Local Government

Independent ICT advice for the technology decisions your council cannot get wrong.

Councils are judged on ICT governance, cyber risk and how procurement decisions were made. We develop the plans, frameworks and tender documents that give your CEO, elected members and auditors confidence those decisions were made properly.

FROM THE FOUNDER

We have worked with WA councils since 2019.

Simon Cohen established Cohesis in 2019 to give WA councils access to senior ICT expertise they could not otherwise reach. Simon has worked in ICT for over 25 years. Since 2019 that experience has gone into the problems CEOs, Directors of Corporate Services and senior managers actually bring to us:
Common symptoms

You know your council needs independent advice when...

The same findings appear in your audit reports year after year.

You have no current ICT plan your elected members have endorsed.

Your ICT policies were written years ago and no longer describe how the council operates.

Staff are using AI tools and no policy covers what they can put into them.

An ERP replacement is coming and nobody has documented how the council works now.

The PRIS Act commenced on 1 July 2026 and nobody at the council owns it.

Your BCDR plan has not been tested since the day it was written.

Every vendor you speak to recommends their own product regardless of your situation.

Most of this starts to surface in the first conversation. An ICT Health Check is usually the fastest way to see the full picture.

What We Do

What Cohesis does for local government.

Cohesis provides independent local government ICT consulting to metropolitan and regional councils across Western Australia.

We assess ICT environments, write ICT plans and digital strategies, develop governance frameworks and policy suites, and run ERP, vendor and MSP selection processes including market analysis, RFTs and RFQs.

We are a WALGA Preferred Supplier, so councils can engage us directly without going to open tender, subject to their own procurement policies.

Independent assessments

Know where your council stands before the auditors ask.

Most growing businesses have a rough sense that something isn’t working. What they don’t have is a structured, independent view of where the actual risk and inefficiency sits, or which platform or supplier is quietly costing them the most. Every engagement starts here, not because it’s the biggest sale, but because the recommendation is only as good as the assessment behind it.

ICT Health Check

A structured review of your whole ICT environment. What is working, where risk is accumulating, and what to address first. Most councils start here, either ahead of an OAG audit or to establish a baseline before committing to an ICT plan.

Essential Eight Assessment

Every control scored against the ACSC's four maturity levels. Control-by-control findings rather than one aggregated score that hides the gaps, then a remediation roadmap ranked by risk and effort.

PRIS Readiness Assessment

The Privacy and Responsible Information Sharing Act commenced on 1 July 2026, and local governments are public entities under it. We assess whether the governance, controls and named roles the Act sets out are in place, and what needs work before serious data breach reporting begins on 1 January 2027.

AI Readiness Assessment

Your staff are already using AI tools, whether or not the council has approved it. We work with your team to establish which tools are in use, what council information is going into them, and whether policy and controls cover any of it. Then we set out what a governed rollout inside Microsoft 365 would take.

Strategy and planning

A council ICT strategy your elected members can get behind.

Councils rarely lack ideas about technology. What is usually missing is a plan that connects them to the corporate business plan, the budget cycle and what the council can realistically deliver with the staff it has. We write ICT plans your leadership team can put in front of council and still be working to in year three.

3 to 5 year ICT plan

A costed, sequenced ICT plan aligned to your corporate business plan and budget cycle. Priorities ranked by risk and deliverability, so your leadership team can defend the sequence to elected members and auditors can see the reasoning behind each decision.

Digital strategy development

We have written digital strategies for the City of Canning, the City of Perth and the City of Bayswater. Each one built around that council's services, workforce and community obligations. Digital and ICT risks are identified inside the strategy rather than bolted on afterwards, and every recommendation carries a practical next step rather than an aspiration.

Procurement

Procurement decisions your council can defend to anyone who asks.

An ERP replacement is the largest technology decision most councils make in a decade, and the part that goes wrong is rarely the software. It is the requirements nobody documented, the market nobody surveyed, and the scoring criteria written after the vendors had already presented. We run the process in order, and every stage produces a document your council owns.

Business process mapping

How your council works now, documented before anyone writes a requirement. Workflows are mapped across finance, rates, records, planning and customer service, then analysed for where duplication and manual handling sit. Councils often buy this on its own, because it is also the evidence base for everything that follows.

ERP vendor market analysis

An independent view of the ERP market for local government before you commit to a tender. Which systems are genuinely used by councils your size, what each one does well, and where the practical limitations sit. Knowing this early changes what you ask for.

RFT & RFQ documentation

Tender documentation that gives vendors what they need to price accurately and gives your council a scored, defensible outcome. Requirements, evaluation criteria and weightings are agreed before responses arrive, not after.

ERP selection

Vendor responses assessed against criteria your council set. Structured demonstrations, reference checks, commercial terms interpreted in plain language, and a documented recommendation your CEO can take to council.

Vendor & MSP selection

Independent review of your current support arrangements against SLAs, ticket resolution, regional site coverage and user satisfaction. Then a recommendation on the right support model for your council's size and risk profile. We are not a managed service provider, so we are never reviewing a competitor.

Project management

Independent project management that keeps delivery accountable to the council rather than the vendor. Scope, risks and issues reported to your leadership throughout, and we represent the council's interests from requirements through to go-live sign-off.

ERP & MRP SELECTION

Six shires, one ERP selection process

We led the Shires of Williams, West Arthur, Carnamah, Cuballing, Kojonup and Dumbleyung through a collaborative ERP selection. We worked with each shire individually and then all six collectively to gather requirements, agree scoring criteria and build an RFT that let vendors price for the consortium.

Evaluated systems included Magiq, CouncilFirst, Readytech and Datascape.

Governance

Governance frameworks that hold up when the OAG wants evidence.

Auditors do not ask whether your council has good intentions about technology. They ask to see the policy, when it was last reviewed, who owns it, and what happened the last time it was tested. We develop governance frameworks and policy suites that answer those questions with documents rather than assurances.

ICT governance framework

Current state established through interviews with your leadership team and ICT staff, then a framework setting out decision rights, escalation paths and review cycles. Policies aligned to the Essential Eight, LGIS guidance and OAG expectations, with a named owner against each one.

Policy suite development

The full suite developed as connected documents rather than seven separate files. Asset management, risk management, cyber, backup, data classification and privacy, each with accountability written in and a review date your council can actually meet.

Business continuity & disaster recovery planning

The Local Government Act 1995 requires councils to document, test and update disaster recovery arrangements. We build BCDR plans around your actual systems, services and community obligations, then guide your team through the testing cycle so the plan stays current as systems and staffing change.

Microsoft 365 apps

Microsoft 365 apps built for the way councils work.

Two of our apps are built specifically for local government operations. Both run inside your council's existing Microsoft 365 environment, so there is no new infrastructure, no separate logins and no third-party hosting. These are Cohesis products, built by our Agendis team. They are the only systems on this page we license ourselves, and we will always tell you so.

AgendisRISK

Your AI risk assistant, built into Microsoft 365.

A live risk register, compliance assessments, incident tracking and reporting your team can take to council, all inside the environment your staff already use. The Essential Eight framework is built in as standard, so your council can run its own self-assessment at any time and track remediation without waiting for an external review.

Point it at any document where risks, actions and decisions are buried. An OAG audit report, an internal review, a consultant’s findings, minutes from an executive meeting, a workshop transcript. AgendisRISK extracts them as tracked items with owners and due dates, so the things your council has already identified stop sitting in documents nobody reopens.

That includes assessments we deliver, which load straight in. It works exactly the same way with reports from anyone else.

21-day implementation guarantee.

We will have your environment live and your team using it within 21 days of receiving your Microsoft 365 credentials, or we extend your first year at no additional charge.

A professional vCIO demonstrates the AgendisRISK interface on a laptop screen featuring interactive risk heatmaps and compliance registers in a modern office.
WA Local Governments We Have Worked With Since 2019

25+ WA councils & Shires, from the CBD to the regions

Metropolitan and regional local governments across Western Australia, served since 2019.

cities
City of Canning Logo
City of Cockburn Logo
City of Bunbury Logo
shires & Councils
Cohesis Image - Shire of Wiluna Logo
Cohesis Image - Shire of Denmark Logo
Cohesis Image - Shire of Dumbleyung Logo
Cohesis Image - Shire of Mingenew Logo
Shire of Yalgoo Logo

Why Cohesis

We have vendor relationships. We do not have vendor-influenced advice.

We take no commissions & no referral fees

No third-party system we recommend pays us anything. We are not a managed service provider either, so when we review your MSP we are not reviewing a competitor. We do license our own Microsoft 365 apps, including AgendisRISK, and we will always tell you so. What we never do is put our own product into a selection process as though it were the neutral outcome of a comparison.

We know what the OAG looks for

Local government is most of what we do. OAG expectations, obligations under the Local Government Act 1995, the PRIS Act, Essential Eight maturity and LGIS guidance. We know which findings recur across councils and why.

We report what we find

Assessments are evidence-based and the findings go in the report whether they are convenient or not. Sometimes the recommendation is that a council should not change anything yet.

Ready to Move Forward

Most councils have an ICT gap to close. Let's talk about yours.

Tell us where your council is and we will give you a clear picture of how we can help. No obligation. A direct conversation with someone who knows local government.
Common Questions

FAQS

An ICT Health Check. It gives your council an independent, evidence-based picture of where the ICT environment stands, what is working, where risk is accumulating, and what to address first. Councils use it to prepare for an OAG audit, to inform a 3 to 5 year ICT plan, or to establish a baseline before committing to further work.
An ICT Health Check, and a BCDR review if your plan is not current. Both address the areas the OAG focuses on. The health check covers your ICT environment and governance posture. The BCDR review checks your plans against the obligations in the Local Government Act 1995. If Essential Eight gaps need addressing, that assessment runs alongside or immediately after. We will help you prioritise against your audit timeline.
Cohesis is a WALGA Preferred Supplier, so councils can engage us directly without going to open tender, subject to their own procurement policies. Contact us and we will confirm the right pathway for your requirements.
The OAG has increased its focus on ICT governance maturity across WA local governments. Findings commonly relate to ICT policies that are out of date, inadequate BCDR planning, cyber risk that is not being managed, and the absence of a formal ICT risk register. Essential Eight maturity is referenced more often each year.
The Essential Eight is a set of eight cyber security mitigation strategies published by the Australian Cyber Security Centre. Formal compliance is mandatory for Commonwealth entities. WA local governments are increasingly expected to demonstrate Essential Eight maturity in OAG audits, cyber insurance applications and governance frameworks. An assessment measures whether the controls are in place. It does not tell you whether your environment has been compromised.
Yes. Local governments are public entities under the Privacy and Responsible Information Sharing Act 2024, which commenced on 1 July 2026. Eleven Information Privacy Principles apply to how the council collects, uses, stores and shares personal information, and each public entity must designate a privacy officer and an information sharing officer. Mandatory reporting of serious data breaches begins on 1 January 2027. We assess whether the governance, controls and named roles are in place. We do not provide legal advice on the Act.
An ICT Health Check. It gives your CEO and council a clear picture of where the environment stands, the priority risks, and what a realistic improvement plan looks like. From there we work alongside your IT officer to build the plan and the governance, so the capability stays inside the council.
AgendisRISK is a Cohesis product, built by our Agendis team. It is a risk and compliance platform that runs inside your council's existing Microsoft 365 environment, with no additional software or hosting required. It works with any document containing risks, actions or decisions, including reports from other providers, not only assessments we deliver.