Information Security

Information Security Policy

How Real Bytes protects your data, our systems, and the integrity of our operations, every day.

Our Security Commitment

Information security is not an afterthought at Real Bytes. It is central to everything we do. As a managed IT and cybersecurity provider, we hold ourselves to the same standards we set for our clients. This policy outlines the controls, frameworks, and practices we maintain to protect the confidentiality, integrity and availability of all information assets.

This policy applies to all Real Bytes staff, contractors, and partners with access to our systems or client data. It is reviewed annually and updated in response to the evolving threat landscape.

Frameworks & Standards

Australian Essential Eight

ACSC's Essential Eight mitigation strategies

ACSC Partner

Australian Cyber Security Centre partner network

SMB1001:2026

International Edition cybersecurity standard

ISO 27001 Aligned

Information security management best practices

Privacy Act 1988

Australian data protection compliance

SOCI Act 2018

Security of Critical Infrastructure obligations

Policy Areas

Staff Awareness & Training

All Real Bytes staff complete mandatory security awareness training at onboarding and annually thereafter. Training covers phishing recognition, data handling, password hygiene, and incident reporting procedures. Simulated phishing campaigns are run quarterly to reinforce awareness.

Customer Data Handling & Offboarding

For managed services clients, Customer Data is accessed only to provide the contracted Services and is treated as confidential. Access controls, logging and least-privilege principles apply to all engineer activity inside a client environment.

When an engagement ends, Real Bytes makes any Customer Data we hold available to the client for a 60 day Offboarding Period. After that period, we may (subject to applicable law) permanently and irretrievably delete Customer Data in accordance with our usual practices, including secure wipe or disposal of storage devices. Full details are in our Terms and Conditions.

Third-Party Risk Management

All third-party vendors and subcontractors with access to Real Bytes systems or client data are assessed prior to engagement. We require evidence of appropriate security controls, conduct periodic reviews, and maintain data processing agreements (DPAs) where required under Australian privacy law.

Cyber Incident Reporting

Where required by law, Real Bytes may notify and cooperate with relevant Australian authorities (including the Australian Cyber Security Centre) in relation to a cyber incident, including by providing information reasonably necessary to meet legal or regulatory obligations. Unless required by law, Real Bytes has no obligation to make any external report on a client's behalf. Critical infrastructure clients are supported through their own obligations under the Security of Critical Infrastructure Act 2018 (Cth).

Report a Security Issue

If you believe you have discovered a security vulnerability or wish to report a security concern, please contact us immediately.