Skip to content

The security lead your board can name.

Inline Code is your fractional CISO. We run the security frameworks your regulators and customers ask for, from Essential Eight to ISO 27001 and APRA CPS 234, and we secure the AI you are putting to work.

Or download the free AI governance readiness checklist

Illustration of a weekly board briefing: decisions waiting, Essential Eight progress, an AI register and a refused agent action.

Illustrative data

Built on the frameworks you are measured against

See how we map them
  • Essential Eight
  • ISO/IEC 27001
  • APRA CPS 234
  • APRA CPS 230
  • NIST CSF 2.0
  • ISO/IEC 42001
  • NIST AI RMF
  • Privacy Act
  • OWASP Top 10 for LLMs
  • MITRE ATLAS

One practice, three ways in.

Most clients start with one and add the others as the work shows what is needed.

Fractional CISO

A named security lead, without the full-time hire.

We hold the accountable seat for your security and AI risk: board reporting, a quarterly posture re-assessment, policy upkeep and vendor risk reviews, with a direct line to the person doing the work.

Twelve-month engagement with quarterly review points.

Security frameworks

Frameworks that run, not binders that sit.

We map where you stand against Essential Eight, ISO 27001, APRA CPS 234 or NIST CSF 2.0, give you a remediation roadmap in priority order, and test the controls the way an attacker would.

AI security

Attack your AI before someone else does. Then contain it.

We test the AI you have deployed the way an adversary would, deploy new tools with the controls in place, and limit what your agents can reach.

What a boutique practice can actually show you.

In pilot

A Digital CISO Agent that narrates your evidence.

InlineScan reads the security evidence you supply and narrates it against a control catalogue. Every statement in a report says where it came from, so you can check the evidence behind a sentence rather than take the sentence on trust.

A named human reviews and signs any reporting before it reaches a board or a regulator.

How the pilot works
Mathew Sayed, founder of Inline Code

Mathew Sayed

Founder and principal

A certified offensive and defensive security practitioner with a platform engineering background. The person who scopes your engagement is the person who delivers it.

  • Australian-issued professional indemnity cover
  • Fixed-fee statements of work
  • Findings and reports stored encrypted, in Australia
Watch the one-minute explainer

The Inline Code explainer

Read the transcript

Your board answers for cyber risk. Someone has to lead it. Inline Code is your fractional CISO: a named security lead who reports to your board, without the full-time hire.

We run the frameworks you are measured against. Essential Eight, ISO 27001, APRA CPS 234. Mapped, fixed in priority order, and kept current.

And we secure the AI you are putting to work. We attack it the way an adversary would, then limit what your agents can reach. A poisoned email can talk an AI agent into almost anything. It cannot give it access that it was never granted.

Fixed fees. One accountable practitioner. Australian regulators built in, not bolted on.

Inline Code. Book a discovery call at inlinecode dot com dot au.

From first call to a signed plan in five steps.

  1. Discovery call

    Thirty minutes. Confirm fit, scope, and timing. No obligation.

  2. Statement of work

    Fixed-fee SOW issued within two business days of the discovery call.

  3. Engagement kickoff

    Within two weeks of signature. Stakeholder alignment, evidence collection.

  4. Delivery

    Ten business days for the assessment. Ongoing for the fractional role.

  5. Decision

    Findings briefing. Continuation into retainer or enablement work as required.

Free tool

AI governance maturity self-assessment

Twelve questions across the four NIST AI RMF functions. About ten minutes. You get a maturity scorecard on screen and a PDF report to download.

Start the assessment

Buyer questions we hear most.

Direct answers to what risk, security, and board buyers ask in the first thirty minutes.

Have a different question? Send it through and we will reply within one business day.

What does a fractional CISO do each month?

A monthly operations report, and a quarterly board update covering remediation status, the regulatory horizon and incidents. A quarterly posture re-assessment that closes the loop on prior remediation. Policies and standards kept current as your tooling changes, every proposed AI tool assessed before procurement signs, and your audit logs reviewed against agreed control objectives. AI incident response support when you need it, and a direct line to the practitioner, with a same-day response on material decisions. The engagement runs for twelve months with quarterly review points.

How is the assessment different from what a Big 4 firm would deliver?

Three differences. Fixed price scoped at engagement, not a six-figure project that grows. Ten business days end to end, not three months. The same senior practitioner who scopes the work delivers it, no graduate teams. The deliverable is operationally useful, not a slide deck designed for procurement.

We already have a CISO. Why would we need you?

For most mid-market firms, the CISO is fully loaded on traditional information security. AI governance requires distinct framework literacy (NIST AI RMF, ISO 42001, OWASP LLM, MITRE ATLAS) and a different vendor and use case discovery process. The fractional role complements your CISO; it does not replace them.

Do you have professional indemnity insurance?

Yes, the engagement is delivered under an Australian-issued professional indemnity policy. Limit and terms are disclosed on the statement of work. Required for fractional CISO engagements with regulated entities.

How does the assessment to retainer conversion work?

There is no obligation to convert. Approximately forty to fifty percent of assessments lead to a retainer because the findings surface enough material work to justify it. If the assessment shows your posture is already strong, we say so and exit cleanly.

Can you work with our legal counsel on contract review?

Yes. We are not lawyers and do not provide legal advice. Where formal legal review is required (regulator correspondence, contract drafting, statutory interpretation), we flag it and continue producing the technical artefact in parallel. Many engagements run alongside Gilbert + Tobin, MinterEllison, or Mills Oakley.

What happens if we have an AI incident during the engagement?

Retainer clients have direct access to incident response support. We help you triage, contain, communicate, and document. Playbooks for prompt injection, AI data exfiltration, model misuse, vendor outage, and shadow AI discovery are pre-positioned.

Get started

Talk to the security lead who would do the work.

A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.