IndustryCyber security leadership · Australia-wide

Virtual CISO & Cyber Security for Australian Federal Government Departments & Agencies

Independent Virtual CISO and cyber security leadership — Essential Eight uplift, ISM/PSPF-aligned governance and board-ready reporting, without a full-time CISO.

E8
Essential Eight
Assessment & uplift
GOV
Governance
Policy & controls
vCISO
Virtual CISO
Leadership on demand
RSK
Risk & reporting
Board-ready evidence
27+ yrs across security & government-facing systems
Independent leadership & assessment, no products
Australia-wide on-site same / next business day, or remote
24/7 available any day, any time

Independent Virtual CISO and cyber security leadership for Australian federal government departments and agencies — ISM- and PSPF-aligned governance, Essential Eight uplift, and IRAP-readiness support, without a full-time CISO.

Cyber security for federal government departments & agencies

Non-corporate Commonwealth entities are expected to meet the Essential Eight and align to the Information Security Manual (ISM) and Protective Security Policy Framework (PSPF). CISO Advisory provides senior, independent security leadership to help departments and agencies meet those obligations, evidence them to auditors, and report clearly to executives — based in and around Canberra and delivered nationally.

How we help Commonwealth entities

  • Essential Eight assessment & uplift to your target maturity level
  • ISM- and PSPF-aligned security governance, policy and controls
  • Security risk assessments and prioritised remediation roadmaps
  • IRAP-readiness support — preparing systems and evidence ahead of formal assessment, and coordinating with certified IRAP assessors
  • Incident response planning, third-party risk, and executive/board reporting

Independent by design

We provide leadership and assessment — not security products — so our advice is objective and defensible to the ANAO, ministers and oversight bodies. Led by a founder with 27 years of hands-on experience across security and government-facing systems.

Frequently asked questions

Do you align to the ISM and PSPF?
Yes — our governance, controls and reporting are mapped to the ISM and PSPF, with Essential Eight uplift at the core.

Are you an IRAP assessor?
We provide vCISO leadership and IRAP-readiness support, and coordinate with certified IRAP assessors where a formal assessment is required.

Can you work with our existing teams and providers?
Yes — we provide the independent security leadership and governance layer above your in-house team or panel providers.

Securing a federal department or agency? Essential Eight uplift, Virtual CISO, or book a confidential call.

Frameworks we assess and advise against
E8
Essential Eight
ASD · ACSC
ISM
Information Security Manual
ASD
PSPF
Protective Security Policy
Home Affairs
IRAP
IRAP readiness
ASD-endorsed
ISO
ISO/IEC 27001
ISO/IEC
NIST
NIST CSF 2.0
NIST

Independent security leadership for your organisation.

Start with Essential Eight uplift, a Virtual CISO engagement, or a confidential call. No obligation.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act