Case Study
Australian EdTech firm achieves ISO 27001 certification and builds a mature, continuously tested security programme
How CyberPulse helped Meshed Group achieve ISO 27001 certification through end-to-end advisory, process improvement and audit support, alongside an annual penetration testing programme to validate and maintain their security posture.
project snapshot
INDUSTRY
EdTech / SaaS
ORGANISATION SIZE
50–200 staff
LOCATION
Sydney, NSW
ENGAGEMENT
Ongoing
FRAMEWORK
ISO 27001:2022
The Challenge
Trusted by institutions, held to the highest standard
Meshed Group is one of Australia’s leading providers of student management and admissions software, supporting more than 40% of Australia’s private higher education sector. Trusted by education providers across Australia, Meshed’s cloud-based platforms manage the entire student lifecycle, from admissions and enrolments to compliance, finance, reporting and graduation, while securely handling sensitive student and institutional data. The platforms also support institutions in meeting complex regulatory and reporting obligations, including reporting requirements associated with TEQSA, ASQA, TCSI and PRISMS.
As Meshed continued to grow and expand into new institution types, the question of formal security certification became increasingly important in the sales process. Enterprise clients and university partners wanted documented assurance that their student data was protected to an internationally recognised standard. At the same time, Meshed wanted to ensure that certification reflected genuine security maturity, not a compliance exercise. They chose CyberPulse to lead the programme end-to-end.
Key priorities included:
The Solution
End-to-end ISO 27001 delivery with continuous validation through annual penetration testing
CyberPulse delivered a fully managed ISO 27001:2022 programme covering gap assessment, ISMS design, process improvement, policy development and audit coordination, alongside an annual penetration testing programme scoped to Meshed’s platform and infrastructure. The engagement was designed to be sustainable: controls and processes embedded into the way the team works, not maintained as a parallel compliance overhead.
Phase 1: Gap Assessment and ISMS Design
CyberPulse assessed Meshed’s existing security practices against the ISO 27001:2022 control set and identified the gaps between their current state and certification readiness. An Information Security Management System was designed around Meshed’s actual operating model, with controls scoped appropriately for a SaaS business handling sensitive education and personal data. The gap analysis was prioritised by risk so that remediation effort went to the areas that mattered most first.
Phase 2: Process Improvement and Certification
CyberPulse worked directly with the Meshed team to implement the process improvements identified in the gap assessment, building controls and workflows into existing operations rather than layering compliance processes on top. Policies, procedures and evidence collection were structured to support the audit from day one. CyberPulse managed the certification audit end-to-end, coordinating with the certifying body and preparing the evidence packages required across all applicable Annex A controls. Meshed achieved ISO 27001:2022 certification with no major nonconformities.
Phase 3: Annual Penetration Testing and Ongoing Audit Support
With certification achieved, CyberPulse established an annual penetration testing programme covering Meshed’s web applications, APIs and internal infrastructure. Testing is scoped each year to reflect platform changes and new features, ensuring the programme remains relevant rather than running against a static scope. CyberPulse also provides ongoing support for surveillance audits and internal review cycles, maintaining the ISMS as the business and threat landscape evolves.
The Results
Certified, continuously tested and trusted by institutions across Australia
Certified
Achieved ISO 27001:2022 certification with no major nonconformities, enabling Meshed Group to provide independently verified assurance of its information security management system to enterprise and institutional clients.
Continuous Validation
Established an annual penetration testing programme covering web applications, APIs and infrastructure, providing ongoing independent validation of the effectiveness of security controls.
Long-term Security Partnership
Implemented an ongoing audit and advisory programme supporting surveillance audits, continual improvement and the evolution of Meshed Group’s ISMS as the business grows.
Achieving ISO 27001 certification wasn't simply about obtaining a certificate. It was about strengthening our security capability and demonstrating to our clients that information security is embedded in everything we do. CyberPulse became an extension of our team, guiding us through the certification process while helping us embed practical security practices into our day-to-day operations. Their expertise helped transform what could have been a compliance exercise into a genuine uplift in our security maturity. The certification has also provided our clients and prospective institutions with greater confidence in our platform and our commitment to protecting their data.
Services Delivered
Facing a similar challenge?
We can help you build clarity, capability, and confidence.
