Security Solution Consultants provides cyber security services in Brisbane for Queensland Government agencies, statutory bodies, local councils and the suppliers who serve them, as well as the state’s resources and energy operators.

Queensland’s information security policy was reissued as IS18 version 10.0.0 on 17 June 2026 and carries mandated status. It is no longer the “IS18:2018” that many suppliers still cite in tender responses. It binds Queensland Government departments, accountable officers not otherwise in scope, and statutory bodies under the Financial and Performance Management Standard 2019. Local governments are encouraged rather than mandated.

IS18 v10 sets five requirements, including an ISO 27001 based information security management system and the Essential Eight at an agency-selected target maturity level. That differs from the fixed Maturity Level One in New South Wales, and it makes the target a governance decision rather than a technical default. Annual cyber incident simulations are required. The annual return goes to the Cyber Security Unit and is due 30 September, endorsed by the accountable officer through the audit and risk committee, with the attestation published in the agency’s annual report.

Cyber security services in Brisbane, a business leader activating a digital security control

Our Cyber Security Services in Brisbane

  • IS18 v10 readiness and annual return support. Gap assessment against the five requirements, ISMS design, and preparation of the return ahead of the 30 September deadline.
  • Essential Eight target maturity advice. IS18 lets you select the target level. We help you set it defensibly and evidence it, rather than picking a number and hoping.
  • Queensland Information Privacy Act breach readiness. Response plan, the 30 day assessment process and breach register, particularly for councils newly in scope from 1 July 2026.
  • ISO 27001 ISMS certification. The direct route to the management system requirement in IS18 v10.
  • AESCSF assessment for resources and energy. Framework version 2, relevant to Queensland’s electricity, gas and liquid fuel operators.
  • SOCI and CIRMP advisory. For critical infrastructure asset owners, including the enhanced obligations that commenced on 10 June 2026.

What Changed in Queensland This Year

Two things matter. First, IS18 moved to version 10.0.0 in June 2026, so any control mapping built against the 2018 policy is out of date. Second, mandatory notification of data breaches under Chapter 3A of the Information Privacy Act has applied to Queensland state agencies since 1 July 2025 and to local governments since 1 July 2026. Councils are now in scope, assessments must complete within 30 days, and many are discovering they have no documented process.

When we scope cyber security services in Brisbane we check which version of IS18 your existing documentation was written against. It is the single most common gap we find.

GRCLens: Evidence Once, Report Many Times

GRCLens maps IS18, ISO 27001, the Essential Eight, AESCSF and SOCI to one shared control model, so the evidence you gather for the annual return also serves your certification audit and your customer questionnaires. For agencies facing a 30 September deadline, that difference is measured in weeks of effort.

Why Brisbane Organisations Choose Security Solution Consultants

  • We work to IS18 v10.0.0, not the superseded 2018 policy still circulating in supplier templates.
  • Genuine depth across the Essential Eight, ISO 27001, AESCSF and SOCI in one team, which matters in a state where energy and resources sit alongside government.
  • Fixed-scope engagements, so cyber security services in Brisbane come with a defined deliverable and price.
  • Remote-first delivery with on-site workshops in Brisbane and regional Queensland where it is warranted.

Frequently Asked Questions

Is IS18 still called IS18:2018?

No. The current instrument is the Information and cyber security policy (IS18) version 10.0.0, issued 17 June 2026. Referencing the 2018 version in a tender response is a common and entirely avoidable error.

What Essential Eight maturity level does Queensland require?

IS18 v10 requires the Essential Eight but lets the agency select its own target maturity level, unlike the NSW policy which fixes Maturity Level One. The selection needs to be justified and documented.

Do Queensland councils have to notify data breaches?

Yes, since 1 July 2026 under Chapter 3A of the Information Privacy Act. State agencies have been in scope since 1 July 2025. The assessment must be completed within 30 days of becoming aware.

Does IS18 apply to us as a private supplier?

Not directly. It binds Queensland Government agencies and statutory bodies. Suppliers encounter it through procurement and contractual assurance, which in practice means you are asked to evidence equivalent controls.

When is the annual IS18 return due?

30 September, to the Cyber Security Unit, endorsed by the accountable officer through the audit and risk committee. The attestation is then published in the agency’s annual report, so it is a public document.

Get Started

If you need cyber security services in Brisbane ahead of the 30 September return, request an IS18 v10 gap assessment, an Essential Eight review, or a GRCLens demo. Contact us to talk it through. We also work in Melbourne, Sydney and across New Zealand.