Founder

Adam van Vliet

The auditor who's built the thing he certifies.
ISO 27001 LA ISMS design SOC build Board governance Cloud security DevSecOps Essential Eight Australian ISM IRAP Data governance

Adam founded InfoSec Collective in January 2026 to connect Certification Bodies with senior practitioners who carry genuine executive accountability — and to deliver ISO 27001 consulting and board governance advisory to organisations that want certification to mean something.

He’s a qualified ISO/IEC 27001 Lead Auditor with over fifteen years shaping cybersecurity strategy, governance, and transformation across regulated sectors. The path ran the long way round: the better part of a decade as a developer and architect building enterprise identity platforms for organisations across sectors from government and health to resources and primary industry, and embedding application security into the way software shipped, then twice over as a Chief Information Security Officer — standing up SOCs, designing ISMSs that achieved certification, and authoring the governance models that turned security from a compliance chore into a board conversation.

Engagements span ISO 27001 audit lead, ISMS design, and board-level governance advisory — certification that is rigorous and strategically grounded, never cosmetic.


Where Adam creates value
Risk reduction the business doesn't feel
Management systems that fold into how the business already runs and drive measurable risk reduction — certification follows as a by-product, not the goal.
Governance the board can use
Drawing on years spent authoring governance models, chairing security committees, and making the case — sometimes uncomfortably — for security leadership to sit independently of the function it reports on. The result is governance clients can understand and communicate to their own boards.
Certification that means something
Bringing Lead Auditor rigour to engagements so the certificate reflects real posture, not cosmetic compliance.
Technical depth behind the advice
Hands-on experience building SOCs, shipping software, and running cloud — so governance recommendations are grounded in how systems actually work, not just how they're written down.