We help Australian organisations identify and prioritise risk, apply the right controls and verify they work, and meet the standards customers and regulators expect: ISO 27001, PCI DSS and practical maturity improvement.
years testing for government and enterprise
CREST-accredited through CREST ANZ
dotSec is a PCI QSA Company, a PCI DSS-compliant service provider and ISO 27001 certified.
Our advice comes from implementing and maintaining these standards ourselves, not just assessing others.
From certification to a maturity roadmap, our GRC work is practical, evidence-driven and scoped to your risk.
Gap analysis, ISMS implementation and certification support, with fixed or capped pricing.
QSA-led ROCs, gap analysis and SAQ preparation, with a focus on reducing your compliance scope.
A structured view of control effectiveness, governance and risk, with a prioritised improvement roadmap.
Understand which risks matter most, based on operational realities, compliance requirements and business goals.
Turn risk decisions into practical, risk-based controls aligned with your business.
Confirm through testing and assessment that your controls work as intended.
Independent, senior and practical, from a team that has been operating for more than 25 years.
Our consultants bring deep technical and governance knowledge from more than 25 years of hands-on security work.
Our advice and services focus on risk, outcomes and evidence, not product sales.
We work with technical and business stakeholders to deliver realistic, sustainable improvements, and we are happy to complement your in-house team.
We understand the regulatory, threat and industry landscape Australian organisations operate in.
Yes. We work across technical security and governance, risk and compliance. We are ISO 27001 certified and a PCI DSS-compliant service provider, and our team includes PCI QSA, ISO 27001 assessor and implementer certifications.
Yes. ISO 27001, the Essential Eight, APRA CPS 234 and PCI DSS overlap substantially, and running them as one engagement avoids duplicating evidence collection and control testing.
Yes, through workshops, executive briefings, technical knowledge transfer and awareness activities, aligned to real-world threats and your compliance requirements.
Yes. For PCI DSS, for example, we can run the gap analysis and remediation and hand a remediation-complete environment to your chosen QSA for the formal ROC.
Need certification, a compliance gap analysis or a clear maturity roadmap? We will scope the work around your risks, timeline and budget.
Fixed or capped pricing is available, and we will reduce your scope wherever we legitimately can.
Practical and experienced Australian ISO 27001 and ISMS consulting services. We will help you to establish, implement and maintain an effective information security management system (ISMS).
dotSec’s penetration tests are conducted by experienced, Australian testers who understand real-world attacks and secure-system development. Clear, actionable recommendations, every time.
dotSec stands out among other PCI DSS companies in Australia: We are not only a PCI QSA company, we are a PCI DSS-compliant service provider so we have first-hand compliance experience.
Web Application Firewalls (WAFs) are critical, protecting web apps and services by inspecting and filtering malicious requests before they reach your servers. Web page or API, a WAF is your first defence.
Multi-Factor Authentication (MFA) and Single Sign-On (SSO) reduce password risks, simplify access, letting verified and authorised users reach sensitive systems, services and apps.
dotSec provides comprehensive vulnerability management services. As part of this service, we analyse findings in the context of your specific environment, priorities and threat landscape.
We don’t just test whether users will click a suspicious link — we also run exercises, simulating phishing attacks that are capable of bypassing multi-factor authentication (MFA) protections.
dotSec’s penetration testing services help you identify and reduce technical security risks across your applications, cloud services and internal networks. Clear, actionable recommendations, every time!
dotSec has provided Australian managed SOC, SIEM and EDR services for 15 years. PCI DSS-compliant and ISO 27001-certified. Advanced log analytics, threat detection and expert investigation services.
We provide prioritised, practical guidance on how to implement secure configurations properly. Choose from automated deployment via Intune for Windows, Ansible for Linux or Cloud Formation for AWS.
Secure web hosting is fundamental to protecting online assets and customer data. We have over a decade of AWS experience providing highly secure, scalable, and reliable cloud infrastructure.
dotSec helps organisations to benefit from the ACSC Essential Eight by assessing maturity levels, applying practical security controls, assessing compliance, and improving resilience against attacks.
Evaluation against the CIS 18 Controls establishes a clear baseline for stakeholders, supporting evidence-based planning, budgeting, maturity-improvement and compliance decisions
We have over 25 years of cyber security experience, providing practical risk-based guidance, advisory and CISO services to a wide range of public and private organisations across Australia.