by Paul Friend, MBA | ISO Lead Auditor | May 25, 2026 | Blog
The question of Essential Eight vs ISO 27001 comes up consistently for Australian organisations building or maturing their cybersecurity programmes. Both frameworks address information security. Both require structured controls, documented evidence, and ongoing...
by Paul Friend, MBA | ISO Lead Auditor | May 24, 2026 | Blog
Australian law firms face a targeted and intensifying cyber threat environment. The Essential Eight for law firms Australia is no longer a concern reserved for government agencies. It is a practical, defensible baseline that legal practices of every size must...
by Paul Friend, MBA | ISO Lead Auditor | May 11, 2026 | Blog
ISO 27001 certification confirms that an organisation’s information security management system (ISMS) meets the requirements of ISO/IEC 27001. For Australian organisations, it demonstrates independently verified security governance to ISO 27001 certification...
by Paul Friend, MBA | ISO Lead Auditor | May 1, 2026 | Blog, Managed Detection & Response
SOC services Australia organisations rely on deliver continuous security monitoring, threat detection, investigation, and response across an entire IT environment. For Australian mid-market and enterprise organisations, a managed Security Operations Centre is no...
by Paul Friend, MBA | ISO Lead Auditor | May 1, 2026 | Blog, SOC 2
A SOC 2 report is an independent attestation document. A licensed CPA firm issues it to confirm whether a service organisation’s controls meet the AICPA’s Trust Services Criteria. Unlike ISO 27001, which produces a transferable certificate, a SOC 2...