Skip to main content

ISO 27001 · SYDNEY

ISO 27001 consultants for Sydney businesses

Turn a customer’s security requirement into a clear plan. Aegentra helps Sydney businesses build an information security management system (ISMS) aligned with ISO/IEC 27001:2022, complete an objective internal audit and prepare for independent certification. We begin with your services, systems, evidence and deadline—then agree the work, responsibilities and fee.

Melbourne-based · Remote delivery to Sydney · Onsite by arrangement

03 9956 9399
Read Aegentra’s Google reviews

Business-wide feedback, including consulting and Academy training.

Sydney Opera House beside the harbour, with a ferry in the foreground

CHOOSE THE WORK YOU NEED

Implementation, internal audit or a coordinated programme?

If you are building an ISMS, you need implementation support. If the system is already operating, you may need an internal audit rather than another implementation project. If time is tight, a coordinated programme can organise both while keeping their responsibilities separate.

ISO 27001 implementation

Indicative starting budget:A$12,000–15,000 + GST

A$13,200–16,500 including Australian GST.

For suitably scoped businesses with fewer than 10 people. Establish the ISMS boundary, risk assessment, treatment plan, Statement of Applicability and agreed operating controls. Your written proposal defines the consultation, technical work, evidence and certification support included. Internal audit is separately scoped unless expressly included.

See implementation deliverables

ISO 27001 internal audit

FromA$2,300 + GST

A$2,530 including Australian GST.

For a smaller organisation with one clear ISMS scope and straightforward evidence access. An assigned auditor reviews documents, interviews control owners and samples operating evidence against the agreed audit criteria. You receive documented findings and an audit report; the scope records any corrective-action follow-up.

Explore internal-audit scope and reporting

Fast-track implementation and internal audit

Indicative starting budget:A$15,000–18,000 + GST

A$16,500–19,800 including Australian GST.

For suitably scoped businesses with fewer than 10 people. One consultant leads implementation, a different consultant performs the internal audit subject to impartiality checks, and a third manages the project. The package includes assistance arranging a certification body and preparing for its Stage 1 and Stage 2 assessments.

Understand the delivery roles and timing

What changes the fee?

The scope matters more than the postcode. Staff numbers, services, locations, existing maturity, technology, evidence quality and remediation needs affect the work. We confirm a written fixed fee after scoping. These starting budgets are not quotes for every organisation. Larger teams, multiple sites and more complex environments are scoped separately.

Certification-body fees are separate. Your proposal identifies any travel, additional licences, technical remediation and other exclusions before you commit.

Understand the full certification budget

START WITH THE BUYER’S REQUIREMENT

A Sydney tender deadline is not always a certification deadline

Before commissioning work, check what your buyer actually needs: a certificate with a particular scope, answers to a security questionnaire, an improvement plan or evidence that controls operate. Establish when each item is due. That distinction helps you prioritise the work without promising a certificate before the independent assessment has taken place.

For NSW Government opportunities, read the tender, contract and applicable procurement requirements together. NSW’s cyber security policy sets expectations for covered government agencies, including how they manage supplier risks. It is not a blanket ISO 27001 certification requirement for every Sydney business.

Within the agreed ISMS engagement, we help connect relevant security requirements to your scope, risk decisions, accountable owners and operating evidence. Supplier registration, admission to a procurement scheme and ISO certification are separate matters; one does not automatically establish the others.

Aegentra’s company details and supplier registrations

FROM CUSTOMER QUESTIONS TO WORKING CONTROLS

Make the evidence match the way your business operates

A policy can describe how information should be protected. Your records need to show what actually happens. Consider a Sydney professional-services or software business sharing client information through Microsoft 365 and other applications. The useful questions concern access, accountability, recovery and what happens when something goes wrong.

From a requirement to evidence

Choose a topic to trace the work behind it.

Explore an evidence path

Scope

  1. DecideDefine the service boundary
  2. OperateMap systems and suppliers
  3. DemonstrateMaintain the approved scope

Access

  1. DecideAgree access responsibilities
  2. OperateReview permissions and sharing
  3. DemonstrateKeep approvals and review records

Recovery

  1. DecideEstablish recovery needs
  2. OperateTest the recovery arrangements
  3. DemonstrateRecord results and follow-up actions

Incidents

  1. DecideAssign roles and escalation
  2. OperateExercise the response process
  3. DemonstrateRecord lessons and corrective actions

Illustrative evidence paths—not a maturity score. The detailed examples below explain the scope and records to consider.

Illustrative scoping example—not a client result or a universal control checklist.
A buyer may askImplementation work to considerEvidence to maintain
Which parts of your service does the ISMS cover?Define the service boundary, information flows and dependencies, including external providers.An approved scope and a maintained record of relevant systems and suppliers.
Who can access our information?Review identities, privileged access, external sharing and exceptions across the systems in scope.Access approvals, configuration records, periodic reviews and actions taken.
Can you recover the information you depend on?Assign recovery responsibilities and test the arrangements against business needs.Dated test results, recorded problems and follow-up actions.
How will you handle an incident affecting us?Connect incident roles and escalation to the agreed contractual requirements.An exercised response process, contact arrangements and records of corrective actions.

For Microsoft 365, agreed work may include identity and access settings, email protection, device controls and data-loss prevention. We establish what Aegentra will change, what remains with your IT provider and what requires additional licensing. The wider ISMS still includes people, suppliers and systems outside the tenant.

DELIVERY WITHOUT GUESSWORK

A clear division of work, from scoping to certification support

Aegentra is based in Melbourne and supports Sydney organisations remotely. Where onsite work is appropriate, we agree the purpose, location, availability and travel costs in advance. Your proposal names the delivery roles and the decisions, access and evidence required from your team.

  1. Agree the boundary and plan

    Review the business requirement, existing work and dependencies. Confirm deliverables, responsibilities, exclusions and a realistic programme before work begins.

  2. Build and operate the agreed ISMS

    Complete the scoped risk, documentation and control work. Help owners collect usable evidence and understand the ongoing responsibilities they will retain.

  3. Audit with protected objectivity

    The auditor must not audit their own work. Where separate Aegentra consultants implement and audit, documented conflict and impartiality checks determine whether that arrangement is suitable. If objectivity cannot be protected, a separate provider is required.

  4. Prepare for independent assessment

    Support the agreed management review, corrective actions and certification arrangements. The independent accredited certification body conducts Stage 1 and Stage 2 and decides whether to issue a certificate.

Fast-track example · subject to written scope

Separate roles. One coordinated programme.

Open a role to see its responsibilities.

Aegentra delivery roles

Implementation leadBuild the agreed ISMS

Builds the agreed system and helps your control owners put it into operation. Your team retains ongoing control ownership.

Assigned auditorAssess with protected objectivity

A different competent auditor checks the evidence without auditing their own work. Conflict and impartiality checks govern the assignment; a separate provider is required if objectivity cannot be protected.

Project managerCoordinate the programme

Coordinates milestones and certification arrangements without directing audit findings or conclusions.

External certification body

Independent and accredited

  1. Stage 1
  2. Stage 2

The certification body decides whether to issue a certificate. Assessment timing and the outcome are not guaranteed.

How fast can the coordinated programme run?

For an appropriately scoped business with fewer than 10 people, the fast-track option targets implementation in 5–7 weeks. Timely decisions, available evidence and no major remediation blockers are essential. This is an implementation planning target, not a guaranteed certification date. Certification-body availability and findings can extend the overall programme.

In the three-consultant fast-track model, the project manager coordinates milestones and certification arrangements without directing audit findings or conclusions.

ACCOUNTABLE PEOPLE · VISIBLE EVIDENCE

Know who will do the work—and what they are responsible for

Harry Sidhu, Aegentra’s Director and Principal Consultant, oversees engagement scoping and accountable delivery. The proposal identifies the assigned consultants, their responsibilities and the competence relevant to your project.

Across the delivery team are qualifications and experience in information-security management, internal audit, technology risk and security controls. We confirm the relevant credentials of the people assigned to your engagement.

Team qualifications and credentials

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Personnel security clearance

NV1 Security Clearance

NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.

Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

Meet the delivery capability behind the engagement

A published example of our audit work

Our Australian technology-company case study documents 73 lines of enquiry and risk-based sampling of 47 Annex A controls. It shows how evidence was linked to findings and conclusions—not simply that an audit took place.

This is one anonymised Australian engagement, not a Sydney client claim or a standard sample size for every audit.

Read the ISO 27001 internal-audit case study

A PRACTICAL STARTING POINT

Build a project brief before comparing proposals

Hands taking project notes beside a laptop and planning materials

Use this editable worksheet to capture your buyer’s requirement, the services in scope, existing ISO work and the help you need. It gives consultants the same starting information, making differences in scope and exclusions easier to see. You can keep it internally or use it to prepare for a discussion with Aegentra.

Download the ISO 27001 project-scoping worksheet

Editable Excel workbook · No email required · Do not include passwords or sensitive client information.

Download CSV instead

BEFORE YOU COMMISSION THE WORK

Questions from Sydney businesses

Do you have a Sydney office?

No. Aegentra is Melbourne-based. Sydney engagements can be delivered remotely, with onsite work by arrangement. We confirm the delivery method and any travel costs in the proposal.

Can our Sydney office be certified if the rest of the business operates elsewhere?

The scope must reflect the service and its real dependencies. If people, systems or suppliers elsewhere perform essential activities, those interfaces need to be considered. A street address alone does not define a complete ISMS boundary. We help establish an appropriate scope before certification arrangements are agreed.

We already hold ISO 27001 certification. Can you just perform the internal audit?

Yes. You do not need to purchase implementation to commission a separately scoped internal audit. We review your ISMS scope, audit programme, changes and previous findings, then agree the audit criteria, evidence access and reporting required. The auditor’s competence and impartiality are checked before fieldwork.

Does ISO 27001 certification automatically satisfy a bank’s security requirements?

No. A bank may have contractual or regulatory expectations that require evidence beyond a certificate. APRA’s CPS 234 applies to APRA-regulated entities; it should not be presented as automatically applying to every supplier. Check the actual customer requirements and the scope of your certificate before claiming compliance.

APRA CPS 234
Must we replace our IT provider or buy a new compliance platform?

No particular provider or platform is a prerequisite for an Aegentra engagement. We start with what you already use and identify responsibilities and gaps. Any proposed software, licence or technical changes must be agreed in the scope. A platform supports the work; it does not make risk decisions or issue your certificate.

LET’S TALK

Let’s scope your Sydney ISO 27001 project

Tell us what your customer needs, what is already in place and when a decision is due. We will discuss the right starting point and the information needed for a written proposal.

03 9956 9399

Overseas: +61 3 9956 9399

Contact@aegentra.com.au

We typically respond within 1–3 business hours.

Your project details

Include your approximate team size, main systems, existing ISO work and target date. Please do not send passwords, personal records or sensitive client documents.

We use your details to respond to your enquiry. Read our Privacy Policy.