Security & Compliance

ISO 27001 Readiness for Perth Businesses

We prepare Perth small and mid-size businesses for ISO 27001 certification — a gap assessment against Annex A, a remediation roadmap, the technical controls built in Microsoft 365, and your evidence organised before the auditor asks for it.

Certification-ready, without the consultant circus

ISO 27001 has stopped being a big-company badge. Perth businesses tendering for enterprise and government work are now asked for it as a condition of entry, and the security questionnaires that arrive with every cyber-insurance renewal overlap so heavily with the standard that answering one honestly means doing most of the other anyway. If your pipeline includes mining services, government supply chains, or any client with a procurement team, the question is increasingly when, not whether.

One thing stated plainly up front: Support Perth is not a certification body. ISO 27001 certificates are issued by accredited external auditors, and anyone offering to sell you the certificate directly is not doing it properly. What we do is get you ready — a gap assessment against the Annex A controls, a prioritised remediation roadmap, the technical controls implemented properly in Microsoft 365, a policy set your business will actually follow, and an evidence pack organised the way auditors expect to find it. Then we stand beside you during the audit itself.

If we have already done Essential Eight work for you, you are further along than you think — the identity, patching, backup, and application-control uplift maps directly onto Annex A, and readiness becomes a matter of formalising what is already running. ISO 27001 sits at the top of the compliance ladder we help Perth businesses climb, and most of it is built from controls we implement every week.

What's Included

Gap & Readiness Assessment

A control-by-control review against ISO 27001 Annex A covering your Microsoft 365 tenant, devices, policies, and day-to-day practice — delivered as a scored report you can hand to the board.

Remediation Roadmap

A prioritised, sequenced plan for closing every gap the assessment finds — what to fix first, what each item involves, and what can safely wait — so the path to audit-ready is concrete.

Scope & Statement of Applicability

Help defining a sensible ISMS scope for a business your size and drafting the Statement of Applicability — the document that tells the auditor which controls apply to you and why.

Identity & Access Controls in M365

MFA enforced properly, Conditional Access policies, least-privilege admin roles, and a joiner-mover-leaver process — access control implemented in Entra ID rather than described in a binder.

Device Management with Intune

Company and BYO devices enrolled in Intune with compliance policies, disk encryption, and screen-lock enforcement — evidence-ready device control instead of an honesty system.

Logging, Backup & Recovery

Audit logging with sensible retention, alerting on the events that matter, and backup that is actually tested — the operational controls certification auditors probe hardest.

Policy Templates, Adapted

An information-security policy set written for a business your size — adapted to how you actually operate and short enough that staff read it, not a 200-page template dump.

Audit Evidence Pack

Evidence collected, organised, and mapped to each applicable control before the auditor asks — configurations, registers, training records, and signed policies in one place.

How It Works

Scoping call

A free 15-min call to understand your business, why ISO 27001 is on the table, and roughly what scope makes sense. You get a fixed written quote — not an estimate that drifts.

Gap assessment

We review your Microsoft 365 tenant, devices, policies, and practices against the Annex A controls and interview the people who actually run things. You get a scored report showing exactly where you stand.

Remediation

We work through the roadmap: identity and MFA hardening, device management in Intune, logging, backup, and the policy set — implemented properly, not just documented.

Evidence preparation

We collect and organise the evidence each control needs — configurations, logs, registers, signed policies — mapped so the auditor can find everything without a scavenger hunt.

Certification audit support

You engage an accredited certification body — we help you choose one. During the audit we are in the room, answering the technical questions and producing evidence on request.

Why Support Perth for ISO 27001 Readiness?

One Senior Engineer, End to End

The person who scopes the work does the work. No junior consultants learning on your tenant, no handoff between a sales engineer and a delivery team, no project-manager layer between you and answers.

Built on Essential Eight Foundations

Readiness work extends the Essential Eight assessments and uplifts we already run for Perth businesses — the same identity, patching, and backup controls, formalised to the standard an external auditor expects.

Fixed Written Quote

Readiness is quoted as a fixed price after the scoping call, so the budget conversation happens once. Ad-hoc work outside scope is $180/hour (excl. GST). No lock-in, no surprise invoices.

Local, 7-Day-a-Week Support

Aaron is based in Perth and available 7 days a week. When the auditor emails a question the afternoon before the stage-two visit, you are not waiting on an east-coast ticket queue.

ISO 27001 Readiness FAQ

Does Support Perth issue the ISO 27001 certificate?

No — and nobody selling you a certificate directly should. Certification is issued by an accredited certification body after an independent audit. We prepare your business for that audit, fix what the gap assessment finds, and sit beside you when the auditor arrives.

How long does readiness take?

It depends on your size and starting point. A small Microsoft 365-based business with some security work already done is typically audit-ready in three to six months. Existing Essential Eight maturity shortens the runway considerably, because much of the technical groundwork is already in place.

What does it cost?

Every engagement gets a fixed written quote after a scoping call — the price depends on headcount, the scope of your ISMS, and how much groundwork already exists. Ad-hoc work outside the quoted scope is billed at $180/hour (excl. GST).

Does a small business actually need ISO 27001?

Only if a contract, tender, or insurer is asking for it — or soon will be. For many Perth SMBs the Essential Eight is the right first step and covers most real-world risk. If that is true for you, we will say so in the scoping call rather than sell you a standard you do not need.

Related Services

Essential 8 Assessment

A maturity assessment against the ACSC Essential Eight — the Australian baseline that covers most real-world risk and does much of the technical groundwork ISO 27001 formalises.

IT Compliance

The full compliance picture for Perth businesses — Essential Eight, cyber-insurance questionnaires, client security requirements, and where ISO 27001 fits on the ladder.

Cyber Security

Day-to-day security for your business — endpoint protection, email security, and the hardening work that keeps the controls in your evidence pack true between audits.

Find out exactly where you stand

A gap assessment that tells you where you are, a roadmap with no padding, and the controls implemented by the same senior engineer who scoped them — so you walk into the certification audit prepared, not hoping.

Or leave your details and we will come to you

One field to start. A senior Perth engineer replies within 2 hours, 7 days a week.

We usually respond within 2 hours. $180/hr ex GST, one-hour minimum, then 30-minute increments. No call-out fee in metro Perth.

Need IT help? Call 1300 769 337