Compliance & Governance
Governance & Data Protection
Governing your data, controlling who can reach it, and proving both. For SMB1001 certification specifically, see our dedicated page.
Looking for SMB1001? Certification readiness now has its own page. See SMB1001 certification for tiers, pricing and how the process works. Backup & recovery and security awareness training also have pages of their own.
Data Governance and Records Management
Ensuring business data is structured, retained, and disposed of in line with policy and regulatory requirements.
- Deployment and management of governance platforms such as AvePoint for Microsoft 365
- Data classification, retention, and disposition policies
- Records management and audit trail maintenance
- Reporting on data sprawl, ownership, and lifecycle
Access and Permissions Governance
Managing who has access to what across a business's systems, and proving it.
- Permissions auditing and clean-up across Microsoft 365 and other platforms using AvePoint
- Access reviews and approval workflows
- Reporting on over-permissioned accounts and shared content
- Ongoing governance policy enforcement
Regulatory Compliance
Helping businesses meet obligations under relevant Australian frameworks and international standards.
- Gap assessments and certification support against ISO 27001 (information security management)
- SMB1001 certification readiness: see our SMB1001 page
- Gap assessments and certification support against ISO 42001 (AI management systems)
- Alignment with the ACSC Essential Eight maturity model
- Compliance with the Australian Privacy Act and the Notifiable Data Breaches scheme
- Remediation planning and implementation support
- Ongoing compliance monitoring and reporting
- Support preparing for external audits and certification renewals
Data Loss Prevention and Sensitivity Labelling
Preventing sensitive information from being shared, stored, or accessed inappropriately.
- Classification and labelling of sensitive data
- Data loss prevention (DLP) policy configuration
- Monitoring and alerting on policy breaches
- Reporting for compliance and audit purposes