft 365-first organisation with sufficient leadership availability and no major remediation blockers. This is a planning assumption, not a guarantee. Timing depends on the ISMS boundary, starting maturity, technical complexity, evidence availability, client decisions, remediation, internal-audit arrangements and the certification body’s schedule. The written proposal records the actual delivery plan and dependencies.

  • We don’t have a Big-Four budget — but our internal IT can’t do this alone. Where do we fit?

    Organisations that need practical security or governance support can agree a scope suited to their existing team and systems. There is no universal minimum customer size: each service has its own eligibility, evidence and complexity assumptions. The proposal identifies the assigned people, responsibilities and fee.

  • How fast can our Microsoft 365 tenant actually be hardened?

    The scope and timetable are confirmed after assessing licences, permissions, current configuration, business dependencies and the changes approved by your team. Implementation uses agreed pilots, change approvals, rollback arrangements, verification and handover. An assessment or ongoing support contract does not automatically include every technical change.

  • After ISO 27001 readiness, who stops the controls from rotting?

    Controls can drift when ownership, review and evidence collection stop. Aegentra On-Demand IT can be scoped to support Microsoft 365 administration, incidents and recurring Aeges reviews, with response hours and responsibilities agreed in writing.

  • Does On-demand IT replace our internal team, or sit alongside it?

    Either. The service can be scoped as an outsourced Microsoft 365 support function or as named escalation support alongside an internal team. Coverage, responsibilities and exclusions are agreed before the month-to-month service begins.

  • Where does our data go during an Aeges scan?

    Assessment reads supported Microsoft 365 configuration. Writing reports to an agreed SharePoint location is a separate permission and action; read-only assessment does not mean no report writes. Before access is approved, confirm the data categories, permissions, processing and storage locations, report destination and retention arrangements in the engagement scope.

  • Do you provide the certification audit yourselves?

    Aegentra does not issue ISO 27001 certificates. Your organisation arranges the Clause 9.2 internal audit using auditors who are objective and impartial. Where Aegentra implements the ISMS, a different competent Aegentra consultant, independent of the implementation work, performs the internal audit subject to documented conflict-of-interest and impartiality checks. If independence cannot be protected, a separate provider is required. Stage 1, Stage 2, surveillance and recertification audits are performed by an independent accredited certification body.

  • Are you a Microsoft Solutions Partner?

    Aegentra’s current Microsoft partner status should be checked through the linked Microsoft directory. Credentials are attributed only to the named people who hold them; an engagement scope identifies the roles assigned to your work.

  • What are the contract terms — are we locked in?

    Project fees and milestones are agreed after scoping. On-Demand IT has an agreed monthly fee and month-to-month scope. Check the written proposal for notice, cancellation, exclusions and any separate software commitments before engaging.

  • Are you based in Australia?

    Aegentra is a registered business name of HansDivisionGroup Pty Ltd, an Australian private company with ABN 84 678 444 463 and ACN 678 444 463. Its ABN and GST registrations have been active since 24 June 2024. The company record can be verified through the Australian Government ABN Lookup.

If your question is about getting certified rather than about working with us, the ISO 27001 certification guide for Australia covers process, real costs and timelines. Enrolment, invoicing and exam questions are answered on the Academy FAQ.

Let's talk.

Schedule a high-level technical consultation with a senior engineer. We evaluate your current posture and define a precise, actionable roadmap.