Our Standards

Trusted frameworks.
Real accountability.

ProTech aligns every client engagement with recognised Australian and international security frameworks - giving you confidence that your IT is built on solid foundations.

Compliance frameworks we work with

We apply these standards practically - in daily operations, not just on paper.

ASD
Essential Eight
Australian Signals Directorate - Essential Eight Maturity Model

The ASD Essential Eight is Australia's baseline cybersecurity framework, mandated or recommended for government and adopted widely across education and critical infrastructure. We implement and maintain all eight strategies for our clients.

Application control
Patch applications
Configure MS Office macros
User application hardening
Restrict admin privileges
Patch operating systems
Multi-factor authentication
Regular backups
VIC GOV
VPDSF / VPDSS
Victorian Protective Data Security Framework & Standards

Victorian Government-mandated standards for organisations handling Victorian public sector data. We assist clients with gap analysis, control implementation, and ongoing compliance reporting aligned to VPDSF/VPDSS requirements.

Data classification & handling
Access control management
Security incident response
Risk management processes
Physical & environmental security
Third-party management
Audit logging & monitoring
Annual compliance reviews
ISO
ISO 27001 Aligned
International Standard for Information Security Management

Our processes and controls are aligned with the ISO/IEC 27001:2022 framework for information security management. While we assist clients pursuing ISO 27001 certification, we are transparent that formal certification is a journey we undertake together.

Information security policies
Asset management
Access control
Cryptography
Physical & environmental security
Supplier relationships
Incident management
Business continuity
NIST
NIST CSF Aligned
NIST Cybersecurity Framework (CSF 2.0)

The NIST Cybersecurity Framework's five core functions - Govern, Identify, Protect, Detect, Respond, and Recover - guide our security practice structure for clients in financial services, professional services, and insurance sectors.

Govern: security governance
Identify: asset & risk management
Protect: access control & training
Detect: anomaly & event detection
Respond: incident response
Recover: recovery planning
PRIVACY
Privacy Act 1988
Australian Privacy Act & Australian Privacy Principles (APPs)

We help organisations comply with the Australian Privacy Act 1988 and the 13 Australian Privacy Principles - including data handling procedures, breach notification preparedness, and privacy impact assessments.

Data collection & use policies
Privacy impact assessments
Notifiable data breach prep
Cross-border disclosure controls
Staff privacy training
Privacy policy documentation
EDUCATION
Education Sector
K–12 School & Education Authority Standards

Schools face unique IT challenges: student data protection, BYOD policies, and departmental compliance. ProTech has hands-on experience supporting K–12 schools with compliant, age-appropriate IT environments.

Student data privacy (Privacy Act 1988 & APPs)
BYOD policy & device management
Content filtering & safe internet
Staff & student account management
Department of Education reporting
Classroom tech support
Core Philosophy

The "Pro Tech" Way

Standards aren't just policies we compile; they are blueprints we operationalise daily. Our custom methodology defines how we support and secure Australian organisations.

01

Local-First Response

Melbourne-centric dispatch

No offshore escalations or automated telephone delays. When a high-impact disruption hits, you interface directly with a senior Melbourne-based engineer who has firsthand knowledge of your network infrastructure.

02

Total Tenant & Account Ownership

Zero vendor lock-in traps

Every cloud workspace, custom domain register, and software subscription we configure is created under your direct corporate legal name. You retain master admin access - ensuring total ownership and freedom.

03

Hardened Security by Design

Essential Eight from day one

We do not treat cybersecurity as a bolt-on accessory. Every routine operating patch, user permission setup, or backup protocol is structurally hardened in strict alignment with ASD guidelines.

04

Radical Operational Transparency

No surprises. No hidden fees.

Say goodbye to ambiguous line items. We guarantee flat monthly rates, all-inclusive reporting, and detailed analytical scorecards detailing exactly how your defensive postures are strengthening.

05

Continuous Team Upskilling

Addressing human-layer vulnerabilities

Because software alone cannot prevent phishing or social engineering, we provide your staff with regular interactive webinars, simulated phishing audits, and targeted cyber-safety micro-trainings.

Why ProTech

The ProTech difference

👥
A full team, not one person
Four dedicated specialists mean you're never left waiting on a single point of failure. If someone's away, the team carries on.
📋
Reports included, always
Monthly performance and security reports are standard - never held hostage behind extra fees or surprise markups.
🔑
You own your accounts
All licences, subscriptions and tenancies stay under your name and your control. We manage them on your behalf, not ours.
1-hour emergency SLA
Enterprise clients receive a guaranteed 1-hour response on critical incidents, with a dedicated account manager as their direct line.
🤝
Honest about our scope
We're straightforward about what we can confidently deliver today and what we'll work toward with you - no overpromising.
Procurement & RFP Support

Compliance documentation for your RFP

Responding to a tender or due-diligence request? We provide a full compliance matrix mapping our controls to Essential Eight, VPDSF, ISO 27001, and Privacy Act requirements.

📋
Compliance Matrix

Our controls mapped against Essential Eight, VPDSF/VPDSS, ISO 27001, and Privacy Act 1988. Available on request for active procurement processes.

Request via quote form →
🔒
Security Policy Summary

A one-page executive overview of our security posture, incident response process, and data handling practices - ready for your information security team.

Request via quote form →
📊
Service Level Agreement

Our standard SLA template for each plan tier, including response times, escalation paths, and uptime commitments - tailored to your requirements on request.

Request via quote form →

Honest about what we do and what we're building toward

We're transparent with every client: we confidently handle the hands-on daily compliance work. For formal state certifications like ISO 27001, we partner with you on that journey - committed to doing the work, not just ticking boxes.