Website Security for
Government & Statutory Bodies

Drupal, GovCMS and legacy public-sector websites secured, upgraded and maintained by Brisbane engineers, with the evidence your agency needs under Queensland’s data breach scheme.

Pixelbird client
Pixelbird client
Pixelbird client

Over a decade of website security expertise

Public Sector Sites Are Under Pressure

Queensland government agencies have been under a mandatory data breach notification scheme since 1 July 2025, and local councils since 1 July 2026. Agencies must assess suspected breaches, keep a breach register and publish a data breach policy.

At the same time, many public-sector sites run on Drupal versions that are out of support or close to it. Drupal 10 reaches end of life on 9 December 2026, and Queensland bodies are still running it.

Statutory bodies, boards and authorities often sit between the big platforms, with smaller teams and older sites built by contractors who have moved on.

Businessman Wearing Headset Talking To Caller In Busy Customer Services Centre

Secure,

Supported and

Accessible

Sites

Secure, Supported

and Accessible Sites

Secure, Supported

and Accessible Sites

We work on Drupal and GovCMS, WordPress and legacy PHP sites for public-sector organisations: security reviews, upgrades and migrations off end-of-life versions, custom module and code reviews, and WCAG 2.2 accessibility fixes.

Our audit gives you an independent view of where your site stands, what personal information it holds and whether you could assess a suspected breach quickly, with findings your executive and audit committee can act on.

Brisbane based, on your time zone, and comfortable working within procurement and change-control processes.

Smiling mature confident professional executive manager at office.

Why Agencies

Choose

Pixelbird

Why Agencies

Choose Pixelbird

Why Agencies

Choose Pixelbird

Drupal & GovCMS Engineers

Upgrades, custom modules and security reviews from engineers who know Drupal’s internals, not just its admin screens.

Accessibility Built In

WCAG 2.2 AA testing and fixes as part of every upgrade, not an afterthought.

Evidence for Oversight

Dated, independent findings for your executive, audit committee and breach register.

0

December 2026: Drupal 10 Reaches End of Life

0 %

Of Drupal Sites on End-of-Life Versions (Aug 2026)

0

Data Breaches Notified to the OAIC in 2025

0 +

Years Shipping Production Software

How It Works

We confirm your platform, hosting arrangements and constraints, and give you a fixed price.

Young African businessman looking at data on computer screen

Step 2: Independent

Assessment

Our engineers review your site, modules, access, data handling and accessibility.

Group of young happy business people looking at laptop screen, communocating and discussing work

Step 3: Report

& Remediate

You get rated findings for your executive and audit committee, and we can fix them.

Brands We Have Helped

What People Say

Makes the Magic Happen

“Love the professional finishes . Dustin and the team know how to make the magic happen.”

Sam Hunter

Sam Hunter

Corporate Headshot Photographer

Always Shows Up

“I have hired Pixelbird many times to build websites and to host. I recommend Dustin and his team without question.”

Kym Bolger

Kym Bolger

Social Media Marketing

Responsive Professionalism

“Dustin is friendly and good to work with. He is good at finding better ways to provide solutions and automate the processes.”

Ivan Huang

Ivan Huang

CPA

What You Can Expect

What You Get

Pixelbird

Typical Agency

Drupal Upgrades

With Us

Audit first, staged and tested

With Them

A rebuild quote

GovCMS

With Us

Self-managed and managed sites supported

With Them

Generic Drupal advice

Custom Modules

With Us

Reviewed against security advisories

With Them

Not reviewed

Accessibility

With Us

WCAG 2.2 AA tested and fixed

With Them

A plugin and a statement

Breach Readiness

With Us

Logging and data flows checked

With Them

Not considered

Personal Information

With Us

Data held by the site mapped

With Them

Not assessed

Change Control

With Us

Staging, release notes and rollback

With Them

Changes straight to live

Documentation

With Us

Clear handover docs

With Them

Knowledge in one person’s head

Reporting

With Us

Findings for executive and audit committee

With Them

Technical jargon

Location

With Us

Brisbane, on your time zone

With Them

Offshore or interstate

Frequently Asked Questions

Yes. On self-managed GovCMS sites we help with development, upgrades and security work. On fully managed sites, where the platform team handles core patching, we help with themes, configuration and accessibility.

Agencies must assess suspected breaches, notify the Office of the Information Commissioner and affected people when an eligible breach occurs, keep a breach register and publish a data breach policy. Get advice on your obligations.

Plan the move to Drupal 11 before 9 December 2026. It’s usually a much smaller upgrade than a Drupal 7 migration, but modules and custom code need checking first.

Yes. We test against WCAG 2.2 AA and fix templates, components and content patterns, ideally as part of an upgrade.

Yes. We’re happy to work alongside in-house IT and digital teams, taking on the specialist development and security work.

Keep Your Agency’s Site Secure and Supported