Case Study
Australia’s largest privately-owned digital services group achieves ISO 27001 certification across a complex, multi-brand environment
How CyberPulse guided Nexigen Digital through end-to-end ISO 27001:2022 certification and established an ongoing penetration testing programme across a group that serves more than 200,000 Australian businesses.
project snapshot
INDUSTRY
Digital Services
ORGANISATION SIZE
50–200 staff
LOCATION
Melbourne & Gold Coast
ENGAGEMENT
Ongoing
FRAMEWORK
ISO 27001:2022
The Challenge
Enterprise-grade security obligations across a growing, multi-brand group
Nexigen Digital is Australia’s largest privately-owned group of online service providers, operating multiple brands including VentraIP, Synergy Wholesale and Digital Eagles. The group provides domain names, web hosting, business email and digital marketing services to more than 200,000 Australian businesses, and runs a wholesale platform used by resellers, developers and portfolio managers across the country. That scale and reach creates a serious security obligation: the group is not just responsible for its own data, but for the infrastructure and credentials of hundreds of thousands of customer accounts.
As Nexigen Digital grew through acquisition and expanded its service offering, the security environment became increasingly complex. Multiple brands, multiple product lines, and a wholesale channel all needed to be brought under a coherent security framework. Enterprise clients and wholesale partners were asking harder questions about security posture, and the group recognised that ISO 27001 certification would provide the structured foundation needed to address both internal governance requirements and external expectations.
Key challenges included:
The Solution
ISO 27001 end-to-end delivery, with penetration testing built to scale with the group
CyberPulse delivered an end-to-end ISO 27001:2022 engagement covering gap assessment, ISMS design, control implementation, policy consolidation and certification audit management. Alongside the certification programme, CyberPulse established an ongoing penetration testing programme scoped to reflect the group’s infrastructure and updated each cycle to account for new acquisitions, products and attack surface changes.
Phase 1: Gap Assessment and Scope Definition
CyberPulse conducted a structured gap assessment across Nexigen Digital, mapping existing controls against the ISO 27001:2022 Annex A requirements and identifying the delta between current state and certification readiness. Particular attention was given to defining the ISMS scope correctly across multiple brands and a wholesale channel, so that the programme was both auditable and commercially proportionate. Gaps were risk-ranked and sequenced into a remediation plan that the team could execute without derailing operational priorities.
Phase 2: ISMS Design, Policy Consolidation and Control Implementation
CyberPulse designed the ISMS architecture for the group and led the consolidation of security policies across brands into a single, coherent policy framework. Controls were implemented or formalised across access management, asset management, supplier relationships, incident management and business continuity, with documentation structured to meet audit requirements from day one. Internal awareness training was delivered to ensure staff across the group understood their obligations under the new framework. CyberPulse managed the certification audit end-to-end, achieving ISO 27001:2022 certification with no major nonconformities.
Phase 3: Ongoing Penetration Testing and Audit Support
CyberPulse established a structured annual penetration testing programme covering Nexigen Digital’s customer-facing web applications, hosting control panels, wholesale platform APIs, internal networks and newly acquired brand infrastructure. Each testing cycle is scoped collaboratively to reflect changes in the attack surface since the prior engagement, ensuring findings remain relevant to the current environment. CyberPulse also provides ongoing support for ISO 27001 surveillance audits and internal review cycles, maintaining the ISMS as the group continues to grow.
The Results
Certified, scoped correctly, and tested against a live and evolving attack surface
Certified
ISO 27001:2022 achieved across all of Nexigen Digital with no major nonconformities, covering multiple brands, product lines and a wholesale reseller channel
200,000+
Customer accounts now covered by a certified, independently audited security programme, strengthening trust with businesses and wholesale partners alike
Annual
Penetration testing programme in place across customer-facing platforms, hosting infrastructure and wholesale APIs, rescoped each cycle to reflect acquisitions and new services
CyberPulse didn’t just help us build an ISMS; they helped us build a more resilient business. Their practical approach ensured that every control we implemented serves a real purpose and has a positive, tangible impact on our daily operations.
Services Delivered
Facing a similar challenge?
We can help you build clarity, capability, and confidence.
