by Paul Friend, MBA | ISO Lead Auditor | Oct 2, 2025 | Blog
Cybersecurity compliance in Australia is no longer optional. Organisations across all sectors are subject to a patchwork of obligations, ranging from the Essential Eight and ISM, through to ISO/IEC 27001:2022, APRA CPS 234, the SOCI Act, and the Privacy Act Notifiable...
by Paul Friend, MBA | ISO Lead Auditor | Sep 20, 2025 | Blog, SOC 2
Australian organisations preparing for SOC 2 often face an early and consequential decision: whether to pursue SOC 2 Type 1 or SOC 2 Type 2. Both reports demonstrate a commitment to security governance and customer trust. However, they provide very different levels of...
by Paul Friend, MBA | ISO Lead Auditor | Sep 16, 2025 | Blog
Executive Summary Audit readiness services have become essential for organisations navigating increasingly complex compliance requirements. Whether the target is ISO 27001, ISO 42001, PCI DSS, IRAP or SOC 2, the value of readiness lies not only in passing an audit but...