Case Study

Australia’s largest privately-owned digital services group achieves ISO 27001 certification across a complex, multi-brand environment

How CyberPulse guided Nexigen Digital through end-to-end ISO 27001:2022 certification and established an ongoing penetration testing programme across a group that serves more than 200,000 Australian businesses.

project snapshot

INDUSTRY

Digital Services

 

ORGANISATION SIZE

50–200 staff

 

LOCATION

Melbourne & Gold Coast

 

ENGAGEMENT

Ongoing

FRAMEWORK

ISO 27001:2022

 

The Challenge

Enterprise-grade security obligations across a growing, multi-brand group

Nexigen Digital is Australia’s largest privately-owned group of online service providers, operating multiple brands including VentraIP, Synergy Wholesale and Digital Eagles. The group provides domain names, web hosting, business email and digital marketing services to more than 200,000 Australian businesses, and runs a wholesale platform used by resellers, developers and portfolio managers across the country. That scale and reach creates a serious security obligation: the group is not just responsible for its own data, but for the infrastructure and credentials of hundreds of thousands of customer accounts.


As Nexigen Digital grew through acquisition and expanded its service offering, the security environment became increasingly complex. Multiple brands, multiple product lines, and a wholesale channel all needed to be brought under a coherent security framework. Enterprise clients and wholesale partners were asking harder questions about security posture, and the group recognised that ISO 27001 certification would provide the structured foundation needed to address both internal governance requirements and external expectations.

Operations centre displays monitoring the large-scale digital infrastructure Nexigen Digital brought under its ISO 27001 certified ISMS

Key challenges included:

Defining an ISMS scope that was meaningful and auditable across a multi-brand, multi-product group without over-engineering the programme for the size of the business
Consolidating security policies and controls across brands and teams that had each evolved independently, with inconsistent documentation and varying levels of control maturity
Addressing the specific risk profile of a hosting and digital infrastructure provider, where customer data, payment information and privileged access to customer environments all carry elevated sensitivity
Establishing a penetration testing cadence that would keep pace with a business actively acquiring new brands and launching new services, rather than testing a static environment once a year
Building the internal capability and awareness to sustain the ISMS beyond certification, without creating an ongoing compliance burden that would slow the business down

The Solution

ISO 27001 end-to-end delivery, with penetration testing built to scale with the group

CyberPulse delivered an end-to-end ISO 27001:2022 engagement covering gap assessment, ISMS design, control implementation, policy consolidation and certification audit management. Alongside the certification programme, CyberPulse established an ongoing penetration testing programme scoped to reflect the group’s infrastructure and updated each cycle to account for new acquisitions, products and attack surface changes.

Phase 1: Gap Assessment and Scope Definition

CyberPulse conducted a structured gap assessment across Nexigen Digital, mapping existing controls against the ISO 27001:2022 Annex A requirements and identifying the delta between current state and certification readiness. Particular attention was given to defining the ISMS scope correctly across multiple brands and a wholesale channel, so that the programme was both auditable and commercially proportionate. Gaps were risk-ranked and sequenced into a remediation plan that the team could execute without derailing operational priorities.

Phase 2: ISMS Design, Policy Consolidation and Control Implementation

CyberPulse designed the ISMS architecture for the group and led the consolidation of security policies across brands into a single, coherent policy framework. Controls were implemented or formalised across access management, asset management, supplier relationships, incident management and business continuity, with documentation structured to meet audit requirements from day one. Internal awareness training was delivered to ensure staff across the group understood their obligations under the new framework. CyberPulse managed the certification audit end-to-end, achieving ISO 27001:2022 certification with no major nonconformities.

Phase 3: Ongoing Penetration Testing and Audit Support

CyberPulse established a structured annual penetration testing programme covering Nexigen Digital’s customer-facing web applications, hosting control panels, wholesale platform APIs, internal networks and newly acquired brand infrastructure. Each testing cycle is scoped collaboratively to reflect changes in the attack surface since the prior engagement, ensuring findings remain relevant to the current environment. CyberPulse also provides ongoing support for ISO 27001 surveillance audits and internal review cycles, maintaining the ISMS as the group continues to grow.

The Results

Certified, scoped correctly, and tested against a live and evolving attack surface

Certified

ISO 27001:2022 achieved across all of Nexigen Digital with no major nonconformities, covering multiple brands, product lines and a wholesale reseller channel

200,000+

Customer accounts now covered by a certified, independently audited security programme, strengthening trust with businesses and wholesale partners alike

Annual

Penetration testing programme in place across customer-facing platforms, hosting infrastructure and wholesale APIs, rescoped each cycle to reflect acquisitions and new services

"

CyberPulse didn’t just help us build an ISMS; they helped us build a more resilient business. Their practical approach ensured that every control we implemented serves a real purpose and has a positive, tangible impact on our daily operations.

Daniel Foenander
Director of Operations, Nexigen Digital

Services Delivered

ISO 27001:2022 Advisory
Gap Assessment
ISMS Design and Implementation
Policy Consolidation
Certification Audit Management
Annual Penetration Testing
Ongoing Audit Support
Surveillance Audit Management

Facing a similar challenge?

We can help you build clarity, capability, and confidence.