About · Whitesec AU
An independent compliance and readiness advisory for Australian SMEs.
We build your controls, write operational policies, and execute internal pre-audits. Because ISO standards prohibit consultants from auditing their own work, an accredited certification body performs the final assessment.
- Base
- West Perth, WA
- Coverage
- Australia-wide
- Role
- Advisory, not a certifier
- Billing
- Fixed-scope packages
The Whitesec model
What makes us different is mostly what we refuse to do.
01 — Independent by design
We prepare you. We never certify you.
ISO rules keep consultancy and certification strictly separate, and we hold that line on purpose. We build the ISMS and run your internal pre-audits, then an accredited certification body assesses you impartially and issues the certificate. Your certification stands up because the people who graded it weren't the people who prepared it.
- We do
- ISMS build · defensible evidence · pre-audit · remediation · vCISO
- We don't
- Issue certificates · assess our own work · sell you the audit too
02 — Fixed scope, fixed price
You approve the deliverables and the fee before we start.
Readiness runs as a defined package. The scope is written into the proposal and the fee is agreed up front, so compliance becomes a line item you can budget rather than an open-ended bill you can't predict. The price only moves if you change the scope in writing.
- Deliverables listed in the proposal, not discovered later
- One fixed fee, agreed before kickoff
- No hourly meter and no quiet scope creep
How an engagement runs
Five stages, in order, from a gap to a handover.
The sequence is the same whether you're chasing ISO 27001, Essential Eight, or SMB1001. Only the framework changes.
- 01
Scope
Confirm the framework, boundary, and deadline. Fix the deliverables and price.
- 02
Assess
Gap analysis against the standard. Findings scored, not just listed.
- 03
Build
ISMS, policies, and controls put in place and mapped to evidence.
- 04
Pre-audit
Internal audit and management review, so Stage 1 holds no surprises.
- 05
Certification support & handoff
Evidence file handoff and live support during Stage 1 and Stage 2 independent auditor assessments.
Certification bodies
We prepare you for the audit. An accredited body runs it.
Independent certification bodies our clients frequently engage for Stage 1 and Stage 2 audits. We are not affiliated with them, and naming them signals independence, not endorsement.

Certification body
BSI Group

Certification body
PECB
Who runs it
Two founders, both practitioners, accountable on every engagement.
Co-Founder · Practice Lead
Galang Muthohhari
Runs the technical practice: offensive security, VAPT, and the hands-on verification behind every readiness engagement.
Co-Founder · Strategy Lead
Zibusiso “Zi” Dewa
Runs strategy and delivery: turning regulatory obligations into scoped, audit-ready outcomes clients can act on.
Credentials across the practice
- CISSP
- CEH
- OSCP
- ISO 27001 Lead Auditor
- ISO 27701
- GRCP
Book a 30-minute readiness consult.
We'll scope your gap, name the right package, and give you a fixed price. No obligation, and nothing to sign to have the conversation.