IT Compliance & Risk Management for Perth Firms

When AHPRA, the Law Society, CPA Australia or your cyber insurer asks how client data is protected, "our IT guy handles it" isn't an answer. We implement and evidence the controls they actually check — multi-factor authentication, tested backups, patching and monitoring — mapped to the Essential Eight.

Perth-Based · ABN 16 696 780 597 · Fixed-Scope Engagements · No Lock-In

Who's Asking, By Industry

Compliance isn't abstract — a named regulator, professional body or insurer sets the expectations for your industry. These are the ones Perth firms answer to.

CPA Australia · CA ANZ · TPB

Accountants & Bookkeepers

The Tax Practitioners Board expects practices to protect client data and control who can access it; the ATO's digital service standards assume MFA and secure access as a baseline. We set up IT for accounting firms that stands up to both.

Legal Practice Board WA · Law Society WA

Law Firms

Confidentiality and trust-account integrity are professional obligations, not IT nice-to-haves. Matter files, email and remote access get locked down so privilege doesn't depend on luck. See how we support professional practices.

AHPRA · RACGP

Medical & Allied Health

AHPRA-registered practitioners must keep health records secure and available; RACGP's standards spell out backups, access control and secure messaging. Our healthcare IT support is built around exactly that.

TGA · Pharmacy Board

Pharmacy & Pharmaceutical

Dispensing records, cold-chain monitoring and supplier systems fall under TGA and Pharmacy Board record-keeping expectations — with the same Privacy Act duties as every other health provider.

And for everyone: the Privacy Act and the OAIC

The Notifiable Data Breaches scheme means eligible breaches must be reported to the OAIC and your clients. All health service providers are covered regardless of size — and financial services firms answer to ASIC and AFSL obligations on top. The controls below are the same ones every one of these bodies expects to see.

The Controls, By Name

Regulators and insurers don't ask "are you secure?" — they ask for specific controls. These are the ones on the questionnaire, each mapped to the ACSC Essential Eight.

Multi-Factor Authentication

MFA on email, remote access and admin accounts, enforced by policy rather than left to each person's judgement. The single control every insurer now demands.

Essential Eight: Multi-Factor Authentication

Backups That Restore

A backup nobody has tested is a hope, not a control. We configure automated backups and actually run restore tests, with evidence you can hand over.

Essential Eight: Regular Backups

Patching, On Schedule

Operating systems and applications updated on a defined cycle, with a record of what was patched and when (not "Windows updates itself, probably").

Essential Eight: Patch Applications & Operating Systems

Monitoring & Alerting

Someone actually watching: endpoint alerts triaged, sign-in anomalies flagged, and a monthly snapshot of what was caught. Part of our Security Essentials baseline.

Supports every Essential Eight strategy

Admin Rights, Restricted

Day-to-day accounts don't run as administrators, and privileged access is limited to the people who need it: reviewed, not accumulated.

Essential Eight: Restrict Administrative Privileges

Microsoft 365, Hardened

Conditional Access, Defender and data-loss controls configured across your tenant in one fixed-scope pass — our Microsoft 365 security hardening engagement.

Implements multiple Essential Eight strategies in M365

Renewing cyber insurance?

If the trigger is an insurer's questionnaire, our cyber insurance readiness check verifies MFA, backups, EDR and patching against the questions and prepares the evidence before you answer anything.

AI Is the Newest Compliance Gap

Staff are already pasting client information into public AI tools — usually with good intentions and no policy. For regulated professions, that's a confidentiality problem before it's a productivity win.

Find the shadow AI

Our fixed-fee AI risk assessment maps which AI tools are actually in use across your business, what data is going into them, and where the exposure sits.

Set a usable policy

A practical AI usage policy your staff will actually follow — what's allowed, what never leaves the building, and which tools are approved. Training available through our AI workshops.

What It Costs

Compliance uplift work is scoped and quoted in writing before anything starts — most engagements are fixed-scope with a defined deliverable and evidence pack.

Fixed-scope

Uplift engagements

Compliance reviews, Essential Eight uplifts, M365 hardening and insurance readiness are quoted as fixed-scope projects, so you know the number before we start.

Hourly

$180/hr ex GST

Ad-hoc labour is one-hour minimum, then 30-minute increments. It is the same published rate as everything else we do. See what an hour covers.

These are internal technical reviews and uplift work, not government-accredited audits. If a tender needs a certified assessor, we'll tell you and point you the right way.

Answer the Questionnaire With Confidence

Tell us which regulator, standard or insurer is asking, and we'll tell you honestly what's involved — and what you already have covered.

Need IT help? Call 1300 769 337