The security lead your board can name.
Inline Code is your fractional CISO. We run the security frameworks your regulators and customers ask for, from Essential Eight to ISO 27001 and APRA CPS 234, and we secure the AI you are putting to work.
Illustration of a weekly board briefing: decisions waiting, Essential Eight progress, an AI register and a refused agent action.
Illustrative data
Built on the frameworks you are measured against
See how we map them- Essential Eight
- ISO/IEC 27001
- APRA CPS 234
- APRA CPS 230
- NIST CSF 2.0
- ISO/IEC 42001
- NIST AI RMF
- Privacy Act
- OWASP Top 10 for LLMs
- MITRE ATLAS
One practice, three ways in.
Most clients start with one and add the others as the work shows what is needed.
Fractional CISO
A named security lead, without the full-time hire.
We hold the accountable seat for your security and AI risk: board reporting, a quarterly posture re-assessment, policy upkeep and vendor risk reviews, with a direct line to the person doing the work.
Twelve-month engagement with quarterly review points.
Security frameworks
Frameworks that run, not binders that sit.
We map where you stand against Essential Eight, ISO 27001, APRA CPS 234 or NIST CSF 2.0, give you a remediation roadmap in priority order, and test the controls the way an attacker would.
AI security
Attack your AI before someone else does. Then contain it.
We test the AI you have deployed the way an adversary would, deploy new tools with the controls in place, and limit what your agents can reach.
What a boutique practice can actually show you.
-
Named accountability
A practitioner, not a logo. The person who scoped your engagement is the person who delivers it.
-
Offensive and defensive certified
A practitioner who can break a system and then design the control that stops it.
-
Australian regulator literacy
APRA prudential standards, the Privacy Act, and ASD guidance as native context, not appended sections.
-
Fixed-fee delivery
You know cost and timeline before you sign. We do not run open-ended discovery engagements.
-
Vendor neutral
No reseller arrangements, no product commissions. Tool recommendations are tied to control objectives.
-
Hands on the console
We configure the admin console as well as write the board paper.
What changed in 2026
Two regulatory events moved AI from policy to proof.
Boards used to ask whether there was an AI policy. They now ask who has tested the AI and who is watching it.
- APRA 30 April 2026
Letter to industry on artificial intelligence
AI is not a separate regime. AI-enabled services must be managed under CPS 230 and CPS 234, and APRA expects continuous monitoring rather than a point-in-time audit. Read the source - CISA and ASD ACSC May 2026
Careful adoption of agentic AI services
Least privilege, a distinct identity per agent, continuous logging, red teaming through the lifecycle, and human approval for irreversible actions. Read the source
In pilot
A Digital CISO Agent that narrates your evidence.
InlineScan reads the security evidence you supply and narrates it against a control catalogue. Every statement in a report says where it came from, so you can check the evidence behind a sentence rather than take the sentence on trust.
A named human reviews and signs any reporting before it reaches a board or a regulator.
How the pilot works
Mathew Sayed
Founder and principal
A certified offensive and defensive security practitioner with a platform engineering background. The person who scopes your engagement is the person who delivers it.
- Australian-issued professional indemnity cover
- Fixed-fee statements of work
- Findings and reports stored encrypted, in Australia
From first call to a signed plan in five steps.
-
Discovery call
Thirty minutes. Confirm fit, scope, and timing. No obligation.
-
Statement of work
Fixed-fee SOW issued within two business days of the discovery call.
-
Engagement kickoff
Within two weeks of signature. Stakeholder alignment, evidence collection.
-
Delivery
Ten business days for the assessment. Ongoing for the fractional role.
-
Decision
Findings briefing. Continuation into retainer or enablement work as required.
Free tool
AI governance maturity self-assessment
Twelve questions across the four NIST AI RMF functions. About ten minutes. You get a maturity scorecard on screen and a PDF report to download.
Start the assessment
Buyer questions we hear most.
Direct answers to what risk, security, and board buyers ask in the first thirty minutes.
Have a different question? Send it through and we will reply within one business day.
What does a fractional CISO do each month?
A monthly operations report, and a quarterly board update covering remediation status, the regulatory horizon and incidents. A quarterly posture re-assessment that closes the loop on prior remediation. Policies and standards kept current as your tooling changes, every proposed AI tool assessed before procurement signs, and your audit logs reviewed against agreed control objectives. AI incident response support when you need it, and a direct line to the practitioner, with a same-day response on material decisions. The engagement runs for twelve months with quarterly review points.
How is the assessment different from what a Big 4 firm would deliver?
Three differences. Fixed price scoped at engagement, not a six-figure project that grows. Ten business days end to end, not three months. The same senior practitioner who scopes the work delivers it, no graduate teams. The deliverable is operationally useful, not a slide deck designed for procurement.
We already have a CISO. Why would we need you?
For most mid-market firms, the CISO is fully loaded on traditional information security. AI governance requires distinct framework literacy (NIST AI RMF, ISO 42001, OWASP LLM, MITRE ATLAS) and a different vendor and use case discovery process. The fractional role complements your CISO; it does not replace them.
Do you have professional indemnity insurance?
Yes, the engagement is delivered under an Australian-issued professional indemnity policy. Limit and terms are disclosed on the statement of work. Required for fractional CISO engagements with regulated entities.
How does the assessment to retainer conversion work?
There is no obligation to convert. Approximately forty to fifty percent of assessments lead to a retainer because the findings surface enough material work to justify it. If the assessment shows your posture is already strong, we say so and exit cleanly.
Can you work with our legal counsel on contract review?
Yes. We are not lawyers and do not provide legal advice. Where formal legal review is required (regulator correspondence, contract drafting, statutory interpretation), we flag it and continue producing the technical artefact in parallel. Many engagements run alongside Gilbert + Tobin, MinterEllison, or Mills Oakley.
What happens if we have an AI incident during the engagement?
Retainer clients have direct access to incident response support. We help you triage, contain, communicate, and document. Playbooks for prompt injection, AI data exfiltration, model misuse, vendor outage, and shadow AI discovery are pre-positioned.
Get started
Talk to the security lead who would do the work.
A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.