Zero
Non-conformities across 6 ISO 27001 audits
Designed and led the ISMS through six consecutive surveillance and recertification cycles without a single non-conformity.
Sydney · Independent Advisory · Est. 2006
Executive-grade information security advisory for DEWR providers, not-for-profits and mid-market organisations who need defensible governance, audit-ready controls and a trusted advisor at the table — without retaining a Big Four engagement.
By the numbers
19+
Years in IT & Security
6
Consecutive ISO 27001 audits, zero non-conformities
18
Subcontractor RFFR assessments led
ML3
Essential Eight, 5 years sustained
Advisory services
Executive-level security leadership on a fractional basis — board reporting, strategy, risk posture and program ownership.
Learn moreImplementation, gap assessment and certification readiness designed to pass external audit and operate sustainably.
Learn moreRight Fit For Risk uplift for DEWR providers and their subcontractors, aligned to ACSC ISM and Essential Eight.
Learn moreIndependent maturity assessments and pragmatic roadmaps to ML2 / ML3 — no over-engineering, no vendor agenda.
Learn moreTenant hardening, Purview, Defender, Entra ID and conditional access aligned to your control framework.
Learn moreGovernance, classification and information architecture for cloud and SharePoint migrations done properly.
Learn moreEnterprise risk frameworks, third-party risk, and risk treatment plans your board and auditors can rely on.
Learn moreBridge the gap between engineering reality and compliance obligations — practical controls, evidence and reporting.
Learn moreWhy clients engage me
CEOs, CIOs, boards and risk committees engage me for clarity, accountability and audit-ready outcomes — without the bloat of a tier-one consultancy.
No product quotas, no vendor incentives. Advice is calibrated to your risk and budget — not a partner programme.
Acting CISO and Information Security Manager engagements — I've owned the program, not just audited it.
Six consecutive ISO 27001 surveillance and recertification audits delivered with zero non-conformities.
ACSC ISM, Essential Eight, RFFR and DEWR expectations — translated into controls your team can actually run.
Frameworks & expertise
Deep working knowledge of ACSC, ISO, NIST and Microsoft control sets — translated into pragmatic, auditable programs for organisations operating under government and regulator scrutiny.
Selected engagements
Zero
Designed and led the ISMS through six consecutive surveillance and recertification cycles without a single non-conformity.
18
Led Right Fit For Risk readiness for a DEWR provider and its subcontractor network — uplifted to government expectations.
ML3
Took an organisation from baseline to Maturity Level 3 and held it through hybrid Microsoft and SaaS environments.
Certifications




















How we work together
A confidential conversation to understand context, drivers, regulators and the outcome that matters.
Structured review of current state against the relevant framework — ISO 27001, Essential Eight, RFFR or ISM.
A prioritised, costed plan calibrated to your risk appetite, change capacity and certification timeline.
Hands-on advisory through implementation, audit and continuous improvement.
Client perspectives
Names withheld · scroll to read
Identities of clients and organisations withheld. Full references available on request under NDA.
Begin the conversation
A 30-minute advisory call — no pitch, no scripted discovery. Just a candid conversation about the outcome you need and whether I'm the right person to help you get there.

All initial conversations are confidential. Engagements operate under NDA where required.