IT Compliance & Risk Management for Perth Firms
When AHPRA, the Law Society, CPA Australia or your cyber insurer asks how client data is protected, "our IT guy handles it" isn't an answer. We implement and evidence the controls they actually check — multi-factor authentication, tested backups, patching and monitoring — mapped to the Essential Eight.
Who's Asking, By Industry
Compliance isn't abstract — a named regulator, professional body or insurer sets the expectations for your industry. These are the ones Perth firms answer to.
Accountants & Bookkeepers
The Tax Practitioners Board expects practices to protect client data and control who can access it; the ATO's digital service standards assume MFA and secure access as a baseline. We set up IT for accounting firms that stands up to both.
Law Firms
Confidentiality and trust-account integrity are professional obligations, not IT nice-to-haves. Matter files, email and remote access get locked down so privilege doesn't depend on luck. See how we support professional practices.
Medical & Allied Health
AHPRA-registered practitioners must keep health records secure and available; RACGP's standards spell out backups, access control and secure messaging. Our healthcare IT support is built around exactly that.
Pharmacy & Pharmaceutical
Dispensing records, cold-chain monitoring and supplier systems fall under TGA and Pharmacy Board record-keeping expectations — with the same Privacy Act duties as every other health provider.
And for everyone: the Privacy Act and the OAIC
The Notifiable Data Breaches scheme means eligible breaches must be reported to the OAIC and your clients. All health service providers are covered regardless of size — and financial services firms answer to ASIC and AFSL obligations on top. The controls below are the same ones every one of these bodies expects to see.
The Controls, By Name
Regulators and insurers don't ask "are you secure?" — they ask for specific controls. These are the ones on the questionnaire, each mapped to the ACSC Essential Eight.
Multi-Factor Authentication
MFA on email, remote access and admin accounts, enforced by policy rather than left to each person's judgement. The single control every insurer now demands.
Essential Eight: Multi-Factor Authentication
Backups That Restore
A backup nobody has tested is a hope, not a control. We configure automated backups and actually run restore tests, with evidence you can hand over.
Essential Eight: Regular Backups
Patching, On Schedule
Operating systems and applications updated on a defined cycle, with a record of what was patched and when (not "Windows updates itself, probably").
Essential Eight: Patch Applications & Operating Systems
Monitoring & Alerting
Someone actually watching: endpoint alerts triaged, sign-in anomalies flagged, and a monthly snapshot of what was caught. Part of our Security Essentials baseline.
Supports every Essential Eight strategy
Admin Rights, Restricted
Day-to-day accounts don't run as administrators, and privileged access is limited to the people who need it: reviewed, not accumulated.
Essential Eight: Restrict Administrative Privileges
Microsoft 365, Hardened
Conditional Access, Defender and data-loss controls configured across your tenant in one fixed-scope pass — our Microsoft 365 security hardening engagement.
Implements multiple Essential Eight strategies in M365
Renewing cyber insurance?
If the trigger is an insurer's questionnaire, our cyber insurance readiness check verifies MFA, backups, EDR and patching against the questions and prepares the evidence before you answer anything.
AI Is the Newest Compliance Gap
Staff are already pasting client information into public AI tools — usually with good intentions and no policy. For regulated professions, that's a confidentiality problem before it's a productivity win.
Find the shadow AI
Our fixed-fee AI risk assessment maps which AI tools are actually in use across your business, what data is going into them, and where the exposure sits.
Set a usable policy
A practical AI usage policy your staff will actually follow — what's allowed, what never leaves the building, and which tools are approved. Training available through our AI workshops.
What It Costs
Compliance uplift work is scoped and quoted in writing before anything starts — most engagements are fixed-scope with a defined deliverable and evidence pack.
Uplift engagements
Compliance reviews, Essential Eight uplifts, M365 hardening and insurance readiness are quoted as fixed-scope projects, so you know the number before we start.
$180/hr ex GST
Ad-hoc labour is one-hour minimum, then 30-minute increments. It is the same published rate as everything else we do. See what an hour covers.
These are internal technical reviews and uplift work, not government-accredited audits. If a tender needs a certified assessor, we'll tell you and point you the right way.
Answer the Questionnaire With Confidence
Tell us which regulator, standard or insurer is asking, and we'll tell you honestly what's involved — and what you already have covered.