Free Resources
Practical compliance resources for Australian organisations
Guides, interactive readiness checklists, and insights — built around what auditors actually look for, not what makes compliance seem harder than it is. Everything here is free.
Answer questions, see your score, download a prioritised PDF roadmap. Takes 12–15 minutes. Gives you an honest baseline and the most important gaps to close first.
Practitioner-level guides on specific topics — what auditors look for, how to build it, what good looks like. Written for CISOs, compliance owners, and technical leads.
Practical articles on compliance strategy, enterprise sales, and implementation — written for teams that need to make compliance decisions, not just read about them.
Interactive readiness checklists
Answer the questions, see your score, and download a prioritised PDF roadmap. Each checklist is mapped to the relevant framework's maturity criteria so the output tells you exactly where you stand — not just whether you pass or fail.
ISO 27001 Readiness Checklist
Score your ISMS across scope, risk management, Annex A controls, SoA, and internal audit. Identify your top gaps and download a prioritised PDF roadmap.
Start checklist →ISO 27701 Privacy Readiness Checklist
Assess your PIMS maturity across ROPA, DPIA, data rights handling, consent management, and third-party privacy risk. Aligned to the Australian Privacy Act.
Start checklist →ISO 42001 AI Governance Checklist
Score your AI Management System across model inventory, AI risk assessment, human oversight, monitoring, and responsible AI policy. Aligned to the AU AI Safety Standard.
Start checklist →Essential Eight Readiness Checklist
Assess your maturity across all eight ASD controls — application control, patching, macros, MFA, admin privileges, backups, and more. Scored to ML1/ML2/ML3 criteria.
Start checklist →Deep-dive guides
Practitioner-level guides on specific compliance topics. Each one covers the standard, what auditors actually check, how to implement it, and what good evidence looks like.
ISO 42001 Reports — Audit-Ready AI Governance Reporting
The six reports an AI management system actually needs — internal audit report, management review, AI risk & impact assessment summary, Statement of Applicability, board report, and auditor evidence pack.
Read guide →What a Good AI System Inventory Looks Like (ISO 42001)
The single most common reason an AIMS falls over at the first audit. What to track, the fields that work, and how to find AI you didn't know was already running.
Read guide →The ISO 42001 Policy Pack — What You Actually Need
A small, coherent set of policies an auditor can trace from statement to evidence — not twenty documents nobody's read since they were written.
Read guide →ISO 42001 vs NIST AI RMF vs EU AI Act — How the AI Governance Frameworks Map Together
A regulation, a risk methodology and a certifiable management system — how they map onto each other clause by clause, and why ISO 42001 is built to sit at the centre.
Read guide →UK Cyber Essentials Readiness — Automated Inside Your Microsoft 365 Tenant
Four of five Cyber Essentials control themes are evidenced from the same Microsoft 365 checks we already run for Essential Eight and ISO 27001. We prepare you; submission goes through an IASME-licensed body of your choice.
Read guide →Privacy Act 2024 Reforms Readiness — What Changed and What to Check
Mandatory breach notification tightened, automated decision-making now needs formal governance, and penalties went up. A practical readiness checklist — standalone from ISO 27701 certification.
Read guide →Ransomware Payment Reporting Readiness — Cyber Security Act Obligations
If you pay a ransom, you now have to report it. A practical guide to the decision authority, reporting process, and how it pairs with an Essential Eight uplift.
Read guide →AI Vendor Risk Assessment — Faster Than Full ISO 42001
A scoped engagement for procurement-driven AI security questionnaires — a defensible answer in weeks, with a clear upgrade path to full ISO 42001 certification later.
Read guide →The Essential Eight Explained — Australia's Complete Cyber Security Guide
What the Essential Eight is, the maturity model (ML1/ML2/ML3), all eight controls in detail, who needs it, how to achieve ML2, and what evidence auditors expect. Updated June 2026.
Read guide →IS18 Compliance for Queensland Government ICT Suppliers — Complete Guide
What IS18 requires, how it maps to Essential Eight and ISO 27001, what an IS18 Compliance Statement must contain, and how to achieve compliance in 4–12 weeks. Essential reading for any QLD Government ICT supplier.
Read guide →ASD Essentials Series: What Replaces the Essential Eight?
ASD is retiring the Essential Eight and replacing it with the Essentials series — a broader framework covering enterprise IT, OT, cloud and agentic AI. Understand what's changing, when, and what to do now.
Read guide →The RFFR SoA Control Library — Every ISM Control, and What Automates
Browse the complete Right Fit For Risk Statement of Applicability: all 989 ISM (June 2026) controls plus the 7 program-deed obligations, filterable by guideline, with Essential Eight maturity and Microsoft 365 automation coverage marked on every control.
Read guide →Inside a Statement of Applicability (SoA)
What auditors expect, how risk links to Annex A, and how to build an integrated SoA across ISO 27001, ISO 27701, and ISO 42001 in Microsoft 365.
Read guide →What a Good ROPA Looks Like — and Common Mistakes
The anatomy of a useful Record of Processing Activities with worked examples, common gaps that trigger regulatory enquiries, and a SharePoint-based implementation guide.
Read guide →AI Governance Readiness — ISO 42001 Explained
Model inventory, AI risk and impact assessments, human oversight, and monitoring — a practical guide to building an AI Management System inside Microsoft 365.
Read guide →Automating Compliance in Microsoft 365, Azure & AWS
How to turn evidence collection, access reviews, and security posture into continuous assurance using tools you already own — no third-party GRC platform required.
Read guide →How to Build a Risk Register in SharePoint
Full column schema, conditional formatting JSON, Power Automate flows, and views — one SharePoint List covering ISO 27001, ISO 27701, and ISO 42001. No third-party GRC platform required.
Read guide →Insights & articles
Practical articles on compliance strategy, enterprise sales, and implementation guidance for Australian organisations.
Does NIS2 Apply to You? If You Have EU Customers, Maybe Already.
NIS2 enforcement is driving ISO 27001 demand across EU supply chains. What to check if you sell SaaS to EU customers.
Read article → APRA · CPS 230CPS 230 Is in Force. Essential Eight Is the Control Backbone Underneath It.
How APRA's CPS 230 and CPS 234 converge, and what an aligned Essential Eight engagement covers for regulated entities and their suppliers.
Read article → ISO 27001 · CostWhat ISO 27001 Actually Costs in Australia (2026)
A practitioner breakdown of certification costs for Australian mid-market organisations — the five real cost components, the GRC platform question, and the line items most cost guides leave out.
Read article → Enterprise Sales3 Compliance Fears Killing Your Enterprise Deals
Why enterprise procurement has changed, what buyers are actually looking for, and how to turn compliance into a competitive advantage.
Read article → ISO 2700113 Things Most People Don't Know About ISO 27001
ISO 27001 is one of the most misunderstood security standards. Here are 13 surprising truths about the ISMS with practical business examples.
Read article → AI GovernanceISO 42001 AI Governance: A Simple, Business-Ready Playbook
A practical guide to implementing ISO 42001 using the tools you already have — Microsoft 365, SharePoint, and simple workflows.
Read article →Real outcomes from Australian organisations
See how organisations like yours achieved certification, improved maturity, and unlocked enterprise contracts — with specific timelines and outcomes.
ISO 27001 Certification in 12 Weeks
Seed-to-Series-A FinTech from fragmented policies to certified ISMS — with reusable sales assurance that closed two enterprise deals immediately after certification.
Read case study →Zero Maturity to Essential Eight ML2 + ISO 27701 + ISO 42001
Health SaaS provider delivered three frameworks in an integrated management system in 10 weeks — unlocking enterprise health system contracts.
Read case study →Free monthly digest
Get the monthly Australian compliance digest
Practical updates on Privacy Act changes, Essential Eight revisions, ISO 27001 news, and real implementation tips — once a month, no spam.
Not sure which resource to start with?
A free 30-minute call will tell you which framework applies to your situation, what your most important gaps are, and what the fastest path to audit-ready looks like. No obligation.