Security Solution Consultants provides cyber security services in Brisbane for Queensland Government agencies, statutory bodies, local councils and the suppliers who serve them, as well as the state’s resources and energy operators.
Queensland’s information security policy was reissued as IS18 version 10.0.0 on 17 June 2026 and carries mandated status. It is no longer the “IS18:2018” that many suppliers still cite in tender responses. It binds Queensland Government departments, accountable officers not otherwise in scope, and statutory bodies under the Financial and Performance Management Standard 2019. Local governments are encouraged rather than mandated.
IS18 v10 sets five requirements, including an ISO 27001 based information security management system and the Essential Eight at an agency-selected target maturity level. That differs from the fixed Maturity Level One in New South Wales, and it makes the target a governance decision rather than a technical default. Annual cyber incident simulations are required. The annual return goes to the Cyber Security Unit and is due 30 September, endorsed by the accountable officer through the audit and risk committee, with the attestation published in the agency’s annual report.

Our Cyber Security Services in Brisbane
- IS18 v10 readiness and annual return support. Gap assessment against the five requirements, ISMS design, and preparation of the return ahead of the 30 September deadline.
- Essential Eight target maturity advice. IS18 lets you select the target level. We help you set it defensibly and evidence it, rather than picking a number and hoping.
- Queensland Information Privacy Act breach readiness. Response plan, the 30 day assessment process and breach register, particularly for councils newly in scope from 1 July 2026.
- ISO 27001 ISMS certification. The direct route to the management system requirement in IS18 v10.
- AESCSF assessment for resources and energy. Framework version 2, relevant to Queensland’s electricity, gas and liquid fuel operators.
- SOCI and CIRMP advisory. For critical infrastructure asset owners, including the enhanced obligations that commenced on 10 June 2026.
What Changed in Queensland This Year
Two things matter. First, IS18 moved to version 10.0.0 in June 2026, so any control mapping built against the 2018 policy is out of date. Second, mandatory notification of data breaches under Chapter 3A of the Information Privacy Act has applied to Queensland state agencies since 1 July 2025 and to local governments since 1 July 2026. Councils are now in scope, assessments must complete within 30 days, and many are discovering they have no documented process.
When we scope cyber security services in Brisbane we check which version of IS18 your existing documentation was written against. It is the single most common gap we find.
GRCLens: Evidence Once, Report Many Times
GRCLens maps IS18, ISO 27001, the Essential Eight, AESCSF and SOCI to one shared control model, so the evidence you gather for the annual return also serves your certification audit and your customer questionnaires. For agencies facing a 30 September deadline, that difference is measured in weeks of effort.
Why Brisbane Organisations Choose Security Solution Consultants
- We work to IS18 v10.0.0, not the superseded 2018 policy still circulating in supplier templates.
- Genuine depth across the Essential Eight, ISO 27001, AESCSF and SOCI in one team, which matters in a state where energy and resources sit alongside government.
- Fixed-scope engagements, so cyber security services in Brisbane come with a defined deliverable and price.
- Remote-first delivery with on-site workshops in Brisbane and regional Queensland where it is warranted.
Cyber security risk assessment in Brisbane
The most common first engagement, and the one worth getting right, because everything else scopes off it.
A risk assessment establishes what you hold, what could go wrong, how likely it is and what it would cost. The output is a risk register you can actually govern from, rated and owned, not a generic threat list with your logo on the cover.
For Queensland Government agencies and statutory bodies, this is the artefact IS18 v10 expects you to maintain and report against. For private suppliers, it is usually what a government or resources-sector customer has asked to see before awarding work.
What it covers: asset and information identification, threat and vulnerability analysis against your actual environment, existing control effectiveness, residual risk rating, and a prioritised treatment plan with owners and dates.
What it is not: a penetration test. A risk assessment tells you what matters and why. A penetration test tells you whether a specific control holds. Buyers are often quoted one when their customer asked for the other.
ISO 27001, SOC 2 and Essential Eight for Brisbane organisations
Three different obligations that arrive for three different reasons, and are frequently confused in Brisbane tenders.
ISO 27001 is the certifiable management system standard, and it is what IS18 v10 names as the basis for an agency ISMS. If a Queensland Government contract or a national customer is asking for certification, this is the route. We publish our ISO 27001 readiness and certification cost ranges rather than making you ask.
SOC 2 is an attestation report produced by a CPA firm, not a certification. It is asked for most often by US-headquartered customers and SaaS buyers. If your driver is a North American client, SOC 2 is usually what they mean even when they say “ISO”.
Essential Eight is a control baseline rather than a certification. IS18 v10 sets the target maturity level as an agency decision, which is different from the fixed Maturity Level One used in New South Wales, and it means the level itself is a governance choice you need to document.
You may need more than one. You rarely need all three at once, and sequencing them properly is usually the largest available saving.
What cyber security costs in Brisbane
Brisbane sits below Sydney and Melbourne on consulting rates, though the gap is narrowing as mining, energy and Queensland Government demand rises.
Current Brisbane market ranges are hourly rates of AUD 150 to 280 or more, day rates of AUD 1,000 to 1,400 or more, and monthly retainers from AUD 2,000 to 10,000 or more. Project work typically runs AUD 3,500 to 22,000 depending on service type and scope.
Full breakdown, including how Brisbane compares with Sydney, Melbourne, Auckland and Wellington, is in our guide to what a cyber security consultant costs in Australia.
Scope drives cost more than headcount does. A thirty-person fintech with three cloud environments and a payments integration is more work than a two-hundred-person firm certifying one office.
Frequently Asked Questions
Is IS18 still called IS18:2018?
No. The current instrument is the Information and cyber security policy (IS18) version 10.0.0, issued 17 June 2026. Referencing the 2018 version in a tender response is a common and entirely avoidable error.
What Essential Eight maturity level does Queensland require?
IS18 v10 requires the Essential Eight but lets the agency select its own target maturity level, unlike the NSW policy which fixes Maturity Level One. The selection needs to be justified and documented.
Do Queensland councils have to notify data breaches?
Yes, since 1 July 2026 under Chapter 3A of the Information Privacy Act. State agencies have been in scope since 1 July 2025. The assessment must be completed within 30 days of becoming aware.
Does IS18 apply to us as a private supplier?
Not directly. It binds Queensland Government agencies and statutory bodies. Suppliers encounter it through procurement and contractual assurance, which in practice means you are asked to evidence equivalent controls.
When is the annual IS18 return due?
30 September, to the Cyber Security Unit, endorsed by the accountable officer through the audit and risk committee. The attestation is then published in the agency’s annual report, so it is a public document.
What does a cyber security risk assessment cost in Brisbane?
Project work in Brisbane typically runs AUD 3,500 to 22,000 depending on scope and service type, with risk assessments at the lower end of that band for a contained single-site scope. Scope drives the number, so we scope before quoting.
Do we need ISO 27001 or SOC 2?
It depends who is asking. ISO 27001 is a certification and is what IS18 v10 names for Queensland Government agency management systems. SOC 2 is a CPA attestation and is usually what US-headquartered customers mean. If a specific contract is driving the requirement, bring the clause and we will tell you which one it actually calls for.
Can you do the work remotely, or do you need to be on site?
Most of it is remote. Site visits are needed where physical security is in scope or where evidence cannot practically be produced any other way. We work across Brisbane and regional Queensland.
Get Started
If you need cyber security services in Brisbane ahead of the 30 September return, request an IS18 v10 gap assessment, an Essential Eight review, or a GRCLens demo. Contact us to talk it through. We also work in Melbourne, Sydney and across New Zealand.


