Cyber Security Compliance

Someone Asked You to Prove It

Last updated: July 2026

An insurer wants evidence before renewal. A tender asks which frameworks you meet. A large customer sends a security questionnaire with sixty questions. Your board asks whether the business is compliant, and nobody is quite sure what the honest answer is.

That is when most businesses come to us. Not because they set out to pursue compliance, but because someone has asked them to prove something and the deadline is real.

Free 2-minute checkSample

Where are your passwords kept?

Pick the closest to reality, not the ideal.

Your snapshotSample result
68out of 100
Passwords & identity72
Backups & recovery55
People & email64
See your snapshot

Where this usually starts

Insurer renewal

Your cyber cover is up and the underwriter wants evidence before they renew.

A tender or RFP

A bid asks which frameworks you meet before you are allowed to compete.

A customer's questionnaire

A large customer sends a vendor security questionnaire with dozens of questions.

Your board or investors

The board asks whether the business is compliant, and the honest answer is unclear.

Each of these asks a different question, wants different evidence, and carries a different deadline. Answering the wrong one is expensive.

The first mistake is answering the wrong question

A multi-site Australian retailer came to us through a referral, days from an insurance renewal that suddenly demanded proof of security compliance. They had responded by trying to prove that every supplier in their chain held SOC 2 certification, and had even asked their own accountant whether he was certified.

Nobody had asked for any of that. We read the actual policy and the insurer's requirements, went back to the insurer to clarify what would genuinely satisfy them, and the answer looked nothing like what the business had been chasing. You can read the full case study here.

That pattern is the norm rather than the exception. Under time pressure, businesses reach for the most impressive-sounding standard rather than the one that applies.

Which framework actually applies to you

Essential Eight

The Australian Signals Directorate model, measured in maturity levels. Increasingly what insurers, tenders and government-adjacent contracts ask about. If you have been asked which maturity level you are at, start with our Essential Eight assessment.

Privacy Act 1988

Applies to how you handle personal information, and to what you must do when it is exposed. Health service providers are covered regardless of turnover. The obligations, including breach notification, are covered in our incident response plan template.

PCI DSS

Applies if you take card payments, and the requirements depend on how you take them rather than how large you are. Our PCI DSS guide for Australian business explains which self-assessment path fits your setup.

ISO 27001

The international information security management standard, and the one most often named in enterprise tenders. It is a genuine undertaking rather than a checkbox, and it is worth pursuing when a customer or market genuinely requires it rather than because it sounds authoritative.

Not sure which of these is being asked of you? That is usually the first thing we sort out, and it often costs less than you expect.

Two minutes gives you a first read on where you stand before we even speak.

Start the free 2-minute check

How we get you ready

1

Work out what is actually required

2

Close the gaps that matter

3

Be ready when the auditor or assessor arrives

We start by establishing what is actually required, reading the policy, the tender or the questionnaire rather than guessing at it. Then we assess where you genuinely stand against it and prioritise the gaps that carry real weight, not the ones that are simply easiest to close. Then we architect the environment so that compliance holds by design rather than through ongoing manual effort.

Most businesses discover the gap between what they believed was in place and what is actually running. That is the useful part, and it is better found now than by an assessor.

We are not an auditor, and that matters

Vintaris is an advisory firm. We do not audit, certify or accredit, and any firm that offers to both prepare you and certify you is worth a second look.

What we do is get you to the point where the audit is straightforward. We work with certified auditors, and our job is that when the formal assessment comes, you are already operating from a position of strength rather than assembling evidence in a panic. If insurance is what brought you here, our guide on what insurers now actually check covers the same ground from the underwriting side.

Frequently asked questions

Which compliance framework does my business actually need?

It depends on who is asking and why. An insurer usually wants evidence of specific controls, a government-adjacent tender often asks about Essential Eight maturity, a card-taking business faces PCI DSS, and anyone handling personal information has Privacy Act obligations. Working out which question is actually being asked is the first step, and it frequently narrows the work considerably.

Is the Essential Eight mandatory for private businesses?

It is mandated for non-corporate Commonwealth entities rather than for private businesses generally. In practice it has become a de facto requirement, because insurers, tenders and larger customers increasingly ask which maturity level you have reached.

Does the Privacy Act apply to a small business?

Often yes. There is a small business exemption based on turnover, but it does not apply to health service providers, businesses that trade in personal information, and several other categories. If you hold patient records, the Act applies to you regardless of size.

Can you certify us or issue a compliance certificate?

No. We are an advisory firm, not a certification body. We assess where you stand, close the gaps and prepare you for formal assessment, and we work with certified auditors for the audit itself.

Our insurer is asking for proof of controls. What do they actually want?

Usually evidence that specific controls are genuinely in place and operating, most commonly multi-factor authentication, tested backups, endpoint protection and staff training. The important word is genuinely, since assessors check whether the control was real rather than whether the box was ticked on the application.

Vintaris provides cybersecurity assessment and advisory services. Vintaris is not an auditing or certification body. General information on this page is not legal, financial or insurance advice.

Asked to prove your security and not sure where you stand? Start with a two-minute check.

Start the free 2-minute check