About Us

Senior cyber security consulting, that fits the way you work.

Your organisation benefits when cybersecurity is designed to fit your unique workplace. With Acumenis, you’re supported by senior cybersecurity consultants who help you reduce risk, earn trust and meet the expectations of customers, boards, and regulators.

Acumenis is an Australian cyber security consultancy with team members based in Brisbane and Toowoomba.

Acumenis founder Andy Dowling
Brisbane-based cyber security consultant in conversation

What we believe.

Information security is least effective when it's simply bolted on after the fact. Compliance frameworks become drag, controls don't get adopted, and the people responsible for cyber and compliance carry personal risk if something goes wrong.

We started Acumenis to change all that. We believe security should be designed around how people actually work. You benefit from senior consultants who understand the reality of your organisation, scoping that reflects real risk (not maximised hours), and outcomes you can stand behind when reporting to your stakeholders.

An Australian cyber security consultant checking a security dashboard
Our Approach

How we work.

Every engagement is led and delivered end-to-end by a senior consultant based in Australia. Acumenis is independent of vendors and managed services, so the recommendations you receive are shaped entirely by your security posture, risk, and business context, scoped to what your environment actually needs.

Senior leadership team.

Andy Dowling
Andy Dowling
Managing Director

Andy founded Acumenis in 2017 and leads the firm. He has more than 30 years of experience across technology and cyber security, and works directly with clients on the firm's more complex engagements.

Before Acumenis, Andy was CTO of a national Managed Service Provider, accountable for the IT environments and security posture of organisations across Australia. That operational grounding shapes how Acumenis approaches security today: practical, achievable, and built into the way the business actually runs, rather than bolted on beside it.

Andy holds a Bachelor of Information Technology (Applied Computer Science), is a qualified ISO 27001 Lead Implementer and Lead Auditor, and is a Member of the Australian Institute of Company Directors (MAICD). He also holds a range of industry certifications spanning security, risk, and technology leadership.

Ian Esplin
Ian Esplin
Assurance Lead

Ian leads our Security Assurance team, overseeing penetration testing and vulnerability assessment engagements and ensuring they're delivered to the standard our clients and their stakeholders rely on.

Before pivoting into information security, Ian was a Senior Systems Analyst at an ASX Top 20 company. That deep systems background means he tests with the perspective of someone who has built and run the kinds of environments he assesses.

Ian holds Offensive Security Certified Professional (OSCP) and CREST Registered Tester (CRT) certifications, alongside other industry credentials.

JP Haywood
JP Haywood
Advisory Lead

JP leads our Advisory team, working with clients on ISO 27001, Essential Eight, and broader information security strategy. He also helps organisations establish AI governance frameworks, including ISO 42001 implementation, as AI governance becomes an increasingly critical part of mature risk management.

Before joining Acumenis, JP was the Information Security Manager at Australia's largest mutual bank, where he oversaw the establishment of the bank's Security Operations Centre (SOC), SIEM, and SOAR platforms. That hands-on operational experience means JP advises clients with the perspective of someone who has built and run the security functions he helps others establish.

JP is a regular speaker at industry conferences including AusCERT, CrikeyCon, and SecTalks, and is actively involved in the Australian information security community.

Credentials in detail.

Our credentials are independently audited and current.

CREST Accreditation

Acumenis is CREST (International) accredited for penetration testing across Australasia. This accreditation is independently audited and means our testing methodology, technical capability, and engagement processes meet recognised professional standards. Many enterprise and government procurement teams require CREST accreditation as a baseline, and increasingly so do larger commercial customers.

ISO 27001 Certification

Acumenis is ISO 27001 certified, holding ourselves to the same standard we help clients meet. The certification covers our information security management practices and is independently audited annually. Our consultants include qualified ISO 27001 Lead Implementers and Lead Auditors.

Industry certifications held by our team

Our consultants hold a range of recognised industry credentials, including:

Offensive Security Certified Professional (OSCP)

CREST Registered Tester (CRT)

ISO 27001 Lead Implementer and Lead Auditor

Certified Incident Handler (CIH)

ISO 27701 Lead Auditor

Certified Ethical Hacker (CEH)

ISO 42001 Lead Auditor

Cisco CCNA CyberOps (SECFND)

Cyber security consultant presenting at a conference
The Community

Supporting the Australian InfoSec community.

Cyber security is a community effort. The Australian information security community has supported the careers of our consultants, and we work to give back through sponsorship, speaking, and direct involvement with the events and groups developing the next generation. With our team and most of our clients based across Brisbane and South East Queensland, we're particularly invested in the Queensland and broader Australian community.

Industry conferences

Acumenis sponsors and supports industry conferences across Australia, including BSides Brisbane and Realms of Cyber and other events that develop technical capability and bring practitioners together. Members of our team are regular speakers at conferences including AusCERT, CrikeyCon, and SecTalks.

University engagement

We work with university programs that build the next wave of information security and governance, risk, and compliance practitioners. This includes involvement with and sponsorship of the QUT GRC Club in Brisbane, and guest lectures at universities.

Why this matters

Strong industry communities produce better practitioners, better consulting, and better outcomes for the Australian organisations that rely on us. Supporting the community is part of how we do our job, not separate from it.

Who we work with

We work best where security carries real responsibility.

Startups
& scale-ups

Building secure, scalable foundations to support growth without slowing the business down.

Mid-market
& regulated organisations

Validating controls, managing risk, and meeting customer and regulatory expectations.

Enterprise
& government

Needing senior-led testing, assurance, and advisory that supports complex environments and stands up to internal scrutiny.

Not sure where you fit? Speak with an expert today.

Frequently asked questions.

Straight answers to the questions we hear most. Can't find yours? We're happy to help.

Do you also help with the implementation?

es, through our ISO 27001 implementation service, but not on the same engagement as your internal audit. Where Acumenis has implemented your ISMS, your internal audit is conducted by a different consultant to preserve the independence the standard requires.

Who does Acumenis work with?

Acumenis works with Australian organisations across a wide range of sizes and sectors. Our clients include early-stage startups with small teams, mid-market and regulated organisations across industries such as healthcare and critical infrastructure, and large enterprises including ASX50-listed companies and government agencies. Engagements range from focused penetration testing for a single application to multi-phase ISO 27001 implementations and ongoing advisory relationships.

How long has Acumenis been operating?

Acumenis has been operating since 2017. The firm was founded by Andy Dowling, who continues to lead it as Managing Director. Since founding, Acumenis has grown to a team of senior consultants delivering testing, assurance, and advisory services across Australia.

Where are Acumenis consultants based?

All Acumenis consultants are based in Australia, with team members in Brisbane and Toowoomba. We support clients nationally and internationally, meeting in person across South East Queensland and travelling as engagements require. Projects are handled by the same senior consultant from start to finish, giving you clear accountability and on-shore data handling throughout.

Is Acumenis CREST accredited?

Yes. Acumenis is CREST (International) accredited for penetration testing across Australasia. CREST accreditation is independently audited and demonstrates that our testing methodology, technical capability, and engagement processes meet recognised professional standards. CREST accreditation is required by many enterprise and government procurement teams as a baseline supplier requirement.

Is Acumenis ISO 27001 certified?

Yes. Acumenis is ISO 27001 certified, holding ourselves to the same information security standard we help clients meet. The certification covers our information security management practices and is independently audited annually. Our consultants include qualified ISO 27001 Lead Implementers and Lead Auditors who deliver implementation and audit services for clients pursuing certification.

What makes Acumenis different from other cyber security consultancies?

Three things set Acumenis apart. First, every engagement is led and delivered end-to-end by a senior consultant, with no junior delivery or hand-offs. Second, Acumenis is independent of vendors and managed services, so recommendations are shaped entirely by client need rather than by products being sold or infrastructure being managed on the side. Third, Acumenis is Australian-owned and Australian-delivered, with all consultants based locally and engagements handled on-shore.

How does Acumenis stay independent?

Acumenis is an independent cyber security consultancy. We don't operate as a managed service provider, reseller, or product vendor, and we don't bundle product or service sales into our consulting engagements. Recommendations are shaped entirely by your security posture, risk, and business context, free from the conflicts of interest that arise when consulting is delivered alongside product or managed service revenue.

How do I start working with Acumenis?

The best starting point is a scoping conversation. Get in touch through our contact page or call us, and we'll arrange a conversation with a senior consultant to understand your environment, objectives, and constraints. From there, we'll recommend an approach that reflects real risk and provide a written proposal with clear scope, timeline, and deliverables.

Environmental commitment

Acumenis runs with low overhead by design. We minimise paper use through paperless processes, choose energy-efficient technology where we can, and partner with Carbon Neutral to plant a tree for every invoice we issue. Practical, not performative.

Acumenis

Let's talk about where you are and where you need to be.

Whether you're preparing for certification, validating your controls, or building security foundations for growth, we'll help you get there with clarity and confidence.