For the board

An independent review of your information security posture.

Ex-Corporate · Ex-Compliance · Exceptional

Commissioned by directors. Delivered to the board. Built for the room it will be tabled in.


Why directors commission this
Boards commission independent reviews of financial position, legal exposure, and governance practice. Information security warrants the same treatment.

Personal liability for data breaches is rising. Shareholder action over loss of enterprise value is no longer hypothetical. Privacy class actions against Optus, Medibank, and Latitude Financial Services are now active in the Australian courts.

A 2024 Herbert Smith Freehills survey found 68% of directors and senior counsel reporting increased concern about class action exposure over the past five years, with cyber identified as the top class action risk.

Avg. cost of a cyber incident · large AU business · 2024–25
AUD $202,691
Source: ACSC Annual Cyber Threat Report 2024–25.
Year-on-year change
+219%
The trajectory directors are being asked to govern against.
What we review
Three instruments, one assessment. Scored independently. Presented together.
Strategic
4 dimensions
  • Risk governance
  • Strategic alignment
  • Culture & behaviour
  • Investment & resourcing posture
Board workshop
Operational
7 assets × 8 controls
  • 56 cells, scored 1–5
  • Maturity rubric
  • Lowest-cue rule
  • Asset & control rollups
Document review & interviews
Software development
6 phases
  • Govern
  • Design / Build / Verify
  • Deploy
  • Operate & learn
Vendor / dev engagements only
Sample finding
Each box shows the spread of anonymous director votes; plotted against it, the assessor's independent score. The gap between the two is the finding.
5 Adaptive
4 Proactive
3 Systematic
2 Ad-hoc
1 Nothing
Risk governance
Strategic alignment
Culture & behaviour
Investment & resourcing posture
Middle half of votes Full vote range (min–max) Board median Assessor score
Sample data, illustrative only. The box spans the middle half of director votes; whiskers show the full vote range; the horizontal mark is the board median. The diamond marks the assessor's independent score.
Over time
Recurring assessments turn a snapshot into a trajectory. Risk governance — maturity progression over four annual assessments.
5 Adaptive
4 Proactive
3 Systematic
2 Ad-hoc
1 Nothing
2023
2024
2025
2026
Middle half of votes Full vote range (min–max) Assessor score
The full deliverable goes further — maturity radars by asset and control class, and the complete 7 × 8 operational matrix. The whitepaper documents how each is read.
The maturity model
Built from observation of how real businesses operate and the risks they actually face. Draws on established frameworks where they help, and departs from them where they reflect compliance theatre rather than working security.
L1
Nothing
No defined activity. The control or capability isn't there.
L2
Ad-hoc
Present, but informal and dependent on individuals.
L3
Systematic
Documented, repeatable, and applied consistently.
L4
Proactive
Measured, reviewed, and improving on a cadence.
L5
Adaptive
Anticipates change. Self-correcting. The standard the best operate at.
What directors receive
A deliverable structured for the room it will be tabled in.
01
An assessment, not a briefing.
An honest view of where the organisation stands — derived from independent observation and evidence, not a management summary calibrated to be reassuring.
02
Maturity scored against a defined model.
Five levels (Nothing, Ad-hoc, Systematic, Proactive, Adaptive), applied consistently across all instruments. Documented scoring discipline ensures the result is defensible.
03
Prioritised options for improvement.
Findings translated into options the board can act on — not 47 recommendations, but the handful that materially improve posture.
04
Comparable year-on-year.
Recurring engagements track maturity over time. The board can see whether posture is improving, plateauing, or regressing.
05
Board-pack ready.
The deliverable is structured so it can be tabled at the board meeting after receipt — not decoded, summarised, or rewritten by the security team first.
Engagement structure
Four steps. Defined scope. Predictable timeline.
STEP 01 ~1 week
Scope
Confirm engagement variant and access.
STEP 02 60 min
Workshop
60-minute board workshop with anonymous director voting and behavioural discussion.
STEP 03 2–3 weeks
Evidence
Document review and operational interviews across the agreed instruments.
STEP 04 Board pack
Deliver
Written assessment, visualisations, and prioritised options. Board presentation.

Commission an assessment that arrives board-pack ready.