Cyber Security

vCISO Cost in Australia (2026): What Retainers Don’t Cover

Ashish Srivastava
Ashish Srivastava
Head of Cyber Security & Strategy

Share

Author

Ashish Srivastava
Ashish Srivastava
Head of Cyber Security & Strategy

In this article

    Key takeaways

    • Most vCISOs charge by the hour. The Australian vCISO market has established retainers which vary depending on the scope of work and number of hours per month. There are published retainers that vary from $5,000 to $15,000 per month for 10 to 40 hours.
    • The retainer is only part of the picture. In addition to the cost of the retainer, there are other costs such as licensing, insurance, testing and audits and incident response. These costs can be in the tens of thousands of dollars per year for mid-market and above organisations.
    • There’s no one-size-fits-all for vCISO spend. It largely depends on variables such as organisation size, industry, current security maturity and the security framework they are trying to implement (e.g. Essential Eight, NIST, ISO 27001).

    Boards are often asked by chairs what is the budget for cyber security for the year for their company and most CFOs will advise that it is the retainer paid for the vCISO. That is the wrong answer.

    Most research done by the CFOs of Australian companies searching for virtual CISO pricing consists of 2 types of information: US cost modelling developed for HIPAA and SOC 2 compliance (which is not relevant in Australia); and a provider’s product page outlining a fixed retainer and on occasion some extra items for which there might be an additional charge.

    Neither of these is likely to reveal the total AU$ expenditure on cyber security that you need to present to a board.

    The purpose of this article is to discuss the vCISO role (as defined by the ASD), how the market typically charges for such services and the 6 typical cost lines of a vCISO service that are rarely mentioned in quotes.

    This article is not meant to provide a number for your organisation’s vCISO needs. Size, industry, security maturity and target framework all vary greatly and hence form the basis of a vCISO cost that varies greatly. The direct answer to what does a vCISO cost is, it depends on what you want to achieve.

    What a vCISO does, as the ASD defines it

    A vCISO (virtual Chief Information Security Officer) is an executive-level, part-time cyber security resource providing strategic, compliance and risk-governance work to organisations that need the function but not a full-time hire.

    This article will use the general market definition of vCISO for the introductory section and then move on to the more useful definition provided by the Australian government.

    The ASD’s Information Security Manual contains the Guidelines for Cyber Security Roles. While the ISM was written primarily with government and classified systems in mind, it provides a useful framework against which TechBrain vCISO services can be scoped.

    The ASD’s eleven areas of accountability

    Leadership and guidance. A CISO is a cyber security leader who spans both information technology (IT) and operational technology (OT) helping other parts of the business to operate safely and securely.

    Overseeing the security programme. Ensure the security programme is operating in line with the information security policy, information security standards, regulatory requirements and legislation. Regularly review and identify areas of improvement for the security programme. Maintain a register of information systems and establish security metrics and KPIs to measure and report on.

    Coordinating security and business. Coordinating the security function and the rest of the business to manage the overall risk of the organisation. This would be running a steering committee of senior security people and senior business people to coordinate the management of risk.

    Reporting to the board. The CISO reports directly to the board of directors (and the audit, risk and compliance committee), not via another executive, providing information regarding the organisation’s security risk profile, the status of key systems, planned security work, recent security incidents and the expected return on security investment.

    Overseeing incident response. The CISO for a business is required to be fully aware of all incidents that occur within an organisation, to oversee the response of the organisation to such incidents, and in crisis management to step into the role required to handle such a situation.

    Business continuity and disaster recovery. Contributions to plans for business continuity and recovery from disasters in order to ensure that business functions will continue in the event that there is a disaster to allow for recovery of critical processes.

    Communicating the strategy. An organisation’s CISO develops a communications strategy and works to ensure that all employees (and third parties such as customers and vendors) are made aware of an organisation’s security vision and strategies and of the best ways to deal with security incidents and threats.

    Supply chain risk. Identify, assess, treat and manage on an ongoing basis the risk of harm to information or information systems from people, processes, vendors (suppliers) and other organisations in the cyber supply chain.

    Managing a dedicated budget. The ISM states plainly that the CISO receives and manages a dedicated cyber security budget.

    Overseeing security personnel. Attracting, training and retaining security staff, and delegating with adequate authority and resources.

    Overseeing awareness training. The CISO is also responsible for the organisation’s cyber security awareness programme.

    That ninth point is the subject of this article. The ASD position is that the person accountable for information security should also hold the budget for information security. That budget must be costed.

    💡 Expert Insight: Ashish Srivastava, Head of Cyber Security & Strategy

    A checklist tells you what’s ticked, not how the organisation actually behaves under pressure or who owns a decision when something goes wrong. So in the first quarter we’re building security into how the business thinks, not handing over a template.

    We sit with the client, identify the risks that are actually real for them, and build a risk register that reflects their organisation rather than a generic one. That risk register gets prioritised, the highest risks get security controls first, and everything else gets sequenced into a strategy that we can work through over the following months.

    Legal and regulatory obligations, whether that’s Privacy Act or APRA, get identified and built into that same register at the same time, not left as a separate compliance exercise nobody looks at again.

    What a vCISO costs in Australia in 2026

    A rough analysis of AU mid-market specialists’ published pricing in the market. As examples, organisations seem to charge around $5,000 to $15,000 per month. Typically this would translate to around 10 to 40 hours per month, or 1 to 2 days per week of consulting time however this is only part of the story.

    Three bands, by seat count and regulatory exposure.

    Strategic oversight. Generally this sits at around $60,000 to $96,000 per annum or $5,000 to $8,000 per month and includes annual strategy, quarterly reviews and light compliance. Such a service suits general professional services with low regulatory requirements.

    Programme delivery. Typically this costs in the vicinity of $108,000 to $180,000 per annum or $9,000 to $15,000 per month and would include continuous oversight, board reporting and active management of an ISO 27001, Essential Eight ML2 or APRA CPS 234 information security programme. Programme delivery is suitable for organisations with up to 250 employees in regulated industries such as medical, legal, accounting, wealth management and insurance.

    Certification or recovery sprint. The daily rates of $2,500 to $3,500 for one off jobs such as certification (e.g. ISO 27001) or the occasional cyber incident recovery sprint are typically for large one off projects and should never be annualised and mispriced like a full time hire for a 3 to 6 month project (after which the costs will typically return to those of the normal programme of work for certification or IRAP preparation etc).

    Agreements for organisations with more than 250 seats are generally scoped out on a case by case basis, with costs typically above those for mid market organisations listed above.

    Estimates published in the market create a range of costs for vCISO services of $60,000 per year (at the low end of the mid-market) and greater than $400,000 per year (at the high end of the enterprise market). These are not a pricing guide. They are evidence that the cost of a vCISO for your organisation cannot be read off a blog because the circumstances of every organisation are unique and the service solution should be scoped accordingly.

    Why TechBrain doesn’t price by the hour

    Many providers in the vCISO market charge by the hour, by the day or even by a monthly block of hours. TechBrain charges for outcomes and we are being measured and judged on the value that we are creating.

    As a result of the rapid impact of AI and automation, the value of ticket-fixing and hour-selling has dramatically reduced. The losers in this new market will be those charging by the hour because organisations, quite rightly, demand more than a timesheet demonstrating hours worked. The winners deliver real value to boards of directors in terms of specific skills, experience, tooling, vertical knowledge and relevant certifications all connected to the outcomes the organisation needs to manage cyber risk and satisfy obligations to various stakeholders including regulatory bodies, banks, insurers, shareholders and employees.

    Like all programmes of work, the vCISO programme for your organisation will differ from the programme for the next, as no two organisations are the same. TechBrain does not sell any form of cookie-cutter packages or programmes of work. We listen first, learn how your organisation actually works, and then build a bespoke programme. Each programme includes a number of deliverables which are designed to reduce risk and assist the stakeholders of the organisation in meeting their objectives.

    The table below shows how each of the ASD’s CISO accountabilities is delivered as an outcome.

    ASD accountability areas The outcome TechBrain delivers
    Leadership, board reporting and business alignment A scoped vCISO agreement with named stakeholders, standing strategy meetings and reporting direct to your senior executive or board
    Security programme, risk and metrics A TechSure assessment, a security programme built to your target framework, and a maintained risk register with KPIs your board can track
    Incident response, continuity and disaster recovery Your vCISO acts as incident manager and DRP/BCP coordinator, with plans built to your risk appetite
    People, awareness and communication A security awareness programme and a communication strategy that carries the security message across the organisation
    Supply chain and budget Security evaluation of new systems before they enter your environment, plus assistance with the security budget and return on investment reporting

    Where the money already sits

    The vast majority of the cyber budget for a mid-market organisation is already being spent. It’s already being consumed by software licences, cyber insurance, various tests and assessments whether or not a senior executive has engaged a vCISO retainer.

    That existing spend becomes defensible with the vCISO retainer. The retainer is the only new money being spent, and the cost of certification is a larger one off increase in the year of certification, not a large ongoing increase in annual spend.

    Line Typical annual (AUD) Already in most budgets Covered by the retainer
    Security licensing and SIEM ingestion $30,000 to $40,000 Yes No
    Cyber insurance premium $12,000 to $18,000 Yes No
    Penetration testing $10,000 to $25,000 Usually Scoped and governed, not performed
    Incident response retainer $10,000 to $15,000 Sometimes Planning yes, active response no
    ISO 27001 surveillance audit $4,000 to $15,000 If already certified Prepared for, not performed
    vCISO retainer Varies with scope This is the new line N/A
    Essential Eight ML2 uplift $10,000 to $50,000 Certification year only No
    ISO 27001 initial certification $40,000 to $70,000 Certification year only No

    Of course, it is easy to imagine a simple example of a 75-person organisation and come up with a total cost for them. However, such an example would be completely wrong. Two organisations of the same size in the same industry can easily land six figures apart, depending on their current maturity, the target framework, their insurance coverage and what they already have in place.

    The table above only outlines where the money is spent. It does not provide a total cost for your organisation, and any article that claims to provide one is simply guessing.

    On the other hand, the ASD’s Annual Cyber Threat Report 2024-25 reports that self-reported average direct loss per incident for medium-sized businesses in Australia increased by 55% year on year to $97,200. Please note that this average is for direct losses only and does not take into account indirect losses which can be significant.

    The 6 lines missing from your vCISO quote

    Six cost lines rarely appear on a vCISO retainer quote, and Australian mid market CFOs end up funding all of them.

    Infographic of the six cost lines rarely included in a vCISO retainer quote: penetration testing, audit and IRAP fees, Essential Eight ML2 uplift, security licensing and SIEM, cyber insurance impact, and an active incident response retainer

    Line Typical annual (AUD) Who performs it What the vCISO does
    Penetration testing $10,000 to $25,000 (range $6,000 to $40,000+) Separate testing vendor Scopes and governs the test
    Independent audit and assessment ISO 27001 initial project $40,000 to $70,000; surveillance $4,000 to $15,000 Certification body or ASD-endorsed IRAP assessor Prepares you for it
    Essential Eight ML2 uplift Gap assessment $10,000 to $50,000; $2,250/mo indirect IT time thereafter Your IT team Builds and governs the plan
    Security licensing and SIEM ingestion Per user per month, plus data ingestion Your licensing vendor Sizes it against what you already own
    Cyber insurance premium $12,000 to $18,000 Your broker and underwriter Produces the evidence pack for renewal
    Active incident response A$250 to $550/hr retained; A$1,100 to $2,100/hr emergency Separately retained IR provider Plans, tabletops and tests. Not live response.

    Four of these deserve a note.

    Audit is not equal to certification. Although the IRAP assessment is conducted by ASD-endorsed assessors as opposed to certification bodies, the cost is based on the system boundary of the organisation being assessed. The cost of audit for a certification body is based on an auditor day rate (e.g. 3 days to 15 days) and so is not something that can be included in a vCISO’s retainer as an independent third party audit.

    Licensing. The cost of security licensing and SIEM ingestion is typically charged per user, per seat, on a monthly basis and in addition, there may also be a charge for data ingestion into the SIEM per gigabyte ingested. Also check if the required licensing for detection is already included in your current licensing bundles.

    We have encountered many mid-market organisations who have paid double for duplicate detection tooling. TechBrain operate their own SIEM and support all the major platforms so this line should be sized off your current licences rather than the vendor’s preferred sales boundaries. Note that this is a licensing cost and not a retainer cost.

    Insurance. Insurance underwriters have a new eligibility gate for features and terms and conditions in a policy. This would include a named security lead, MFA across the entire environment, and EDR deployment. And in its 2024 claims report, Marsh McLennan noted that 37% of denied claims were due to organisations that had failed to enable MFA.

    The reality is that underwriters’ views on cyber security are evolving rapidly, with the result that organisations of high cyber maturity will pay 20% to 40% less for similar cyber coverage than organisations of average (or ‘below average’) cyber maturity.

    Incident response. Similar to audit, incident response (IR) is now another compliance line that CFOs need to procure and pay for on an annual basis. Outlined AUD fees for incident response are rarely advertised and figures provided above are only intended to act as a rough order of magnitude for planning purposes.

    The bigger pressure for CFOs around IR is around regulatory compliance, particularly around the mandatory reporting of ransomware payments made under the Cyber Security Act 2024 for organisations with greater than $3M in annual turnover. This commenced on 30 May 2025.

    💡 Expert Insight: Ashish Srivastava, Head of Cyber Security & Strategy

    One of the most common issues I see isn’t a misclassification of a regulation, but a misunderstanding of what a security tool is actually meant to address. Businesses buy an endpoint product or MDR service, assuming that having the tool in place means the risk is covered.

    The problem is, nobody stops to ask: what specific risk is this actually mitigating? With so many security products available, it’s easy to end up overspending on overlapping tools while leaving the risks that matter most, including those a regulator, auditor or insurer may ask about, largely unaddressed.

    You end up spending more on security, without actually knowing whether it’s providing adequate coverage.

    What actually applies to your business

    A number of frameworks are outlined below which are not ‘off the shelf’ for all organisations. Rather they are conditional and apply on the basis of licence, industry, function and supply chain. The greatest risk to boards is misapplication of scope, not intent.

    Decision tree showing which Australian cyber security obligations apply: all mid-market businesses face the Privacy Act, Notifiable Data Breaches scheme and Essential Eight Maturity Level 2, with APRA CPS 234 direct or flow-down and the SOCI Act 2018 applying only conditionally

    TechBrain is ISO 27001 certified by an accredited certification body, however the scope of the certificate refers only to the internal processes of TechBrain. Clients of TechBrain are not covered by this certificate and it can only be used as a working reference model.

    Privacy legislation for Australian mid-market businesses to comply with is the Privacy Act 1988 (Cth), and the OAIC’s Notifiable Data Breach scheme requirements as an APP entity. Small businesses (less than $3 million turnover) are currently exempt from Privacy Act obligations but this is to change under the pending Privacy Act reforms. Health and other organisations dealing with personal information, regardless of size, will also need to comply with Privacy legislation.

    The approach taken by ASIC in relation to enforcement of responsibility of AFS licensees for maintaining appropriate cyber security controls was established in ASIC v RI Advice Group.

    Most recently in February 2026 the Federal Court found FIIG Securities failed to maintain adequate cyber security controls with the matter resulting in a $2.5M penalty and $500,000 in costs, the first civil penalty imposed under the general AFS licensee obligations.

    For the boards of companies such as FIIG the consequence of such a breach is that not only is a breach declared and penalties paid by the company, but also that directors can be found to be liable for the governance failure that allowed the breach to occur in the first place, with the potential for directors’ liability under the Corporations Act s180. This is referred to as stepping-stone liability.

    In addition to these frameworks, the ASD has identified the Essential Eight mitigation strategies which form non-statutory advice for organisations. Achieving a Maturity Level of 2 against the Maturity Model for the Essential Eight represents a working baseline for the majority of AU mid-market organisations currently.

    Organisations are typically compared to other organisations by numerous cyber stakeholders, such as insurers, federal government procurement bodies, and board-level assessors.

    Conditional obligations

    Framework Applies when
    APRA CPS 234 (flow-down) You are a material service provider to an APRA-regulated entity such as a bank, insurer or superannuation fund. That entity must assure your cyber security as part of its own obligations.
    APRA CPS 234 (direct) You hold an APRA-regulated licence yourself.
    SOCI Act 2018 You operate a critical infrastructure asset above sector thresholds. Its 11 sectors do not include general mining as a standalone category.
    AFSL regime You are a financial services or wealth management licensee.
    Revised TASA Code You are a tax agent or accounting professional. Effective July 2025, published by the Tax Practitioners Board.

    Scope drivers by vertical

    Vertical Primary scope drivers
    Mining SOCI scope is limited, as general mining is not one of the 11 sectors, though there is energy-sector exposure for coal used in power generation. The more relevant drivers are Tier-1 supply-chain requirements (Rio Tinto publishes supplier cyber security requirements; BHP publishes minimum supplier requirements with thresholds varying by procurement category) and OT/IT convergence, where SCADA and industrial control system risk sits alongside corporate IT risk.
    Medical NDB reporting under OAIC legislation, additional reporting under state health records legislation, and clinical software vendor risk.
    Legal practice Professional conduct rules on client confidentiality, plus indirect APRA flow-down where the practice acts for a financial services licensee.
    Accounting AFSL data security requirements if licensed, reporting under the revised TASA Code, and practice-management software exposure.
    Wealth management AFSL obligations, APRA flow-down, FoFA conflict-of-interest data and client portfolio integrity.
    Real estate and insurance Trust account integrity for brokered data, plus state licensing requirements covering that data.

    The first 90 days and the 12-month board cadence

    A vCISO delivers a set of outcomes by month, not hours by month. The board governs those outcomes so the vCISO is accountable for a set of named artefacts on a named cadence.

    Month On the board’s desk
    1 Board-ready risk register, first draft of the NDB response runbook, Essential Eight gap analysis
    3 Essential Eight ML1 attestation evidence pack, IR plan tested by tabletop, review of the top 20 vendor risks
    6 Substantive progress against ML2, ISO 27001 readiness gap document, cyber insurance renewal pack
    9 Mid-year board cyber report, continuous monitoring established on vendor risk
    12 Annual board cyber statement, ML2 evidence pack, year-two roadmap with its budget envelope

    Recording down treatment of each risk as accept, treat, transfer or avoid creates a good audit trail for the vCISO’s stance on individual risks should it ever be questioned by a regulator.

    A vCISO functions better with a SOC than separate. Same SLA, same threat model, one phone number to call at 2am. A vCISO and a detection-and-response team are best delivered within the same engagement to keep the board’s view of risk aligned with the actual telemetry that an analyst sees.

    💡 Expert Insight: Ashish Srivastava, Head of Cyber Security & Strategy

    Without a SOC, month one is largely built from conversations and document review, organisations are working off what stakeholders know is happening. With a SOC already running behind the vCISO, TechBrain gets actual security events surfacing across the organisation from day one, not assumptions about what’s likely going on.

    That real telemetry feeds straight into the risk profile, so instead of a tabletop exercise built on hypothetical scenarios, we’re working off what’s genuinely been seen in the environment.

    If there’s an internet-facing service with a vulnerability sitting open, or MFA that’s misconfigured somewhere, that gets picked up and addressed in month one, not flagged as a finding to chase up in month three once someone’s had time to look properly.

    How TechBrain helps

    TechBrain provides a unified virtual CISO and managed SOC service to the Australian mid-market.

    TechBrain vCISO service is provided on a fractional retainer basis and is delivered as scoped against the ASD published CISO role definition, through an ISO 27001-certified Information Security Management System (ISMS), producing relevant governance artefacts for the boards of companies operating in regulated vertical markets including but not limited to: mining, medical, legal, accounting, insurance and wealth management.

    • Virtual CIO and CISO services: strategic security leadership, compliance assistance, high quality board reporting and risk governance on a fractional retainer basis.
    • Essential Eight assessment: assess Essential Eight coverage, identify any gaps and develop a strategy to meet regulatory requirements, with supporting evidence to take back to the board and provide to your insurers.
    • ISMS and ISO 27001 audit readiness: prepare your organisation’s ISMS for initial certification and for the subsequent surveillance audit. Reference will be made to the TechBrain operational ISO 27001 certified ISMS as appropriate.
    • Managed SOC: we monitor 24/7 and respond to threats, under the same SLA and threat model as our vCISO service.
    • Cyber incident response planning: we develop a Cyber Incident Response Plan and then conduct a tabletop exercise for you and your team. The retainer for emergency response can sit with TechBrain or with another provider, and scoped accordingly.
    • Cyber risk assessment: development of an ISO 27001-aligned risk register, treatment plan and all supporting documentation ready for board review.

    So what does a vCISO cost in Australia? It depends. Don’t take what the market data above has stated as the basis for pricing a vCISO programme for your organisation. Anyone that provides you with a number before understanding your organisation is guessing with your money.

    Give Ash a call to discuss the specific needs of your organisation. The call will cover the number of seats, industry and vertical, current maturity and programme requirements, and target maturity and outcomes. By the end of the call you will have a clear understanding of the requirements of a vCISO programme for your organisation.

    Want to know what a vCISO programme would actually look like for your organisation? TechBrain delivers a streamlined, cost-effective vCISO service built for Australian SMEs and mid-market organisations, scoped to your size, industry and target framework rather than a fixed block of hours. Explore our virtual CISO service, or book a call with Ash to talk through what your organisation actually needs.

    FAQs

    How does TechBrain price its vCISO service?

    We charge for our vCISO services by the programme, not by the hour. The scope of the programme is defined by the required outcomes for the organisation. It is based on the size of the organisation, the industry, current maturity and target framework(s). The cost of the programme is therefore based on a conversation about the objectives of the organisation rather than a rate card.

    Is the retainer the whole cyber budget?

    A large share of a typical cyber budget is spent on software, the organisation’s cyber insurance premium and various tests and scans that the organisation is already paying for as part of their IT spend. The retainer provides strong justification for that existing spend.

    Why does a certification year cost so much more?

    Certification year costs a lot more than the annual retainer because the certification for ISO 27001 and the Essential Eight ML2 uplift is a one-off programme cost. As a market range the cost for the ISO 27001 certification for a mid-market scope of work is $40,000 to $70,000. The cost for the Essential Eight ML2 gap assessment is $10,000 to $50,000. Note that these are one off costs and do not need to be paid in the following year, and pricing will be based on your organisation’s specifications.

    What happens if my vCISO gets sick, leaves or takes a full-time role mid-engagement?

    So then the vCISO falls ill, goes on annual leave or gets a full time job and that all happens in the middle of a contract. The solo vCISO has gone and you start looking again. The vCISO from a team-anchored provider has a named second person who has already been introduced to you and your environment, your SOC team etc. The SLA for the service as outlined in the SoW is still in place.

    Is a virtual CISO enough for cyber insurance, or do I need additional controls?

    In general the insurer wants to confirm that an organisation has a security person named, that basic controls are in place such as MFA, EDR, backups tested etc.

    There is a huge premium difference, as much as 20 to 40 percent, between an organisation of advanced cyber maturity vs less mature. A vCISO can help create an evidence pack to support the risk register, the IR plan, the tabletop sessions, the outcomes of the tabletop sessions etc. and then attest to the basic controls that have been put in place by the organisation to support the annual renewal.

    How long does it take to reach Essential Eight ML2 with a vCISO?

    For a SME this typically takes around 6 to 12 months. The vCISO will develop a plan for your organisation and govern it, while your IT staff complete the control configuration as part of their normal work. Once you have reached ML2, there is an ongoing cost in indirect IT time to operate at that level.

    Disclaimer: This article is general information, current as at 2026, and is not legal, compliance or financial advice. Cost ranges are drawn from published market sources and will not reflect your organisation’s circumstances. Regulatory obligations change and depend on your specific situation. Confirm what applies to you with your own legal and compliance advisers.

    Sources

    1. ISM Guidelines for Cyber Security Roles (December 2024), Australian Signals Directorate.
    2. ASD Annual Cyber Threat Report 2024-25, Australian Signals Directorate.
    3. 26-021MR ASIC action sees FIIG Securities ordered to pay $2.5 million over cyber security failures, ASIC, February 2026.
    4. 22-104MR Court finds RI Advice failed to adequately manage cybersecurity risks, ASIC, May 2022.
    5. Evaluating the Cost of vCISO Services in Australia, Securitribe.
    6. Virtual CISO, Siege Cyber.
    7. vCISO Services Australia Guide, CyberPulse, September 2025.
    8. CISO as a Service, Insicon Cyber.
    9. Cyber Insurance Market Trends 2024, Marsh Australia.
    10. Penetration Testing Cost Australia, CyberPulse, October 2025.
    11. ISO 27001 Certification Cost in Australia, Quality Assure.
    12. Cost Analysis for Achieving Essential Eight Compliance, Onsite Helper.
    13. Security of Critical Infrastructure Act 2018, Cyber and Infrastructure Security Centre.

    Ashish Srivastava

    Head of Cyber Security & Strategy

    I’ve been working in the cyber security space fo over 10 years, turning Essential Eight and ISO 27001 into practical steps that cut risk, shorten audits and lift security maturity.

    Ashish Srivastava

    Ashish Srivastava

    Head of Cyber Security & Strategy

    I’ve been working in the cyber security space fo over 10 years, turning Essential Eight and ISO 27001 into practical steps that cut risk, shorten audits and lift security maturity.

    Related Posts

    View all