ISO 27001 doesn't fail on paperwork. It fails on people.
Culture IT builds information security management systems that pass certification — and habits that hold up after the auditor leaves.
Four themes. Ninety-three controls.
One culture running through all of them.
ISO/IEC 27001:2022 groups every Annex A control into four themes. Only one is explicitly about people — but people execute the other three.
What we actually deliver
Each of these six stands alone if you need it to, but they're built to interlock into a single ISMS your team can run without us.
Gap Assessment & Roadmap
We map your current controls against Annex A and hand you a prioritised, resourced plan to close the gaps — not a 200-page audit nobody reads.
Risk Assessment & SoA
A risk methodology your team can repeat next year without us, and a Statement of Applicability that reflects real decisions, not copy-paste justifications.
ISMS Documentation & Policy Build
Policies written in language your staff will actually follow, structured so document control doesn't become its own second job.
Security Culture & Awareness Training
Role-specific ISMS user education, phishing simulations, and reporting channels designed so people flag incidents instead of hiding them.
Internal Audit & Management Review
Independent internal audits and management review cycles that catch drift before your certification body does.
Certification & Surveillance Support
We sit alongside you through Stage 1, Stage 2, and every surveillance audit after — no surprises, no scrambling.
The cycle the standard already asks for
ISO 27001 runs on Plan–Do–Check–Act. Most consultancies handle Plan and Do, then leave. We're built around Check and Act — where culture actually forms.
Plan
Scope, risk assessment, Statement of Applicability, policy drafts, and a baseline read on how security actually feels to your staff today.
Do
Controls go live, ownership is assigned by name, and training is built for the role people do — not a generic annual module.
Check
Internal audit, phishing metrics, incident-reporting rates, and management review — measured against behaviour, not just documents.
Act
Nonconformities closed, training refreshed based on what actually happened, and the ISMS adjusted before the next surveillance audit.
Compliance versus culture
"Passing the audit is not the same as being secure."
— why we're called back in after a breach at a certified organisation
Built by people who've sat on both sides of the audit table
Culture IT was founded on a simple observation: most failed ISO 27001 programs weren't missing controls — they were missing buy-in. We work in-house alongside your team rather than handing over a binder and disappearing, because a management system only holds up if the people running it understand why it exists.
We work with small to medium businesses, government, and mining organisations, taking on a limited number of implementations at a time so every engagement gets direct attention through Stage 1, Stage 2, and beyond.
- Sami AndersonCYBER SECURITY DIRECTOR
- Catalina AndersonMARKETING DIRECTOR
- ISO/IEC 27001 ISMS Implementation & Awareness TrainingCORE FOCUS
Start with a readiness call
Twenty minutes, no obligation. We'll tell you honestly whether you're ready to start — or what to fix first.
- contact@cultureit.com.au
- Postal address
- PO Box 40, Forrestfield WA 6058
- Focus
- ISO 27001 ISMS implementation & user education / awareness training