Case Study

Australian EdTech firm achieves ISO 27001 certification and builds a mature, continuously tested security programme

How CyberPulse helped Meshed Group achieve ISO 27001 certification through end-to-end advisory, process improvement and audit support, alongside an annual penetration testing programme to validate and maintain their security posture.

project snapshot

INDUSTRY

EdTech / SaaS

 

ORGANISATION SIZE

50–200 staff

 

LOCATION

Sydney, NSW

 

ENGAGEMENT

Ongoing

 

FRAMEWORK

ISO 27001:2022

 

The Challenge

Trusted by institutions, held to the highest standard

Meshed Group is one of Australia’s leading providers of student management and admissions software, supporting more than 40% of Australia’s private higher education sector. Trusted by education providers across Australia, Meshed’s cloud-based platforms manage the entire student lifecycle, from admissions and enrolments to compliance, finance, reporting and graduation, while securely handling sensitive student and institutional data. The platforms also support institutions in meeting complex regulatory and reporting obligations, including reporting requirements associated with TEQSA, ASQA, TCSI and PRISMS.


As Meshed continued to grow and expand into new institution types, the question of formal security certification became increasingly important in the sales process. Enterprise clients and university partners wanted documented assurance that their student data was protected to an internationally recognised standard. At the same time, Meshed wanted to ensure that certification reflected genuine security maturity, not a compliance exercise. They chose CyberPulse to lead the programme end-to-end.

Key priorities included:

Achieving ISO 27001:2022 certification to meet the expectations of enterprise and institutional clients and support the sales process
Implementing process improvements that would lift actual security capability alongside the formal certification programme
Establishing a repeatable annual penetration testing programme to validate controls and maintain confidence in the platform's security posture
Building an ongoing audit support relationship so that surveillance audits and recertification cycles could be managed without disrupting the team

The Solution

End-to-end ISO 27001 delivery with continuous validation through annual penetration testing

CyberPulse delivered a fully managed ISO 27001:2022 programme covering gap assessment, ISMS design, process improvement, policy development and audit coordination, alongside an annual penetration testing programme scoped to Meshed’s platform and infrastructure. The engagement was designed to be sustainable: controls and processes embedded into the way the team works, not maintained as a parallel compliance overhead.

Phase 1: Gap Assessment and ISMS Design

CyberPulse assessed Meshed’s existing security practices against the ISO 27001:2022 control set and identified the gaps between their current state and certification readiness. An Information Security Management System was designed around Meshed’s actual operating model, with controls scoped appropriately for a SaaS business handling sensitive education and personal data. The gap analysis was prioritised by risk so that remediation effort went to the areas that mattered most first.

Phase 2: Process Improvement and Certification

CyberPulse worked directly with the Meshed team to implement the process improvements identified in the gap assessment, building controls and workflows into existing operations rather than layering compliance processes on top. Policies, procedures and evidence collection were structured to support the audit from day one. CyberPulse managed the certification audit end-to-end, coordinating with the certifying body and preparing the evidence packages required across all applicable Annex A controls. Meshed achieved ISO 27001:2022 certification with no major nonconformities.

Phase 3: Annual Penetration Testing and Ongoing Audit Support

With certification achieved, CyberPulse established an annual penetration testing programme covering Meshed’s web applications, APIs and internal infrastructure. Testing is scoped each year to reflect platform changes and new features, ensuring the programme remains relevant rather than running against a static scope. CyberPulse also provides ongoing support for surveillance audits and internal review cycles, maintaining the ISMS as the business and threat landscape evolves.

The Results

Certified, continuously tested and trusted by institutions across Australia

Certified

Achieved ISO 27001:2022 certification with no major nonconformities, enabling Meshed Group to provide independently verified assurance of its information security management system to enterprise and institutional clients.

Continuous Validation

Established an annual penetration testing programme covering web applications, APIs and infrastructure, providing ongoing independent validation of the effectiveness of security controls.

Long-term Security Partnership

Implemented an ongoing audit and advisory programme supporting surveillance audits, continual improvement and the evolution of Meshed Group’s ISMS as the business grows.

"

Achieving ISO 27001 certification wasn't simply about obtaining a certificate. It was about strengthening our security capability and demonstrating to our clients that information security is embedded in everything we do. CyberPulse became an extension of our team, guiding us through the certification process while helping us embed practical security practices into our day-to-day operations. Their expertise helped transform what could have been a compliance exercise into a genuine uplift in our security maturity. The certification has also provided our clients and prospective institutions with greater confidence in our platform and our commitment to protecting their data.

Pramesh Khadka
CEO, Meshed Group

Services Delivered

ISO 27001:2022 Advisory
Gap Assessment
ISMS Design and Implementation
Process Improvement
Certification Audit Support
Annual Penetration Testing
Ongoing Audit Support
Surveillance Audit Management

Facing a similar challenge?

We can help you build clarity, capability, and confidence.