ABOUT HEXOSYS

Our
Expertise.

Practice profile

HEXOSYS is a practitioner-led consultancy. Engagements are delivered by senior architects with more than 18 years in ICT and more than 12 years in cybersecurity, solution and enterprise architecture, across government, critical infrastructure and regulated enterprise environments in Australia and New Zealand.

  • 18+ years of hands-on ICT practice
  • 12+ years in cybersecurity, solution and enterprise architecture
  • Australian citizen practitioners holding active NV1 security clearance
  • SABSA Chartered Security Architect - Foundation (SCF)
  • Bachelor of Information Technology

Frameworks and obligations

Advisory and assurance capability across the obligations that govern Australian regulated organisations:

Commonwealth

  • ASD Essential Eight and the Information Security Manual (ISM)
  • Protective Security Policy Framework (PSPF)
  • IRAP-aligned assessment preparation and remediation
  • Hosting Certification Framework (HCF) requirements
  • Defence Industry Security Program (DISP) requirements

State and territory

  • Victorian Protective Data Security Framework and Standards (VPDSF / VPDSS)
  • NSW Cyber Security Policy
  • Queensland Information Security Policy (IS18)
  • South Australian (SACSF) and Western Australian government frameworks

Critical infrastructure and energy

  • SOCI Act and Critical Infrastructure Risk Management Program (CIRMP) obligations
  • Australian Energy Sector Cyber Security Framework (AESCSF)
  • IEC 62443 for operational technology and industrial control systems

Financial services

  • APRA CPS 234 and CPS 230 alignment

International and sector standards

  • ISO 27001, ISO 27002 and ISO 22301
  • NIST Cybersecurity Framework and SP 800-53 / 800-171
  • CIS Controls
  • PCI DSS

Technical architecture depth

Architecture experience grounded in complex production estates rather than reference diagrams:

  • Microsoft Azure and AWS security architecture
  • VMware environments, including network virtualisation and segmentation
  • Identity and access management (IAM) architecture
  • Public key infrastructure (PKI) design and operation
  • Network security architecture and zoning

How this shows up in engagements

Every engagement is led by the practice principals - no delegation to junior staff, no vendor commissions, no product resale. Recommendations are evidence-based, framework-mapped and defensible at board and audit level.

Work with the practice.

Speak directly with a HEXOSYS security architect.

Book a Security Consultation