Case Study · ISO 27001:2022

Efex: ISO 27001 Certification for a National Managed Services Provider

How a 250+ employee, 22-location Australian MSP achieved ISO 27001 certification on schedule, then built an internal audit capability that's kept its surveillance audits clean.

Efex
Managed IT Services
250+
Employees
22 across Australia
Locations
7,500+
Customers served
ISO 27001:2022
Standard

Efex is one of Australia’s largest managed technology services providers — more than 250 employees, 22 locations, and over 7,500 customers, built through an aggressive acquisition strategy that has folded businesses like Datcom into the group. For an MSP operating at that scale, security certification isn’t optional: it’s what enterprise clients and their own procurement teams expect to see before they’ll sign.

The challenge

An MSP of Efex’s size sits in an unusual position: they’re not just securing their own environment, they’re a trusted operator inside their clients’ environments too. That raises the bar for what “good enough” security governance looks like — generic policy templates and a folder of unread documents weren’t going to hold up under real client due diligence, let alone a certification audit.

The approach

Prashant worked through the standard implementation pathway — gap analysis, risk assessment, policy and control development, and full Stage 1/Stage 2 audit support — but the details that mattered to Efex’s team were less about the framework and more about how the project was run:

  • Fixed-cost, fixed-scope engagement — no hourly billing risk on a project spanning a multi-site organisation.
  • Weekly tracking meetings to keep a project of this scale moving, with clear ownership on every outstanding item.
  • Practical, plain-English translation of Annex A requirements for a technical team that needed to actually run the ISMS day to day, not just pass an audit once.
  • Internal auditor training, so Efex’s own team could sustain the system after certification instead of depending on an external consultant indefinitely.

The result

Efex achieved certification on schedule. In their own words:

“I had the pleasure of working with Prashant on our ISO 27001 certification journey, and I can’t recommend him highly enough. He guided us through what could have been an overwhelming process with remarkable clarity and structure — from gap analysis and risk assessments to policy development and audit preparation. Prashant has a rare ability to translate complex compliance requirements into practical, actionable steps that our whole team could understand and execute. He was responsive, thorough, and always a step ahead. Thanks in large part to his expertise, we achieved certification smoothly and on schedule.”

Rube Sayed, General Manager, Enterprise — Efex / Datcom

The internal auditor training program has had a lasting effect beyond the original certification:

“Prashant ran our internal auditor training programme and it transformed how our team thinks about compliance. Not theoretical — genuinely practical, with real examples from our industry. Our internal audits are now far more rigorous and our last external surveillance audit had zero major non-conformances.”

Charles Mann, IT Director — Efex

Zero major non-conformances on a surveillance audit, well after the original certification project ended, is the outcome that matters most: it means the ISMS is a system Efex’s own team runs and owns, not a document set that was only ever built to pass one audit.

If you’re an MSP considering ISO 27001

Efex’s starting position — a large, multi-site, acquisition-driven business — is more complex than most MSPs’ current reality. If a national provider that size could get certified on schedule with a fixed-cost, hands-on approach, a leaner single-site MSP has an easier path. Book a free consultation to talk through what that would look like for your business.

Ready to get certified?

45-minute no-obligation consultation. Honest assessment. Fixed-price proposal.

Book Free Consultation
Chat with us