Our Team – SeComPass
The People Behind the Practice

Meet Our Team

Experienced security and privacy professionals dedicated to guiding your cybersecurity journey.

Jatinder Oberoi

Founder & Principal Consultant

Krish Pasumarthi

Head of Compliance Practice

Brian Heatherich

Head of Security Architecture

Sukhy Bassan

Head of Auditing Practice

Ryan Ashton

Head of Sales

Join Our Team

We're always looking for talented security professionals.

View Openings
Who We Are – SeComPass

Our Values

Instil Confidence

We ensure your data and privacy are protected so your customers can trust you completely.

Drive Growth

Security and privacy are key marketing catalysts that differentiate you from the competition.

Transparent

We are open in our practices and pricing, bringing our authentic selves to every engagement.

Value for Money

Our risk-based approach focuses only on relevant risks — achieving the highest security for the least cost.

Our Purpose

Our Philosophy

Focused and pragmatic security advice — cutting through complexity to deliver what matters most for your business.

Our Mission

To offer organisations the best security and privacy advice, ensuring maximum business benefits and security ROI. We constantly strive to get the best for our customers and our people.

Our Vision

To be a trusted security and privacy partner, protecting organisations worldwide through expertise, integrity, and innovation.

"It would be great to meet and have a chat about your current and desired security posture"
— Jatinder Oberoi, Founder/Principal

Get in Touch
FAQ – SeComPass
Got Questions?

Cybersecurity & Compliance FAQs

Common questions about ISO27001, SOC2, vCISO services, and cybersecurity compliance in Australia and New Zealand.

What cybersecurity services do you offer in Australia and New Zealand?
Services

SeComPass offers a full suite of cybersecurity and privacy services across Australia and New Zealand, including:

Security Leadership: Virtual CISO (vCISO), virtual ISM, virtual SCO, and virtual DPO services — senior-level expertise without the full-time cost.

Certifications: ISO27001, ISO27701, SOC2 assurance, Essential Eight assessment, and VPDSF attestation.

Compliance: NZISM, Australian Privacy Act, NZ Privacy Act 2020, GDPR, and PSPF regulatory assurance.

GRC Automation: Streamlined governance, risk, and compliance management to reduce audit overhead and improve security maturity visibility.

How much does ISO27001 certification cost in Australia or New Zealand?
Certifications

ISO27001 certification costs vary based on your organisation's size, existing security maturity, and the scope of your Information Security Management System (ISMS). Factors that affect the cost include the number of employees, systems in scope, and how much remediation work is needed before the audit.

SeComPass provides a transparent, fixed-scope quote after a no-obligation initial assessment — so there are no surprises. Our risk-based approach ensures you invest only in what's necessary to achieve certification efficiently.

Does my business need ISO27001 or SOC2?
Certifications

ISO27001 is the right choice if you're selling to enterprise, government, or regulated industries in Australia, New Zealand, or globally. It is an internationally recognised standard that proves your information security management is robust and independently audited.

SOC2 is best suited for SaaS and technology companies targeting US-based enterprise customers. It has become a near-mandatory requirement for closing large US contracts, particularly in financial services and healthcare sectors.

Both certifications signal to customers and partners that security is a core business priority — not an afterthought. SeComPass can help you determine which certification delivers the greatest commercial value for your stage and target markets.

What is a virtual CISO (vCISO) and does my business need one?
Services

A virtual CISO (vCISO) is a senior cybersecurity leader engaged on a part-time or fractional basis. It gives your organisation strategic security leadership — risk management, security roadmap development, policy frameworks, board reporting, and vendor oversight — at a fraction of the cost of a full-time CISO hire.

A vCISO is ideal for scale-ups, mid-sized businesses, and organisations that need experienced security leadership but cannot justify a full-time executive salary. It's also a strong option for businesses preparing for ISO27001, SOC2, or government contract requirements.

SeComPass vCISO services are available across Australia and New Zealand and scale with your needs.

How long does ISO27001 certification take?
Certifications

The timeline to achieve ISO27001 certification typically ranges from 3 to 12 months, depending on your organisation's size, current security maturity, and the complexity of the scope.

SeComPass uses an agile, accelerated methodology to shorten implementation timelines wherever possible — helping you get certified and market-ready faster than traditional approaches. We've helped organisations achieve certification in as little as 3 months when the foundation is in place.

What is the Essential Eight and does my Australian business need to comply?
Certifications

The Essential Eight is a prioritised cybersecurity mitigation framework developed by the Australian Cyber Security Centre (ACSC). It is mandatory for Australian federal government agencies and is increasingly expected by state government bodies and critical infrastructure operators.

Even if your business is not legally required to comply, achieving Essential Eight maturity significantly reduces your exposure to ransomware, malware, and data breach incidents — and is increasingly being requested in procurement and tender processes.

SeComPass can assess your current Essential Eight maturity level (ML1–ML3) and build a practical, prioritised roadmap to uplift your controls.

What is NZISM compliance and who needs it in New Zealand?
Certifications

The New Zealand Information Security Manual (NZISM) is the New Zealand Government Chief Information Officer's cybersecurity standard for all government agencies and their suppliers. If your organisation provides software, cloud services, or IT infrastructure to NZ government agencies, NZISM compliance is typically a contract requirement.

SeComPass has extensive experience helping New Zealand organisations achieve and maintain NZISM compliance, including Protective Security Requirements (PSR) assurance. We can conduct a gap analysis and help you implement the required controls efficiently.

Can SeComPass help with Australian Privacy Act or NZ Privacy Act compliance?
Privacy

Yes. SeComPass provides privacy compliance services covering the Australian Privacy Act 1988, the New Zealand Privacy Act 2020, GDPR, CCPA, and other international privacy frameworks.

Our virtual Data Protection Officer (vDPO) service provides ongoing privacy governance, data breach response planning, Privacy Impact Assessments (PIAs), and third-party data sharing reviews — keeping your organisation compliant and your customers' data protected.

We also help organisations achieve ISO27701 — the international privacy information management standard that extends ISO27001 to cover privacy obligations.

How can I streamline security audits and track our compliance maturity?
Services

SeComPass uses GRC (Governance, Risk and Compliance) automation tools to dramatically reduce the manual effort involved in security audits. This includes automated evidence collection, policy management, control monitoring, and audit-ready reporting.

You get real-time visibility into your organisation's security maturity across frameworks like ISO27001, Essential Eight, and SOC2 — so you're always audit-ready rather than scrambling to prepare. This approach typically reduces audit preparation time by 60–70%.

How does SeComPass price its cybersecurity and compliance services?
Pricing

SeComPass offers flexible, transparent pricing based on project scope and complexity. We provide a fixed-scope quote after an initial no-obligation consultation — no hidden fees, no hourly billing surprises.

Our risk-based approach means we scope only what's relevant to your specific situation, ensuring maximum security and compliance value for your investment. Whether you need a one-time certification engagement or ongoing virtual security leadership, we'll structure a commercial model that works for your business.

How do I get started with SeComPass?
General

Getting started is straightforward. Book a no-obligation security assessment through our contact page or call us directly in Australia (+61 481 842 997) or New Zealand (+64 21 542 997).

We'll review your current security and compliance posture, understand your business goals and target markets, and recommend the most practical and cost-effective path forward — whether that's a certification, a vCISO engagement, or a targeted gap assessment.

Still have questions about cybersecurity compliance in Australia or New Zealand? We'd love to help.

Book a Free Assessment
Since 2017 – SeComPass
Trusted Partner

Helping Organisations
Stay Secure Since 2017

From scale-ups to established enterprises across Australia and New Zealand — we've guided organisations through certifications, compliance frameworks, and building lasting security programmes.

7+
Years of
Experience
100+
Organisations
Secured
AU&NZ
Across Both
Markets
ISO
SOC2
Certifications
Delivered
Trusted by leading organisations
Groov
Vocus
Auckland Airport
Southern Cross Health
Atturra
FileInvite
Vinarchy
Ports of Auckland
"

Always been happy with the results, valued the ongoing relationships with SeComPass. Their pragmatic approach made the ISO27001 journey far less daunting than we expected.

"

SeComPass gave us value for money. Received a really good service and the SeComPass auditor was genuinely helpful throughout the entire process.

Join our growing list of secured organisations

Ready to start your security journey?