by Paul Friend, MBA | ISO Lead Auditor | Jan 15, 2026 | Blog, Penetration Testing
Summary Web application penetration testing is one of the most important controls any organisation can apply to reduce real cyber risk. As web-facing applications, APIs, and microservices power more business outcomes, attackers increasingly target them to gain access...
by Paul Friend, MBA | ISO Lead Auditor | Jan 13, 2026 | Blog, ISO 27001
How long does ISO 27001 certification take? For Australian organisations, timelines typically range from three months to over twelve months from initial preparation through to certification issuance. The primary variables are organisational size, existing security...
by Paul Friend, MBA | ISO Lead Auditor | Jan 13, 2026 | Blog
Summary Cybersecurity audits are no longer optional for Australian organisations. Boards, regulators, insurers, and customers now expect audits that validate not only documented controls, but also real control effectiveness across people, processes, and technology. At...
by Paul Friend, MBA | ISO Lead Auditor | Jan 12, 2026 | Blog, ISO 27001
GRC tools play a critical role in helping organisations achieve and maintain ISO 27001 and SOC 2 compliance. As audits become more continuous and expectations around evidence quality increase, manual approaches struggle to keep pace. Consequently, many organisations...
by Paul Friend, MBA | ISO Lead Auditor | Jan 12, 2026 | Blog
Drata and Vanta are two of the most recognised compliance automation platforms for organisations pursuing SOC 2 and ISO 27001. When evaluating Drata vs Vanta, both platforms aim to reduce manual effort, improve audit readiness, and provide ongoing visibility into...