# Acumenis > Acumenis is an independent Australian cyber security consultancy based in Brisbane, operating since 2017. It delivers CREST (International) accredited penetration testing, ISO 27001 / 27701 / 42001 advisory and certification support, Essential Eight assessments, and incident readiness services to Australian organisations. Every engagement is scoped and delivered end to end by a senior consultant. ## Key Pages - [Home](https://www.acumenis.com.au/): Overview of Acumenis' three solution areas — GRC advisory and audit, security testing, and incident readiness. - [Services](https://www.acumenis.com.au/services): Full catalogue of cyber security services, grouped by solution area. - [Penetration Testing](https://www.acumenis.com.au/services/penetration-tests): CREST (International) accredited penetration testing across infrastructure, web applications, cloud environments and APIs. - [ISO 27001 Implementation](https://www.acumenis.com.au/services/iso-27001-compliance-consulting): ISMS implementation and certification support. - [Incident Response Tabletop Exercises](https://www.acumenis.com.au/services/incident-response-tabletop-exercises): Facilitated incident simulation and response readiness. - [Approach](https://www.acumenis.com.au/approach): The principles and delivery model behind every Acumenis engagement. - [About](https://www.acumenis.com.au/about): Company background, accreditations and consultant team. - [Case Studies](https://www.acumenis.com.au/case-studies): Client outcomes from senior-led engagements. - [Insights](https://www.acumenis.com.au/resources): Practical guidance on ISO 27001, ISO 42001, penetration testing, AI governance and cyber risk. - [Careers](https://www.acumenis.com.au/careers): Open roles and what it is like to work at Acumenis. - [Contact](https://www.acumenis.com.au/contact): Scoping conversations with a senior consultant. ## Key Facts - Acumenis is an independent cyber security consultancy founded in 2017 by Andy Dowling, who continues to lead the firm as Managing Director and Principal Security Consultant. - Acumenis holds CREST (International) accreditation for penetration testing across Australasia, and is itself ISO 27001 certified, independently audited annually. - Acumenis is not a managed service provider, reseller or product vendor. It does not bundle product or managed service sales into consulting engagements, so recommendations are shaped only by the client's risk and business context. - All consultants are based in Australia, with team members in Brisbane and Toowoomba. Testing, reporting and walkthroughs are handled by the same senior consultant from start to finish, with on-shore data handling throughout. - Clients range from early-stage startups to mid-market and regulated organisations in healthcare and critical infrastructure, through to ASX50-listed companies and government agencies. - Service areas are GRC advisory and audit (ISO 27001, ISO 27701, ISO 42001, Essential Eight, security policy development, security risk assessments), security testing (CREST-accredited penetration testing across infrastructure, internal networks, web applications, cloud and APIs), and incident readiness (tabletop exercises and response planning). - Penetration testing engagements typically run one to three weeks of testing plus scoping and reporting. Findings are prioritised by exploitability and business impact rather than delivered as an undifferentiated vulnerability list. - Acumenis consultants include qualified ISO 27001 Lead Implementers and Lead Auditors, and hold credentials including OSCP and CREST Registered Tester. - Contact: 1300 450 970 · hello@acumenis.com.au · Brisbane, Queensland, Australia. ## Optional - [Privacy Policy](https://www.acumenis.com.au/privacy) - [Terms of Use](https://www.acumenis.com.au/terms) - [Modern Slavery Policy](https://www.acumenis.com.au/modern-slavery) - [Threat Intelligence Briefing](https://www.acumenis.com.au/threat-intel-briefing): Email briefing on cyber security news and threat intelligence.