Privacy Policy

CISO Advisory Australia (“we”, “us”, “our”) is committed to protecting your privacy. This policy explains how we collect, use, disclose and safeguard personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Information we collect

We collect personal information you provide directly through our enquiry and booking forms, by email, or by phone, including:

  • Your name and the organisation you represent
  • Contact details — email address and phone number
  • The sector you operate in and the details of your enquiry

When you visit our website, we also automatically collect limited technical information through analytics — including your IP address, device and browser type, pages viewed and referring source — via cookies and similar technologies (see “Cookies and analytics” below).

How we use your information

  • To respond to your enquiry and arrange consultations
  • To provide, scope and deliver our advisory services
  • To communicate with you about your engagement
  • To improve our website and understand how it is used
  • To meet our legal and regulatory obligations

Disclosure of personal information

We do not sell your personal information. We may disclose it to trusted service providers who help us operate our business — including our website host and our analytics provider — and where required or authorised by law. These providers are bound to protect your information and use it only for the purposes we engage them for.

Overseas disclosure

Some of our service providers (for example, analytics services) may store or process information on servers located outside Australia. Where this occurs, we take reasonable steps to ensure your information is handled consistently with the APPs.

Cookies and analytics

We use Google Analytics to understand website usage. This uses cookies to collect anonymised, aggregated data about visits. You can disable cookies in your browser, or opt out of Google Analytics using Google’s browser add-on, without affecting your ability to use the site.

Data security

We take reasonable technical and organisational measures to protect personal information from misuse, loss, unauthorised access, modification or disclosure. As an independent cyber security advisory, security is central to how we operate. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

Access and correction

You may request access to, or correction of, the personal information we hold about you by contacting us using the details below. We will respond within a reasonable period.

Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law, after which it is securely destroyed or de-identified.

Complaints

If you have a concern about how we have handled your personal information, please contact us first so we can address it. If you are not satisfied, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Changes to this policy

We may update this policy from time to time. The current version will always be available on this page.

Contact us

For any privacy enquiry, contact us at contact@cisoadvisory.com.au or call 07 2112 8502.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act