- 03/07/2025
- Posted by: Paul Martinovic
- Category: Blog Posts


Last year, we put a lot of time and effort into gaining our ISO/IEC 27001 certification. While we are proud of our efforts, we didn’t just do it for ourselves. We did it so you can be confident that when you work with us, we prioritise your security.
What is ISO/IEC 27001?
According to iso.org, ISO/IEC 27001 (aka ISO 27001) is “the world’s best-known standard for information security management systems (ISMS).” It defines the requirements an ISMS must meet.
Regardless of size or industry sector, the ISO 27001 standard provides the guidance needed to establish, implement, maintain and continually improve your information security management system – so you can effectively manage the risks related to your data.
What can you expect from us as an ISO 27001 MSP?
In short, gaining ISO 27001 accreditation means that we:
- Have secure systems right across our organisation
- Will pass any compliance audits with flying colours
- Are highly cyber risk-aware and can proactively identify and address weaknesses
- Have validated our industry reputation for credibility and cyber resilience
In summary, achieving ISO 27001 demonstrates that Pinpoint IT has mature IT processes and management and takes a systematic approach to managing sensitive information. In other words, you can trust us to hold ourselves accountable to the highest industry standards.
Additionally, ISO 27001 isn’t a ‘one-and-done’ project. We’re subject to ongoing assessments and audits to ensure we maintain our standards.
What does this mean for you?
At a time when cybercrime is on a steep and seemingly unstoppable rise, we challenged ourselves to do better when it comes to keeping our business and our customers safe.
Our accreditation benefits both our customers who have achieved ISO 27001 themselves and those who have instead made the strategic decision (due to their own internal time, resource, and focus constraints) to only engage with ISO accredited partners.
For those who are ISO 27001 accredited, it provides the confidence that we will demonstrate the same level of experience, capabilities and commitment as you.
If you’re a small or medium business that isn’t ISO 27001 accredited, it means you can rely on us to uphold the highest industry standards on your behalf so that you can concentrate on business growth.
We’re qualified to protect your information as well as ours. To give you an analogy, in choosing to work with an ISO 27001-accredited MSP, you will essentially step up from using a bookkeeper to working with a seasoned and qualified accountant. There’s a world of difference.
ISO 27001 accreditation and the critical infrastructure sector
The Australian 2022 Critical Infrastructure Protection Act evolved from the SOCI (Security of Critical Infrastructure) Act of 2018. Whereas the original act covered just four critical infrastructure sectors (electricity, gas, water, and ports), the reforms in 2021 and 2022 saw that list expanded to cover eleven ‘critical infrastructure sectors’ and twenty-two categories of ‘critical infrastructure assets.’
The new critical infrastructure sectors include:
- Communications
- Food and grocery
- Health care and medical
- Financial services and markets
- Data storage or processing
- Defence industry
- Higher education and research
- Energy
The responsibilities of organisations within these sectors include the requirement to document, regularly review and update their risk management program. As part of this, they must also establish and maintain a process/system for complying with ISO/IEC 27001:2015, and the Essential Eight Maturity Model (or an equivalent framework).
The new act prompted many critical infrastructure organisations, for example, those in defence, to require their MSP to be ISO 27001 qualified.
ISO 27001 accreditation and the financial services sector
For those in the financial services industry, the new prudential standard issued by APRA (Australian Prudential Regulation Authority) is aimed at ensuring banks, insurers and superannuation trustees can better manage operational risks and respond to business disruptions.
The Prudential Standard CPS 230 Operational Risk Management (CPS 230) applies from July 2025. In APRA’s words, it provides a foundation for APRA-regulated entities to strengthen operational risk management through new requirements to address identified weaknesses in existing controls; improve business continuity planning to ensure they are positioned to respond to severe disruptions; and enhance third-party risk management by ensuring risks from material service providers are appropriately managed.
This means that if you are in this sector, your MSP is required to meet specific standards. These standards can include SOC 2, ISO 27001, and HIPAA accreditation (they’re all seen as gold-standard solutions when it comes to alignment with APRA compliance requirements). These global standards are seen as providing a strong baseline and independent verification that your MSP has satisfied their obligations in the areas of risk management, business continuity management, information security, and operational risk management.
Summary
Whether you are a critical infrastructure organisation, in the financial services industry, or are just looking for the best possible security partner – one who has demonstrated the highest level of commitment to keeping your sensitive data – we’re here to help.
Please call us or email enquiries@pinpointit.com.au if you’d like to discuss what we can do for you.
