Senior cyber security consulting, that fits the way you work.
Your organisation benefits when cybersecurity is designed to fit your unique workplace. With Acumenis, you’re supported by senior cybersecurity consultants who help you reduce risk, earn trust and meet the expectations of customers, boards, and regulators.
Acumenis is an Australian cyber security consultancy with team members based in Brisbane and Toowoomba.


What we believe.
Information security is least effective when it's simply bolted on after the fact. Compliance frameworks become drag, controls don't get adopted, and the people responsible for cyber and compliance carry personal risk if something goes wrong.
We started Acumenis to change all that. We believe security should be designed around how people actually work. You benefit from senior consultants who understand the reality of your organisation, scoping that reflects real risk (not maximised hours), and outcomes you can stand behind when reporting to your stakeholders.

How we work.
Every engagement is led and delivered end-to-end by a senior consultant based in Australia. Acumenis is independent of vendors and managed services, so the recommendations you receive are shaped entirely by your security posture, risk, and business context, scoped to what your environment actually needs.
Senior leadership team.

Andy founded Acumenis in 2017 and leads the firm. He has more than 30 years of experience across technology and cyber security, and works directly with clients on the firm's more complex engagements.
Before Acumenis, Andy was CTO of a national Managed Service Provider, accountable for the IT environments and security posture of organisations across Australia. That operational grounding shapes how Acumenis approaches security today: practical, achievable, and built into the way the business actually runs, rather than bolted on beside it.
Andy holds a Bachelor of Information Technology (Applied Computer Science), is a qualified ISO 27001 Lead Implementer and Lead Auditor, and is a Member of the Australian Institute of Company Directors (MAICD). He also holds a range of industry certifications spanning security, risk, and technology leadership.

Ian leads our Security Assurance team, overseeing penetration testing and vulnerability assessment engagements and ensuring they're delivered to the standard our clients and their stakeholders rely on.
Before pivoting into information security, Ian was a Senior Systems Analyst at an ASX Top 20 company. That deep systems background means he tests with the perspective of someone who has built and run the kinds of environments he assesses.
Ian holds Offensive Security Certified Professional (OSCP) and CREST Registered Tester (CRT) certifications, alongside other industry credentials.

JP leads our Advisory team, working with clients on ISO 27001, Essential Eight, and broader information security strategy. He also helps organisations establish AI governance frameworks, including ISO 42001 implementation, as AI governance becomes an increasingly critical part of mature risk management.
Before joining Acumenis, JP was the Information Security Manager at Australia's largest mutual bank, where he oversaw the establishment of the bank's Security Operations Centre (SOC), SIEM, and SOAR platforms. That hands-on operational experience means JP advises clients with the perspective of someone who has built and run the security functions he helps others establish.
JP is a regular speaker at industry conferences including AusCERT, CrikeyCon, and SecTalks, and is actively involved in the Australian information security community.
Credentials in detail.
Our credentials are independently audited and current.

CREST Accreditation
Acumenis is CREST (International) accredited for penetration testing across Australasia. This accreditation is independently audited and means our testing methodology, technical capability, and engagement processes meet recognised professional standards. Many enterprise and government procurement teams require CREST accreditation as a baseline, and increasingly so do larger commercial customers.

ISO 27001 Certification
Acumenis is ISO 27001 certified, holding ourselves to the same standard we help clients meet. The certification covers our information security management practices and is independently audited annually. Our consultants include qualified ISO 27001 Lead Implementers and Lead Auditors.





Industry certifications held by our team
Our consultants hold a range of recognised industry credentials, including:
Offensive Security Certified Professional (OSCP)
CREST Registered Tester (CRT)
ISO 27001 Lead Implementer and Lead Auditor
Certified Incident Handler (CIH)
ISO 27701 Lead Auditor
Certified Ethical Hacker (CEH)
ISO 42001 Lead Auditor
Cisco CCNA CyberOps (SECFND)

Supporting the Australian InfoSec community.
Cyber security is a community effort. The Australian information security community has supported the careers of our consultants, and we work to give back through sponsorship, speaking, and direct involvement with the events and groups developing the next generation. With our team and most of our clients based across Brisbane and South East Queensland, we're particularly invested in the Queensland and broader Australian community.
Industry conferences
Acumenis sponsors and supports industry conferences across Australia, including BSides Brisbane and Realms of Cyber and other events that develop technical capability and bring practitioners together. Members of our team are regular speakers at conferences including AusCERT, CrikeyCon, and SecTalks.
University engagement
We work with university programs that build the next wave of information security and governance, risk, and compliance practitioners. This includes involvement with and sponsorship of the QUT GRC Club in Brisbane, and guest lectures at universities.
Why this matters
Strong industry communities produce better practitioners, better consulting, and better outcomes for the Australian organisations that rely on us. Supporting the community is part of how we do our job, not separate from it.
We work best where security carries real responsibility.
Startups
& scale-ups
Building secure, scalable foundations to support growth without slowing the business down.
Mid-market
& regulated organisations
Validating controls, managing risk, and meeting customer and regulatory expectations.
Enterprise
& government
Needing senior-led testing, assurance, and advisory that supports complex environments and stands up to internal scrutiny.
Frequently asked questions.
Straight answers to the questions we hear most. Can't find yours? We're happy to help.
es, through our ISO 27001 implementation service, but not on the same engagement as your internal audit. Where Acumenis has implemented your ISMS, your internal audit is conducted by a different consultant to preserve the independence the standard requires.
Acumenis works with Australian organisations across a wide range of sizes and sectors. Our clients include early-stage startups with small teams, mid-market and regulated organisations across industries such as healthcare and critical infrastructure, and large enterprises including ASX50-listed companies and government agencies. Engagements range from focused penetration testing for a single application to multi-phase ISO 27001 implementations and ongoing advisory relationships.
Acumenis has been operating since 2017. The firm was founded by Andy Dowling, who continues to lead it as Managing Director. Since founding, Acumenis has grown to a team of senior consultants delivering testing, assurance, and advisory services across Australia.
All Acumenis consultants are based in Australia, with team members in Brisbane and Toowoomba. We support clients nationally and internationally, meeting in person across South East Queensland and travelling as engagements require. Projects are handled by the same senior consultant from start to finish, giving you clear accountability and on-shore data handling throughout.
Yes. Acumenis is CREST (International) accredited for penetration testing across Australasia. CREST accreditation is independently audited and demonstrates that our testing methodology, technical capability, and engagement processes meet recognised professional standards. CREST accreditation is required by many enterprise and government procurement teams as a baseline supplier requirement.
Yes. Acumenis is ISO 27001 certified, holding ourselves to the same information security standard we help clients meet. The certification covers our information security management practices and is independently audited annually. Our consultants include qualified ISO 27001 Lead Implementers and Lead Auditors who deliver implementation and audit services for clients pursuing certification.
Three things set Acumenis apart. First, every engagement is led and delivered end-to-end by a senior consultant, with no junior delivery or hand-offs. Second, Acumenis is independent of vendors and managed services, so recommendations are shaped entirely by client need rather than by products being sold or infrastructure being managed on the side. Third, Acumenis is Australian-owned and Australian-delivered, with all consultants based locally and engagements handled on-shore.
Acumenis is an independent cyber security consultancy. We don't operate as a managed service provider, reseller, or product vendor, and we don't bundle product or service sales into our consulting engagements. Recommendations are shaped entirely by your security posture, risk, and business context, free from the conflicts of interest that arise when consulting is delivered alongside product or managed service revenue.
The best starting point is a scoping conversation. Get in touch through our contact page or call us, and we'll arrange a conversation with a senior consultant to understand your environment, objectives, and constraints. From there, we'll recommend an approach that reflects real risk and provide a written proposal with clear scope, timeline, and deliverables.
Acumenis runs with low overhead by design. We minimise paper use through paperless processes, choose energy-efficient technology where we can, and partner with Carbon Neutral to plant a tree for every invoice we issue. Practical, not performative.

Let's talk about where you are and where you need to be.
Whether you're preparing for certification, validating your controls, or building security foundations for growth, we'll help you get there with clarity and confidence.
