Themis Services
Not a bench. Practitioners who've carried the accountability.
Product and application development, security and certification programmes, and corporate finance work, delivered by people who have carried the accountability themselves, in identity proofing, payments, healthcare and fraud prevention.
Track record
15+
Years across regulated sectors
4
Core sectors: identity proofing, payments, healthcare, fraud prevention
3
Certification frameworks implemented end to end
One contracting entity, one security posture: Themis Systems Pty Ltd.
Three practices
Build it, secure it, fund it.
Most engagements sit in one practice. The interesting ones sit across two: a new product that needs an ISMS before a bank will sign, or a capital raise that needs the product story to be true.
Practice 01
Product & application development
From concept to MVP and minimum lovable product, and from legacy application to something you can maintain.
- New product development, concept through MVP and MLP
- Design thinking, jobs-to-be-done and lean discovery
- Wireframes, prototypes, solution architecture and user stories
- Agile delivery: scrum tooling, artefacts, planning and showcases
- Specifications and documentation that outlive the engagement
Practice 02
Security, risk & certification
The programme, the artefacts and the audit, run to the standard an internal audit function will accept.
- ISO 27001 information security management system, build to certification
- ISO 31000 risk management frameworks, policies and risk registers
- PCI DSS architecture advice, e-commerce acquiring and certification support
- System security plans, security risk management plans, BAU monitoring and alerting
- Incident response, business continuity and disaster recovery planning
- Auditor selection and certification support through to issue
Practice 03
Corporate finance & capital
Modelling and documentation for founders and boards who have to defend the numbers in a room full of financiers.
- Financial models and business plans that capture future value
- Sensitivity analysis and forecast financial statements
- Bespoke information memoranda for targeted fundraising
- Financier selection and founder introductions
- End-to-end fundraising support, share purchase and shareholder agreements
- Negotiation and document execution
How we engage
Small, senior, and accountable to a named person.
You get a named principal who stays on the engagement from scoping to handover, not a rotating bench, backed by a network of specialists engaged per assignment.
A fixed price when the outcome is definable (an ISMS, a model, an information memorandum). Time and materials only where genuine discovery is the work.
Engagement shapes
Four ways this usually starts
Certification sprint
A dated certification target with a gap assessment, a remediation plan and the artefacts written for you.
Build a product
Discovery through to a working MVP, with the architecture and documentation your team can take over.
Raise capital
Model, memorandum, financier shortlist and support through negotiation and execution.
Interim leadership
A senior pair of hands in a product, security or delivery seat while you recruit permanently.
Why it matters to us
We hold the certifications we implement
Themis Systems runs its own ISO 27001, ISO 42001 and SOC 2 posture across TAMMY and Themis Install. When we advise on an information security management system, we are describing something we operate, not something we have read about.
Next step
Tell us the deadline and who has to sign off.
Those two facts shape the engagement more than anything else. Send them through and we will come back with a shape and a price, not a capability deck.