Australian Cybersecurity Consultancy · Est. 2017

Cybersecurity Architecture
for Complex Organisations.

Helping organisations strengthen security, manage risk and make informed technology decisions through architecture, assurance and independent advisory services.

Book a Security Consultation Request an architecture review
NIST CSFISO 27001SABSAZero TrustASD Essential EightAPRA CPS 234SOCI ActAI Governance
2017
Established in Australia
100%
Independent advisory
6+
Industry verticals
AU/NZ
Regional coverage

WHY ORGANISATIONS CHOOSE HEXOSYS

Chosen on evidence, not claims.

18+ YEARS ICT PRACTICE Advisory grounded in hands-on practice across complex, high-stakes environments - not theory delivered from a slide.
12+ YEARS SECURITY ARCHITECTURE A decade designing and assuring architecture across advisory, assurance and technical design.
ENTERPRISE & REGULATED DEPTH Critical infrastructure, financial services and government - where assurance is non-negotiable.
FRAMEWORK-ALIGNED BY DESIGN Programs mapped to ISM, PSPF and NIST so security and compliance reinforce one another.
INDEPENDENT BY PRINCIPLE Vendor-neutral advice aligned to your outcomes across the whole engagement lifecycle.
RISK-INFORMED ASSURANCE Assurance shaped by real-world risk, focused on the obligations that matter.

We do not stop at recommendations. Where the engagement requires it, we help implement, deploy, validate and operationalise the security changes we design.

DESIGNIMPLEMENTVALIDATEOPERATE

SECURITY EXPERTISE ACROSS EVERY DISCIPLINE

Security expertise across every discipline.

Cybersecurity Architecture

A coherent security architecture that aligns protection to business strategy and risk appetite.

LEARN MORE

Security Strategy & Roadmaps

Board-ready strategy and a prioritised multi-year roadmap that sequences investment.

LEARN MORE

AI Security & Governance

Governance and assurance that let the organisation adopt AI with confidence.

LEARN MORE

Cloud Security Architecture

Architecture-led cloud security across Azure, AWS and hybrid estates.

LEARN MORE

Security Compliance & Assurance

Compliance evidenced through architecture: ready for regulator and auditor scrutiny.

LEARN MORE

Security Transformation

Change delivered hands-on: implementation, integration, validation and handover.

LEARN MORE
RELATIONSHIP

Hover a discipline to see how it works with the others. Click to hold the relationship.

WHAT CLIENTS RECEIVE

An evidence chain, not a report dump.

Assessment
EXAMINED
Evidence
VERIFIED
Architecture Decision
GOVERNED
Deliverable
IN WRITING
Action
DELIVERED

HOVER A STAGE TO SEE WHAT ENTERS AND LEAVES IT

HOW HEXOSYS DELIVERS SECURITY OUTCOMES

A methodology that moves in sequence.

1
Understand
Business context, threat landscape, strategic priorities.
2
Assess
Evidence-based review of risks, gaps and maturity.
3
Design
Security architecture and roadmap with measurable outcomes.
4
Implement
Advisory and assurance support driving secure delivery.
5
Improve
Continuous improvement building lasting capability.

HOW WE OPERATE

Independent. Expert. Outcomes-focused.

Independent.

No vendor affiliations and no product sales incentives - our only obligation is the right security outcome for your organisation.

  • Vendor neutrality on record for every engagement
  • No commissions, no partner incentives
  • Evidence-based recommendations only
Expert.

Senior practitioners on every engagement - architecture-led thinking from people who have designed and assured real systems.

  • 18+ years ICT · 12+ years security architecture
  • Government and regulated enterprise systems
  • Design, assurance and hands-on delivery
Outcomes-focused.

Effort goes where it reduces the most risk - advice is tied to outcomes and obligations, not products.

  • Risk-weighted roadmaps with sequencing and cost
  • Every action traceable to an obligation
  • Outcomes verified, not asserted

STRATEGIC SECURITY LEADERSHIP

The executive security decision loop.

Governance sets the boundaries. Risk informs priorities. Strategy sets direction. Architecture makes it real. Investment funds what can be defended. Assurance produces the evidence and closes the loop.

EXECUTIVE DECISION ARCHITECTURE

Six decisions, one closed loop.

Every executive security decision feeds the next: governance frames risk, risk shapes strategy, strategy directs architecture, architecture justifies investment, and assurance returns the evidence that closes the loop. Select a decision to see what informs it and what it drives.

WHAT CLIENTS ACHIEVE

Outcomes that trace back to architecture.

Reduced cyber risk exposure

Effort sequenced where it removes the most real-world risk first.

Improved architecture maturity

A reference architecture the whole organisation can build against.

Stronger compliance posture

Controls mapped to clauses, evidenced the way assessors assess.

Clearer technology decisions

Choices anchored to a target architecture, not a product pitch.

Reduced audit findings

Findings fixed at the architecture, so they do not come back.

Better executive visibility

Security explained in decisions and evidence, not jargon.

CLICK AN OUTCOME TO SEE PROBLEM → ARCHITECTURAL ACTION → EVIDENCE → OUTCOME.

SECTOR EXPERTISE FOR COMPLEX ENVIRONMENTS

Sector context decides the frameworks.

Hover a sector to preview, click to hold it - the obligation map lights the frameworks that typically govern that environment. [DRAFT MAPPINGS]

Government & DefenceProtective security and sovereign assurance obligations
Financial ServicesPrudentially regulated information security and resilience
Critical InfrastructureSystems of national significance and OT environments
Health & CareSensitive personal information at clinical scale
Higher Education & ResearchOpen collaboration with high-value research assets
Energy & UtilitiesConverged IT/OT with continuity-critical operations

GOVERNING FRAMEWORKS & OBLIGATIONS

Information Security ManualISMProtective Security Policy FrameworkPSPFASD Essential EightE8APRA CPS 234CPS234APRA CPS 230CPS230PCI-DSSPCISOCI ActSOCIIEC 62443IECNIST CSFNISTPrivacy Act 1988PRIVISO 27001ISO

Select a sector to see its typical governing set.

SECURITY THINKING

Security thinking from our experts.

Explore all insights
FEATURED · AI GOVERNANCE

The CISO's Guide to AI Governance

A practical governance model for adopting AI with confidence - managing risk while enabling business value. Decision paths, control points and a prioritisation structure boards can follow.

8 MIN READ · FRAMEWORK-ALIGNEDREAD →
COMPLIANCE & FRAMEWORKS

APRA CPS 234 Explained

Information-security obligations for regulated entities: what CPS 234 requires, how architecture evidences it, and how it sits beside CPS 230 operational resilience with CPS 220 risk context.

9 MIN READ · REGULATORYREAD →
ESSENTIAL EIGHT

Essential Eight ML3: A Practical Path

Reaching Maturity Level 3 the way ASD assesses it - evidenced, sequenced and independently verifiable, with control checkpoints at every step.

11 MIN READ · ASD-ALIGNEDREAD →

SECURITY FRAMEWORKS

Frameworks and standards we work across.

Your engagement determines what applies - regulatory obligations, sector context and architecture patterns decide the standards we bring to the work. The groups below are representative, not exhaustive.

CORE ARCHITECTURE

NIST CSFISO 27001SABSAZERO TRUSTISMPSPF

The structural frameworks - how the security architecture itself is organised, governed and evidenced.

REGULATORY

APRA CPS 234APRA CPS 230SOCI ACTPRIVACY ACT 1988

Obligations that bind your sector - controls mapped to clauses, ready for regulator and auditor scrutiny.

OPERATIONAL

MITRE ATT&CKCIS CONTROLSOWASPESSENTIAL EIGHT

How attacks actually happen and the controls that interrupt them - grounded in adversary behaviour.

ASSURANCE & CLOUD

SOC 2PCI-DSSIEC 62443CSAAI GOVERNANCE

Evidence for customers and partners - certifications and attestations your market recognises.

REPRESENTATIVE - YOUR ENGAGEMENT DEFINES THE APPLICABLE SET

DEFENCE IN DEPTH - INTERACTIVE

One architecture, seen through four lenses.

Security architecture that makes defence simpler to operate and harder to bypass.

HOVER = PREVIEW · CLICK = HOLD · [DRAFT COPY]
HEXOSYS - Zero Trust defence in depth Defence in depth,verified at every layer. Every request is evaluated against identity, device,network and application controls before itis allowed anywhere near data. IDENTITY DEVICE NETWORK APPLICATION DATA ALLOW DENY ALLOW NIST CSFGovern · Identify · Protect ISO 27001ISMS certification readiness SABSABusiness-driven architecture ZERO TRUSTNever trust, always verify VERIFY EXPLICITLY · LEAST PRIVILEGE · ASSUME BREACH

The full defence-in-depth system. Every request is evaluated at identity, device, network and application before it is allowed anywhere near data - verified explicitly, least privilege, assume breach.

NIST CSF gives the whole stack a common language - Govern, Identify and Protect applied at every layer, so each control maps to business risk and board reporting. HEXOSYS uses it to structure assessment and board-level reporting.

ISO 27001 turns the layers into an auditable management system - access control evidenced at the identity boundary, secure operations at the application boundary. HEXOSYS uses it to make the architecture certifiable.

SABSA derives every layer from business attributes - each ring exists because a business requirement demands it, traceable from strategy to control. HEXOSYS uses it to keep design decisions business-owned.

Zero Trust assumes breach - the identity perimeter is the strongest ring, every gate verifies explicitly, and ALLOW or DENY is decided at each crossing. HEXOSYS uses it to design the control points and their evidence.

ENGAGE - A GOVERNED PATH, NOT A FORM DROP

Discuss your security challenges with an architect.

STAGE 01 · VALIDATED
Initial enquiry
Acknowledged within one business day - no triage queue, no sales layer.
STAGE 02 · MAPPING
Architect scoping
A senior architect maps your context, obligations and priorities.
STAGE 03 · VERIFIED
Written proposal
Scope, approach, deliverables and cost - in writing, for your records.

Services & Capabilities

Every capability.
One trusted partner.

Integrated cybersecurity consulting across strategy, architecture, assessment and transformation.

Strategy

Security Strategy & Roadmaps

Executive-level security strategies aligned to business objectives and regulatory obligations, with multi-year roadmaps and investment prioritisation. We translate risk and compliance drivers - from APRA CPS 234 to the ASD Essential Eight - into board-ready priorities and a sequenced investment plan, often informed by an initial security assessment.

Strategy DevelopmentMulti-Year RoadmapsBoard ReportingSecurity Governance

Architecture

Cybersecurity Architecture

Enterprise security architecture using SABSA, Zero Trust and cloud-native security patterns, from reference architecture to detailed technical design. Controls are designed into systems from first principles rather than retrofitted, with reusable patterns that hold consistency across platforms. Explore our architecture capabilities.

SABSAZero Trust DesignNetwork SecurityIAM ArchitectureData Protection

AI Security

AI Security & Governance

AI risk frameworks, governance models and secure AI architecture to safely adopt artificial intelligence at enterprise scale with appropriate controls. We help organisations govern AI across its lifecycle - from data and model risk through to deployment assurance - so innovation proceeds within a defensible control environment. See our AI security approach.

AI GovernanceAI Risk AssessmentsSecure AI ArchitectureAI Assurance

Cloud

Cloud Security Architecture

Confidence that cloud and hybrid environments are designed and governed securely, supporting resilient, compliant business operations. This spans identity and access design, workload protection and secure landing zones across major cloud platforms, aligned to recognised cloud security benchmarks.

Azure SecurityAWS SecurityCSPMContainer Security

Compliance

Security Compliance & Assurance

Navigate complex regulatory and compliance obligations with structured assurance programs across Australian and international standards, including ISO 27001, the ASD ISM and PCI DSS. Assurance is mapped to the obligations that apply to your sector, giving executives and boards clear evidence of control effectiveness.

ISO 27001NIST CSFEssential EightAPRA CPS 234SOCI Act

Transformation

Security Transformation

End-to-end security transformation programs including capability uplift, operating model design and ongoing advisory support for sustained improvement. As an independent, vendor-neutral advisor, we focus on durable capability and measurable maturity gains rather than tooling for its own sake.

Program AdvisoryCapability UpliftSecurity Operating Model

Discuss your security priorities.

A senior HEXOSYS consultant will respond within one Australian business day.

Arrange a Consultation
← hexosys.com.au

Industry Solutions

Security expertise
shaped by sector.

Every sector has unique threat vectors, regulatory obligations and risk profiles. HEXOSYS brings deep sector knowledge to every engagement, mapping the standards that apply - from the ASD ISM and PSPF in government to APRA CPS 234 and CPS 230 in financial services - to the controls that matter most for your organisation.

Government

Federal, state and local government security architecture, ISM compliance, PSPF alignment and whole-of-government security transformation programs.

ISMPSPFEssential EightIRAP ReadinessProtective Markings
Financial Services

APRA CPS 234 and CPS 230 compliance, banking security architecture, cyber resilience programs and financial sector regulatory compliance for banks, insurers and wealth managers.

APRA CPS 234APRA CPS 230PCI-DSSASD Essential Eight
Critical Infrastructure

SOCI Act compliance, critical infrastructure risk management programs (CIRMP), OT/ICS security architecture and sector-specific uplift across energy, water, transport and communications.

SOCI ActOT/ICS SecurityCIRMPIEC 62443
Healthcare

Clinical system security, health data protection, My Health Record compliance and healthcare cyber resilience for public and private health organisations.

Privacy ActMy Health RecordClinical Security
Technology

SaaS security, DevSecOps integration, cloud-native security architecture and software supply chain security for fast-growing technology organisations.

DevSecOpsSOC 2 Type IIOWASPSupply Chain Security
Education

Research institution security, student data protection, higher education cyber resilience and compliance programs.

Privacy ActResearch SecurityData Protection

Sector-specific security expertise.

Speak with a HEXOSYS consultant who understands your industry.

Engage Our Team
← hexosys.com.au

Cybersecurity Architecture

Security designed
from first principles.

Enterprise security architecture that aligns security design to business strategy, risk appetite and technology direction. Built to last, not to checkbox.

What We Deliver

Architecture capabilities

01
Architecture Reviews

Independent assessment of existing security architecture identifying gaps, risks and improvement opportunities against frameworks and best practice.

02
Security Design

Target state security architecture design aligned to business objectives, regulatory requirements and the organisation's risk appetite.

03
Security Patterns

Reusable security design patterns and reference architectures that embed security controls consistently across systems and platforms.

04
Reference Architectures

Enterprise security reference architectures providing a consistent blueprint for security design decisions across technology programs.

05
Enterprise Security Strategy

Board-level security strategies with clear priorities, investment rationale and measurable outcomes aligned to business direction.

06
Security Roadmaps

Multi-year security roadmaps that sequence investment, reduce risk progressively and build security capability in a structured, sustainable way.

Framework Expertise

Architecture standards we apply

We apply established architecture and security frameworks pragmatically, selecting and combining them to suit each organisation’s context rather than following any single methodology by rote. The same rigour underpins our independent security assessments.

  • SABSA
  • Zero Trust Architecture
  • TOGAF
  • NIST CSF
  • ISO 27001
  • CIS Controls
  • Cloud Security Alliance
  • ASD Essential Eight
  • MITRE ATT&CK
  • OWASP
  • Secure-by-Design

Start with architecture.

Engage Hexosys
← hexosys.com.au

AI Security & Governance

Adopt AI securely.
Govern it responsibly.

AI introduces new security and governance challenges. HEXOSYS helps organisations adopt AI safely with frameworks that scale from project to enterprise, addressing model integrity, data protection and clear accountability alongside the security architecture that surrounds every AI system.

AI SECURITY & GOVERNANCE

Comprehensive AI security
across the full lifecycle.

Strategy

AI Security Strategy

Comprehensive AI security strategy aligned to your adoption roadmap, risk appetite and regulatory obligations.

Governance

AI Governance Frameworks

AI governance structures, accountability frameworks, ethical AI principles and risk management for responsible deployment.

Risk

AI Risk Assessments

Structured assessment of AI-specific risks including model integrity, data poisoning, adversarial attacks and prompt injection.

Architecture

Secure AI Architecture

Security architecture for AI systems, ML pipelines, LLM deployments and AI-enabled applications. Secure-by-design from inception.

Compliance

AI Regulatory Compliance

Navigate emerging AI regulations including the EU AI Act, Australian AI Ethics Framework and sector-specific AI governance requirements.

Assurance

AI Assurance Reviews

Independent assurance reviews providing objective evidence of responsible AI deployment and governance.

Govern your AI risk.

Discuss AI Security
← hexosys.com.au

Security Assessments

Understand your
true security posture.

Independent, expert-led assessments that give you an honest, evidence-based view of your security maturity, risks and gaps without vendor bias. Findings are benchmarked against recognised frameworks and translated into prioritised, board-ready recommendations that feed directly into strategy and architecture.

Assessment Programs

Choose the right program
for your needs.

Security Health Check
Targeted · 1-2 Weeks

Rapid review of a specific security domain. Ideal for targeted assurance on a particular risk area.

  • Defined scope review
  • Gap analysis against framework
  • Risk-rated findings report
  • Remediation recommendations
  • Executive summary
Enquire
Recommended
Cyber Maturity Assessment
Comprehensive · 4-6 Weeks

Structured maturity assessment across people, process and technology, benchmarked against industry frameworks.

  • NIST CSF or Essential Eight assessment
  • Maturity scoring across all domains
  • Threat landscape analysis
  • 3-year security roadmap
  • Board-ready executive report
  • Investment prioritisation model
Get Started
Security Risk Assessment
Enterprise · 6-10 Weeks

Comprehensive ISO 31000-aligned risk assessment across your entire organisation and supply chain.

  • ISO 31000 methodology
  • Enterprise risk identification
  • Threat modelling workshops
  • Risk register development
  • Treatment plan and roadmap
  • Board risk reporting templates
Enquire

Request an assessment.

Request an Assessment
← hexosys.com.au

Insights & Perspectives

Security thinking
from our experts.

Detailed guidance on these topics is published through the HEXOSYS Knowledge Platform - explore all insights.

TRUST BOUNDARY

AI Security

The CISO's Guide to AI Governance in the Enterprise

How security leaders can build governance frameworks enabling responsible AI adoption.

June 2026

GOVERNANCEAPPLICATIONSIDENTITY · NETWORKCLOUD PLATFORM

Architecture

Zero Trust Architecture: Beyond the Buzzword to Business Outcomes

Practical guidance for implementing Zero Trust across identity, device, network and application layers.

May 2026

CONTROL MATURITYESSENTIAL 8ISO 27001CPS 234AUDIT EVIDENCE

Compliance

ASD Essential Eight: A Practical Path to Maturity Level 3

Step-by-step guidance for organisations working toward Essential Eight Maturity Level 3.

April 2026

Risk Management

Security Risk Management for Complex Organisations

Building a risk management framework that connects security risk to business risk.

March 2026

Cloud Security

Securing Enterprise Workloads in Azure and AWS

Architecture patterns and security controls for enterprise cloud environments.

February 2026

Secure-by-Design

Why Secure-by-Design Reduces Long-Term Security Cost

The economic case for embedding security at the design stage to reduce later remediation effort and cost.

January 2026

Insight into Action

Apply these principles in your organisation.

Discuss how these security and architecture perspectives translate to your environment with a HEXOSYS Security Architect.

Speak with a Security Architect

HEXOSYS Knowledge Platform

Explore the HEXOSYS Knowledge Platform

Architecture-led insights, compliance explainers and practical resources for regulated Australian organisations.

View All Insights AI Governance Compliance & Frameworks Resources Essential Eight ML3 Checklist

About Hexosys

Built on experience.
Focused on outcomes.

Our Story

Independent expertise
since 2017.

HEXOSYS was established in August 2017 by cybersecurity professionals with extensive experience across financial services, critical infrastructure, healthcare, enterprise technology and regulated industry environments.

Having worked inside some of Australia's most complex regulated organisations, we recognised a consistent need for independent cybersecurity expertise that prioritises business outcomes and practical improvements over vendor product cycles.

Today, HEXOSYS provides advisory, architecture and assurance services to complex organisations seeking trusted guidance across cybersecurity, AI security and secure-by-design initiatives throughout Australia and New Zealand.

Mission

To help complex organisations strengthen security, manage risk and enable business outcomes through practical cybersecurity leadership, architecture excellence and trusted advisory services.

Our Commitment

Independent advice.

Practical outcomes.

Architecture-led thinking.

Long-term value.

Capability

Practitioner-led security capability.

Security Architecture

SABSA-informed enterprise security architecture and control design.

Security Governance

CISM-informed governance, policy, risk and operating model advisory.

Risk & Assurance

CRISC-informed risk, control and assurance advisory.

Security Audit

CISA-informed audit, evidence and assurance support.

Cloud Security

Azure and AWS security architecture experience across enterprise environments.

ISMS Advisory

ISO 27001-aligned ISMS advisory, implementation support and audit readiness.

Cybersecurity Leadership

CISSP-informed cybersecurity architecture, strategy and assurance.

Regulatory Alignment

Support for Essential Eight, ISM, PSPF, APRA CPS 234, CPS 230 and SOCI-aligned uplift.

Work with us.

Contact Hexosys
← hexosys.com.au

Contact & Engage

Start a
Conversation.

Every HEXOSYS engagement begins with a confidential conversation. We respond within one Australian business day.

Send an Enquiry

Fields marked are required.

A business email helps us route your enquiry to the right advisor.
Minimum 50 characters and at least 5 words. To help us prepare, consider including your organisation or industry, current challenge, desired outcome and preferred timeframe.
PDF, Word, Excel, PowerPoint, PNG, JPG, CSV, TXT or RTF - up to 10 MB.Attachments are security screened before processing, are not publicly accessible, and are reviewed only by authorised HEXOSYS personnel.
· Ready to send
Privacy Policy

Open the Privacy Policy before confirming consent.

Please confirm you have read the Privacy Policy before sending your enquiry.

Handled confidentially · Response within one Australian business day · Australia & New Zealand

Independent, architecture-led advice for organisations operating in complex and regulated environments.

Our Engagement Process
01
Discovery

We review your objectives and current environment to understand context and priorities.

02
Consultation

Confidential discussion to understand risks, priorities and desired outcomes.

03
Recommendation

Strategic recommendations and a tailored engagement approach.

04
Delivery

Advisory, architecture, assessment and implementation services aligned to objectives.

Contact

admin@hexosys.com.au

Australia & New Zealand

hexosys.com.au

HEXOSYS Pty Ltd · ABN 54 619 222 776

Confidential

All enquiries are treated with strict confidentiality. We do not disclose client information or engagement details to third parties under any circumstances.

What to Expect
01
Secure enquiry received

Your enquiry is securely received and reviewed by HEXOSYS.

02
Senior advisor review

A senior HEXOSYS advisor reviews your requirements to understand your objectives before any discussion.

03
Confidential follow-up

We’ll respond within one Australian business day to arrange a confidential discussion, or request any additional information if required.

← hexosys.com.au

Legal

Privacy
Policy.

How HEXOSYS Pty Ltd (ABN 54 619 222 776) collects, uses, discloses and protects personal information across our operations in Australia and New Zealand.

Effective June 2026. This Privacy Policy applies to the HEXOSYS website (hexosys.com.au) and to enquiries and communications you have with us. We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, and, where applicable, the New Zealand Privacy Act 2020.

1 · Who We Are

HEXOSYS Pty Ltd (ABN 54 619 222 776) is an independent cybersecurity advisory, architecture and assurance consultancy serving organisations in Australia and New Zealand. References to “HEXOSYS”, “we”, “us” or “our” are to HEXOSYS Pty Ltd.

2 · Information We Collect

We collect personal information that you provide to us and information generated when you use our website:

  • Contact form enquiries - first and last name, organisation, role or title, email address, area of interest and the details of your enquiry.
  • Business enquiries and correspondence - contact details and any information you choose to share when engaging with us about our services.
  • Email communications - the content of emails you send us and associated metadata such as sender address and timestamps.
  • Technical information - limited technical and device information processed through essential cookies so the website functions correctly and remains secure. We do not currently use third-party analytics to identify, profile or track individual visitors.
3 · How We Use Your Information

We use personal information to: respond to your enquiries and provide our advisory, architecture and assurance services; communicate with you about engagements and business matters; operate, maintain and improve our website; protect the security and integrity of our website and systems; and comply with our legal and regulatory obligations.

4 · Consent and Legal Basis

Where you submit an enquiry through our contact form, you confirm your agreement to this Privacy Policy before your enquiry can be sent. We otherwise handle personal information on the basis of your consent and our legitimate business interests in operating and providing our services. You may withdraw consent at any time by contacting us, although this may affect our ability to respond to you.

5 · Disclosure of Information

We do not sell personal information. We may disclose information to trusted service providers who support our operations - such as website hosting and email providers - who are required to protect it and use it only for the services they provide to us. We may also disclose information where required or authorised by law. We never disclose client engagement details or confidential project information to third parties.

6 · Cookies and Analytics

Our website currently uses only essential technical cookies that are necessary for the site to function and remain secure. We do not currently use third-party analytics or tracking technologies to identify, profile or track individual visitors. You can control or disable cookies through your browser settings, though some site features may not function as intended if cookies are disabled. If we introduce analytics in future, we will update this policy and obtain consent where required.

7 · Storage, Security and Overseas Handling

We take reasonable technical and organisational measures to protect personal information against loss, misuse and unauthorised access, disclosure or alteration. Information may be stored or processed in Australia or, through our service providers, overseas; where information is handled outside Australia or New Zealand we take reasonable steps to ensure it is protected to a comparable standard.

8 · Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, to maintain our business records, and to meet legal or regulatory requirements, after which it is deleted or de-identified.

9 · Your Rights

You may request access to, or correction of, the personal information we hold about you, and you may ask us to delete information where appropriate. In Australia these rights arise under the Australian Privacy Principles; in New Zealand under the Information Privacy Principles of the Privacy Act 2020. To make a request, contact us using the details below.

10 · Changes to This Policy

We may update this Privacy Policy from time to time. The current version is published on this page with its effective date, and continued use of our website indicates acceptance of the updated policy.

11 · Contact and Complaints

For privacy questions, requests or complaints, contact us at admin@hexosys.com.au. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) in Australia, or the Office of the Privacy Commissioner (OPC) in New Zealand.

← hexosys.com.au

Legal

Terms of
Use.

The terms governing your use of the HEXOSYS website (hexosys.com.au), operated by HEXOSYS Pty Ltd (ABN 54 619 222 776).

Effective June 2026. By accessing or using this website you agree to these Terms of Use. If you do not agree, please do not use the site.

1 · Use of the Website

You may use this website for lawful, informational purposes only. You must not use it in any way that is unlawful, infringes the rights of others, or interferes with the operation or security of the site.

2 · Information Only

Content on this website is provided for general information about HEXOSYS and our services. It does not constitute professional, security or legal advice, and should not be relied upon as such. Engagements are governed by separate written agreements.

3 · Intellectual Property

All content, branding, text and design on this website are owned by or licensed to HEXOSYS Pty Ltd and are protected by applicable laws. You may not reproduce or redistribute material without our permission.

4 · No Warranties and Limitation of Liability

The website is provided on an “as is” basis. To the extent permitted by law, HEXOSYS makes no warranties about its accuracy or availability and is not liable for any loss arising from your use of, or reliance on, the website.

5 · External Links

This website may link to third-party sites. We are not responsible for the content or practices of those sites and provide such links for convenience only.

6 · Governing Law

These Terms are governed by the laws of New South Wales, Australia. Privacy matters are addressed in our Privacy Policy.

7 · Changes to These Terms

We may update these Terms of Use from time to time. The current version is published on this page with its effective date, and continued use of our website indicates acceptance of the updated Terms.

8 · Contact

Questions about these Terms can be sent to admin@hexosys.com.au.

← hexosys.com.au

Trust

Security
& Disclosure.

Our security commitment, responsible disclosure process, and how HEXOSYS Pty Ltd (ABN 54 619 222 776) protects the information entrusted to us.

As an independent cybersecurity consultancy, HEXOSYS holds its own systems, website and communications to the standards we advise our clients to adopt. This page sets out our security commitment, how to report a concern responsibly, and how we handle the information entrusted to us.

1 · Security Commitment

We apply security-by-design and least-privilege principles across our website, email and internal tooling, and we treat the confidentiality, integrity and availability of information entrusted to us as a core professional obligation. Our security posture is reviewed on an ongoing basis and improved as threats and good practice evolve.

2 · Responsible Disclosure

We welcome reports from security researchers and members of the public who identify potential weaknesses in our website or communications. Please give us a reasonable opportunity to investigate and remediate before any public disclosure, act in good faith, and avoid accessing, modifying or deleting data that is not your own. We will not pursue action against researchers who report issues responsibly and in line with this policy.

3 · Vulnerability Reporting

To report a suspected vulnerability, email admin@hexosys.com.au with enough detail for us to reproduce and assess the issue - the affected URL or component, the steps to reproduce, and any supporting evidence. Please avoid automated scanning or testing that could disrupt our services or those of our clients. We aim to acknowledge legitimate reports promptly and will keep you informed through validation and remediation.

4 · Data Protection Principles

We collect only the information we need, use it solely for the purpose for which it was provided, and retain it no longer than necessary. Access is limited to those who require it, information in transit is protected using current encryption standards, and we align our handling of personal information with the Australian Privacy Act 1988 and the Australian Privacy Principles, and the New Zealand Privacy Act 2020. Further detail is set out in our Privacy Policy.

5 · Information Handling

Enquiries and business correspondence are handled through managed, access-controlled business systems. We classify information according to its sensitivity, apply appropriate safeguards to client and commercial material, and dispose of information securely when it is no longer required. Client engagement material is governed by the confidentiality and security arrangements agreed for each engagement.

6 · Third-Party Services

Our website and communications rely on a small number of reputable third-party providers, such as hosting, email and content delivery. We select providers with appropriate security and privacy practices, share only the data necessary for each service, and review these arrangements periodically. Where a provider processes personal information on our behalf, that processing is covered by our Privacy Policy.

7 · Contact Security Team

For security matters - vulnerability reports, disclosure questions, or concerns about how information is handled - contact us at admin@hexosys.com.au. For general enquiries, please use our contact form. HEXOSYS Pty Ltd (ABN 54 619 222 776) operates across Australia and New Zealand.

← hexosys.com.au