AI security for Australian enterprise and regulated entities
We test AI systems, secure them, and stay accountable for the risk.
Most AI security advice stops at the policy. We work where these systems actually fail: the prompts, the tools, the agent permissions, and the data the model can reach. We find it, help you fix it, and can hold the accountable officer seat while you do.
Or grab the free AI Governance Readiness Checklist →
We deliver against
What changed in 2026
Two regulatory events moved AI from policy to proof.
Boards used to ask whether there was an AI policy. They now ask who has tested the AI and who is watching it.
Letter to industry on artificial intelligence
AI is not a separate regime. AI-enabled services must be managed under CPS 230 and CPS 234, and APRA expects continuous monitoring rather than a point-in-time audit.
Read the source ›Careful adoption of agentic AI services
Least privilege, a distinct identity per agent, continuous logging, red teaming through the lifecycle, and human approval for irreversible actions.
Read the source ›The practice
Two divisions. One accountable practitioner.
Most firms do one or the other. The technical shops test and hand you a PDF. The advisory shops write the policy and never touch the system. We do both, which is why the report and the remediation agree with each other.
Division one
AI Security
We test what you have deployed, then secure it.
Adversarial testing of the AI you have in production, secure deployment of the AI you are about to ship, and containment for agents with access to real systems.
- AI Offensive Security Review Test what you deployed
- Secure AI Enablement Deploy it with controls
- AI Defence and Agent Containment Contain what agents reach
- Digital CISO Agent In development
Division two
Risk and Governance
Then we stay accountable for it.
The named accountable officer seat, the posture assessments a board and a regulator will accept, and conventional offensive security across your wider estate.
- Fractional AI and Information Risk Officer From AUD 8,000 per month
- AI Governance Posture Assessment AUD 15,000 to 25,000
- Security Posture Assessment AUD 18,000 to 30,000
- Penetration Testing AUD 12,000 to 90,000
Why us
What a boutique practice can actually show you.
Offensive and defensive certified
A practitioner who can break a system and then design the control that stops it. Current certifications supplied for vendor onboarding on request.
Eight frameworks, natively
NIST AI RMF, ISO/IEC 42001, APRA CPS 234 and CPS 230, the Privacy Act, OWASP for LLMs, MITRE ATLAS and ASD Essential Eight.
The accountable officer seat
We hold the named risk officer role for clients in financial services, healthcare, professional services, technology and hospitality.
Platform engineering background
We configure the admin console as well as write the board paper. Advice that survives contact with your infrastructure.
The shift
The question your board is now asking.
Boards at Australian SMEs and regulated mid-market organisations are asking three questions that did not exist eighteen months ago.
- 01 Which AI tools are our staff using, and have we approved them?
- 02 If a regulator reviewed our AI controls tomorrow, would we pass?
- 03 If an AI incident occurred this week, who would respond, and how?
AI tooling has been adopted faster than the governance to manage it. Microsoft 365 Copilot, ChatGPT Enterprise, Claude, and GitHub Copilot are now sitting alongside personal accounts on staff devices. The frameworks built for traditional information risk were not written for generative systems.
Delivery speed
0 days
From kickoff to board-ready posture report
Frameworks
0
NIST · ISO · APRA · OWASP · MITRE · ASD · APP · EU AI Act
Pricing
Fixed fee
No open-ended scoping. No surprise invoices.
Why Inline Code
Operators, not framework dumpers.
Most AI governance work today is policy theatre. Long documents, no operational change. We do the opposite. Our practice is led by certified offensive and defensive security practitioners who have stood up and operated controls.
Australian regulator literacy
APRA prudential standards, the Privacy Act, and ASD guidance as native context, not appended sections.
Productised, fixed-fee delivery
You know cost and timeline before you sign. We do not run open-ended discovery engagements.
Vendor neutral
No reseller arrangements, no product commissions. Tool recommendations are tied to control objectives.
Right-sized for mid-market
Controls a forty-person risk team can actually operate, not controls written for tier-one banks.
Continuity beyond engagement
Findings convert into a retainer that operates the controls we recommend, so reports do not sit on shelves.
Named accountability
A practitioner, not a logo. The person who scoped your engagement is the person who delivers it.
Process
From first call to signed governance posture in five steps.
Discovery call
Thirty minutes. Confirm fit, scope, and timing. No obligation.
Statement of work
Fixed-fee SOW issued within two business days of the discovery call.
Engagement kickoff
Within two weeks of signature. Stakeholder alignment, evidence collection.
Delivery
Ten business days for the assessment. Ongoing for the fractional role.
Decision
Findings briefing. Continuation into retainer or enablement work as required.
Free tool
AI Governance Maturity Self-Assessment
Twelve questions across the four NIST AI RMF functions. Takes four minutes. You receive an automated maturity scorecard and a personalised PDF report by email. No sales call required.
Start the assessmentCommon questions
Buyer questions we hear most.
Direct answers to what risk, security, and board buyers ask in the first thirty minutes.
How is the assessment different from what a Big 4 firm would deliver?
We already have a CISO. Why would we need a fractional AI risk officer?
Do you have professional indemnity insurance?
How does the assessment to retainer conversion work?
Can you work with our legal counsel on contract review?
What happens if we have an AI incident during the engagement?
Have a different question? Send it through and we will reply within one business day.
Get started
Bring AI risk under board oversight in two weeks.
A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.