About CISO Advisory

Independent security leadership you can trust.

CISO Advisory Australia provides independent, senior cyber security leadership to government, councils and enterprise — helping organisations reduce risk, strengthen governance and stay compliant, without the cost of a full-time CISO.

27 yrs
Hands-on security & government-facing systems
100%
Independent — no products, no vendor ties
Australia-wide
On-site same / next business day, or remote
24/7
Available any day, any time
Who we are

We are an independent cyber security advisory practice. We don't resell products and we aren't tied to any vendor — which means our advice serves you, not a sales target. Our focus is practical governance, executive-level reporting and outcomes that hold up to audit and to the board.

Our founder

Ken Armitt

Founder & Principal Advisor

27 years hands-on across cyber security, SaaS, fintech, payments and government-facing systems. Ken works directly with executives, boards and risk committees to translate technical risk into business decisions — and to build security programs that endure. Every engagement is delivered with that senior judgement, not handed to a junior team.

What we do
vCISO

Virtual CISO

Senior security leadership on demand.

E8

Essential Eight

Maturity assessment and uplift.

ISO

ISO 27001

Readiness and certification support.

CPS

APRA CPS 234

Compliance for regulated entities.

DD

Cyber due diligence

For investors and acquirers.

AI

AI consulting & robot integration

Secure, practical AI adoption and automation.

Who we work with

We work with Australian federal, state and local government and councils, financial institutions, critical infrastructure operators, healthcare providers and well-funded enterprise. We can be on-site the same day or next business day, or work remotely — anywhere in Australia.

Federal government State government Local government & councils Financial institutions Critical infrastructure Healthcare Well-funded enterprise
The frameworks we work to

Assessed, uplifted and evidenced for auditors, regulators and boards.

E8Essential Eight
ISOISO 27001
CPSAPRA CPS 234
ISMACSC ISM
PSPFPSPF
IRAPIRAP
NISTNIST CSF
SOC2SOC 2
PCIPCI DSS

Talk to us.

To discuss how we can help your organisation, book a confidential consultation or call — available 24/7, any day, any time.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act