Policies

How we protect data, people, and every engagement we run.

As a managed services and cybersecurity consultancy, we hold ourselves to the same governance standard we build for our clients. The policies below cover how we handle data, how our people work, and how we secure our own estate.

Effective date
1 January 2025
Next review
31 December 2025
Framework alignment
ISO/IEC 27001 · ACSC Essential Eight · Privacy Act 1988

Data Protection & Privacy

Client and candidate data is handled under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), with data held onshore and access restricted to what a role actually requires.

  • Data minimisation and purpose limitation for every system we build or operate
  • Encryption at rest (AES-256) and in transit (TLS 1.2+) for all client and candidate data
  • Australian-hosted data residency, with client data logically segregated per engagement
  • Notifiable Data Breaches (NDB) scheme compliance — assessment and notification within statutory timeframes
  • Defined retention schedules with secure, logged disposal at end of life

Hybrid Work Policy

Our default working pattern is on-site, with 2–3 remote days per week available by team agreement so client-facing and infrastructure work always has the coverage it needs.

  • Core on-site presence for client delivery, with 2–3 scheduled remote days per week
  • Remote work permitted only from enrolled, managed devices under Intune / MDM policy
  • Client-sensitive or high-intensity engagements are performed on-site by default
  • Fixed in-office collaboration windows keep teams and escalation paths aligned
  • Remote access is conditional — device compliance and MFA are checked before every session

Zero Trust Security

We operate on a "never trust, always verify" model: no user, device or network segment is trusted by default, regardless of whether it sits inside our perimeter.

  • Every access request is authenticated, authorised and encrypted, irrespective of network origin
  • Least-privilege and just-in-time access provisioning — standing admin rights are the exception, not the default
  • Multi-factor authentication (MFA) enforced organisation-wide, no exceptions
  • Network and workload micro-segmentation to contain lateral movement
  • Continuous device posture and identity verification, not a one-time login check
  • An assume-breach posture: detection and containment are designed in, not bolted on

Access Control & Identity Governance

Access follows the person and the role, not the request — every grant is reviewed, time-bound where appropriate, and removed the moment it's no longer needed.

  • Role-based access control (RBAC) mapped to job function, reviewed quarterly
  • Conditional access policies tied to device compliance, location and risk signal
  • Privileged access management (PAM) for all administrative and infrastructure accounts
  • Immediate deprovisioning of access on role change or offboarding

Incident Response & Business Continuity

Detection and response run continuously, with a tested plan for both security incidents and broader service disruption.

  • 24/7 monitoring with a defined incident runbook, severity tiers and escalation paths
  • Disaster recovery plans with tested Recovery Time and Recovery Point Objectives (RTO/RPO)
  • Client and regulator notification procedures aligned to the NDB scheme
  • Post-incident review feeding lessons learned back into controls and training

Vendor & Third-Party Risk

Every vendor or subprocessor that touches client data is assessed before onboarding and reassessed on an ongoing basis, not just at signature.

  • Security and privacy due diligence before any vendor is engaged
  • Contractual data protection and confidentiality obligations flowed down to subprocessors
  • Periodic reassessment of vendor risk for the life of the engagement

Acceptable Use & Security Awareness

People are as much a part of the control set as the platform — every team member is trained, tested and accountable.

  • Acceptable use policy covering company systems, devices and data handling
  • Mandatory security awareness training and regular phishing simulations
  • Clear, consistently applied consequences for confirmed policy breaches

Compliance & Standards Alignment

We hold ourselves to the same standard we govern our clients to, verified by independent review rather than self-assessment alone.

  • Information security controls aligned to ISO/IEC 27001
  • Maturity uplift tracked against the ACSC Essential Eight
  • Regular independent audits and penetration testing of our own environment

Have a compliance or security question?

For due diligence packs, a specific control's evidence, or anything else about how we operate, our team can walk you through it directly.

Talk to our team