# Logic Weave — Full Service Descriptions > Logic Weave is a fractional CISO and cybersecurity advisory firm based in Melbourne, Australia. We provide accountable security leadership for scaling Australian SMBs — FinTech, HealthTech, and SaaS companies with 20 to 300 employees. Founded by Mahesh Thiyagarajan with 24+ years of security experience across APAC, Logic Weave delivers ISO 27001 certification, Essential Eight maturity uplift, GRC as a Service, internal security audits, penetration testing, and SOC 2 Type 2 readiness. We are not a traditional consulting firm — we embed into your business, own the execution, and stay accountable until outcomes are delivered. Melbourne headquarters, Australia-wide delivery. ## GRC as a Service - URL: https://www.logicweave.io/melbourne-grc-as-a-service Logic Weave's GRC as a Service is an ongoing governance, risk, and compliance program delivered as a monthly retainer. It is designed for Australian SMBs — particularly FinTech, HealthTech, and SaaS companies — that need a living compliance program without the cost of building a full-time GRC function in-house. The service covers three tiers — Lite, Standard, and Premium — scaled to the organisation's stage, certification status, and regulatory obligations. Lite provides essential policies, baseline framework gap review using Vanta, annual risk identification, and a GRC roadmap. Standard adds a full policy library, quarterly risk meetings, vendor risk management, ongoing control testing, ISMS management reviews, security awareness training with phishing simulation, and two annual penetration tests. Premium extends to multi-framework coverage (ISO 27001, Essential Eight, SOC 2), continuous risk oversight, incident simulation, unlimited security questionnaire assistance, board-ready metrics, and continuous maturity uplift. Logic Weave uses frameworks including ISO 27001, ACSC Essential Eight, SOC 2, and NIST CSF. The methodology is practitioner-led: we run the risk meetings, test the controls, maintain the evidence, and keep the program defensible between audits — not just for them. GRC platforms like Vanta are supported natively, but not required. Deliverables include maintained policy libraries, risk registers with tracked treatments, compliance monitoring dashboards, management review documentation, security awareness training records, and quarterly or continuous reporting depending on tier. The engagement model is a fixed monthly retainer with no surprise fees; additional scope is priced separately and transparently. What makes Logic Weave different from other GRC providers is accountability. Most managed GRC providers send monthly reports and call it managed. Logic Weave runs the program day-to-day — attending risk meetings, testing controls, managing vendor due diligence, and maintaining audit readiness. The goal is zero regression between audits: sustained confidence, not periodic compliance theatre. For most SMBs, this replaces the need for an internal compliance function until a full-time hire is justified. Logic Weave is Melbourne-based and delivers GRC as a Service to organisations across Australia. ## Penetration Testing - URL: https://www.logicweave.io/melbourne-pentesting Logic Weave provides manual-first penetration testing for Australian SMBs, covering web applications, external and internal infrastructure, APIs, cloud configurations (AWS, Azure, GCP), and social engineering. The service is designed for organisations that need compliance-aligned, evidence-backed pentesting — not automated scan-and-report engagements that produce findings no one acts on. Testing methodology follows OWASP for web applications and APIs, and PTES and OSSTMM for infrastructure. All testers hold industry certifications including OSCP, CEH, CREST, and CCSK. Testing is manual-first: automated tools assist discovery, but findings are verified through manual exploitation with proof-of-vulnerability evidence for every issue reported. The engagement follows a structured process: kick-off and scoping (agreed scope, schedule, and testing windows including after-hours and weekends), execution by certified testers using real-world attack simulations, an evidence-backed report with executive summary and technical findings rated by business impact (not just CVSS scores), a prioritised remediation roadmap with debrief session, and a zero-cost retest within 45 days to verify that critical and high findings are properly remediated. Deliverables include a scoping document, detailed technical report with screenshots and proof-of-vulnerability for every finding, executive summary suitable for board and auditor review, prioritised remediation guidance, and retest verification report. Reports are aligned to ISO 27001, Essential Eight, and SOC 2 compliance requirements. What distinguishes Logic Weave from commodity pentesting providers is end-to-end accountability. Many pentest firms deliver a PDF and disappear. Logic Weave owns the gap list and stays accountable until vulnerabilities are verified closed — not just acknowledged. The zero-cost retest within 45 days is included in every engagement. Findings are prioritised by business impact and ease of exploit, giving development and IT teams actionable guidance rather than a raw list of CVEs. Logic Weave carries professional indemnity and public liability insurance. The firm has delivered pentesting engagements for Neuro+, Profile Financial, Accurateli, Isuzu Australia, Kyocera, Airwallex, NSW Education, and others. Melbourne-based, with testing delivered Australia-wide. ## Internal Security Audit - URL: https://www.logicweave.io/melbourne-internal-audit Logic Weave delivers internal security audits for Australian SMBs that need independent, practitioner-led assurance — not checklist-driven compliance exercises. The service is built for organisations preparing for ISO 27001 certification or surveillance audits, assessing Essential Eight maturity, or requiring independent control verification for board governance or regulatory obligations. Four audit types are available: ISMS Internal Audit (testing controls before ISO 27001 certification or surveillance audits, including management review support and evidence preparation), Essential Eight Maturity Assessment (evidence-based maturity testing across all eight ACSC strategies, scored against maturity criteria), Control-Specific Audits (scoped to specific risk register items, regulatory requirements, or board concerns — covering access controls, change management, data protection, vendor management, backup and recovery), and Pre-Certification Readiness Review (structured assessment 6–8 weeks before Stage 1 to reduce the risk of certification audit failure). The methodology is evidence-based and follows ISO 19011 audit guidelines. Logic Weave tests actual control effectiveness through document review, personnel interviews, and evidence inspection — not just what is documented or assumed by leadership. Auditors carry the independence that ISO 27001 clause 9.2 requires: the person who built the control cannot independently verify it works. Deliverables include an audit plan and scope agreement, documented non-conformities and observations with evidence, a prioritised findings report written for external auditors as much as for internal stakeholders, a remediation roadmap with tracked actions, and remediation verification before engagement closure. The engagement follows four phases: scoping (objectives, sampling methodology, schedule), fieldwork (control testing through evidence inspection and interviews), findings report (non-conformities, observations, and recommendations prioritised by risk), and remediation support (Logic Weave owns the gap list and stays accountable until findings are closed with verified remediation). What differentiates Logic Weave from other internal audit providers is practitioner depth and post-audit accountability. Internal audits are a governance activity — they test whether controls, policies, and processes are working — complementary to but distinct from penetration testing, which is a technical assurance activity. Logic Weave brings 24+ years of framework depth across FinTech, HealthTech, and SaaS, combined with ongoing remediation tracking rather than a report-and-walk-away engagement model. Internal audits do not replace external certification audits (which must be conducted by accredited bodies such as BSI, SAI Global, or LRQA), but they prepare organisations to pass them. Logic Weave is Melbourne-based, delivering internal audit services across Australia. ISO 27001 requires at least one internal audit per year; for most SMBs, Logic Weave recommends annual audits with a readiness review the quarter before each external audit. ## Fractional CISO (vCISO) - URL: https://www.logicweave.io/melbourne-fractional-ciso Part-time executive security leadership for FinTech, HealthTech, and SaaS businesses that need a CISO but cannot justify a full-time hire. Logic Weave's Fractional CISO service provides strategic security governance, risk management oversight, and board-level reporting embedded into your leadership team. Engagement models range from a few hours per week to near full-time, scaled to your stage and obligations. Melbourne-based, Australia-wide. ## ISO 27001 Certification - URL: https://www.logicweave.io/melbourne-iso-27001-readiness Full implementation path from gap analysis to certified ISMS, delivered in as little as 16 weeks. Logic Weave builds the management system, writes the policies, implements the controls, and prepares your team for certification audit. The service covers Statement of Applicability, risk assessment, internal audit, management review, and evidence preparation. We stay accountable through certification and beyond. Suitable for FinTech, HealthTech, and SaaS companies selling into enterprise or regulated markets. Melbourne-based, Australia-wide. ## Essential Eight Maturity - URL: https://www.logicweave.io/melbourne-essential-eight-maturity ACSC Essential Eight assessment and maturity uplift for Australian businesses targeting Maturity Level 2 (ML2) or Maturity Level 3 (ML3). Logic Weave assesses current maturity across all eight strategies, builds a prioritised remediation roadmap, and supports implementation to target maturity level. Evidence-based testing, not self-assessment. Aligned to the latest ACSC maturity model. Melbourne-based, Australia-wide. ## SOC 2 Type 2 - URL: https://www.logicweave.io/melbourne-soc2-type2 SOC 2 readiness and implementation for Australian SaaS companies selling into US enterprise markets. Logic Weave manages the trust service criteria mapping, control design, evidence collection, and auditor coordination. The service covers readiness assessment, gap remediation, control implementation, and audit preparation. We work alongside your chosen CPA firm for the formal audit. Melbourne-based, Australia-wide. ## Company - Founder: Mahesh Thiyagarajan — 24+ years of cybersecurity experience across APAC - Location: Suite 1s, 349–351 Bluff Road, Hampton VIC 3188, Melbourne, Australia - Phone: +61 402 644 100 - Email: info@logicweave.io - Website: https://www.logicweave.io - LinkedIn: https://www.linkedin.com/company/logicweave/ - Legal entity: Synverra Pty. Ltd. trading as Logic Weave - Target market: Australian SMBs (20–300 employees) in FinTech, HealthTech, and SaaS - Certifications held by team: OSCP, CEH, CREST, CCSK, ISO 27001 Lead Auditor, CISM, CRISC ## Blog - https://www.logicweave.io/blog/what-does-a-fractional-ciso-do: What Does a Fractional CISO Actually Do? — responsibilities, engagement model, and when Australian SMBs need one. - https://www.logicweave.io/blog/iso-27001-vs-essential-eight: ISO 27001 vs Essential Eight — which framework suits your Australian business and compliance obligations. - https://www.logicweave.io/blog/how-to-choose-cyber-security-consultant-melbourne: How to Choose a Cyber Security Consultant in Melbourne — what to look for and red flags to avoid. - https://www.logicweave.io/blog/how-to-prepare-for-penetration-testing: How to Prepare for a Penetration Test — scoping, evidence, what to expect, and acting on findings. - https://www.logicweave.io/blog/what-is-soc2-type2-australia: What is SOC 2 Type 2 and Does Your Australian Business Need It? — explained for SaaS companies. - https://www.logicweave.io/blog/it-internal-audit-guide: IT Internal Audit Guide for SMBs — what auditors check and how to prepare.