Risk Professionals

Risk Professionals Provide consulting and training in Risk Management including ISO trainings.

The honest answer to "what would we actually get from a CISO" is rarely satisfying when it comes back as a list of respo...
18/06/2026

The honest answer to "what would we actually get from a CISO" is rarely satisfying when it comes back as a list of responsibilities. The role makes more sense when it gets framed as a workplan with phases, dates, and outputs.

A defensible 90-day playbook looks roughly like this.

Days 1 to 30 are discovery and assessment. The CISO maps stakeholders across the business, runs a current-state assessment against a chosen framework (ISO 27001, NIST CSF, cybersecurity governance frameworks, the Essential Eight, or whatever fits the regulatory context), inventories assets and classifies them, reviews existing policies and incident history, and audits the tools, vendor, and cyber insurance footprint. The output is a clear picture of where the program actually sits today.

Days 31 to 60 are strategy and roadmap. A formal gap analysis against the chosen framework. A risk register with named owners against each top risk, not generic departments. A multi-year cybersecurity roadmap with budget attached. Three to five quick wins scoped for immediate ex*****on. The first incident response tabletop run, even at a small scale. The output is a board-ready plan and the credibility that comes with it.

Days 61 to 90 are ex*****on setup. Priority policies updated or created, starting with the ones that will be tested first in audit or by an incident. The awareness training program designed and ready to roll out. A vendor security assessment program documented. A security metrics and reporting framework that defines what gets reported monthly and quarterly. And the first board report delivered against the framework, not against activity. The output is a function that runs, rather than a person who runs around.

That's the work. It's the same work whether the practitioner is full-time, fractional, or on retainer. The only variables are when it starts and what it costs.

Our vCISO (Virtual Chief Information Security Officer) service is built to deliver that 90-day playbook on retainer instead of salary, with a senior practitioner from day one and a practice behind them.

Read the full service description: riskprofs.com/virtual-chief-information-security-officer/

The hard part of hiring a full-time CISO in Sydney isn't the base salary number that gets quoted in conversation. It's e...
17/06/2026

The hard part of hiring a full-time CISO in Sydney isn't the base salary number that gets quoted in conversation. It's everything attached to it.

Working through the actual Year 1 cost picture for a mid-to-senior CISO hire. Base salary sits in the $250 to $350 thousand range based on current Glassdoor and Robert Half data. Add 12 percent mandatory superannuation. Add the 15 to 20 percent bonus and short-term incentive structure that comes with executive roles. Add the 25 to 30 percent executive recruiter fee that gets charged once on the first-year salary. That brings the Year 1 total to somewhere between $380 thousand and $567 thousand, before any equity, sign-on bonus, or onboarding budget.

That's before the time costs. Four to six months to hire the role. Three to six more before the new CISO is fully productive. Up to a year before the function delivers anything material.

And it's before the structural costs. Single point of failure from day one. Knowledge that concentrates with one person. Departure, burnout, or extended leave becomes an outage in the function.

Mid-market organisations don't usually have a CISO problem. They have a CISO economics problem. The function is genuinely needed. The full-time price tag rarely matches the work that actually needs doing.

That's the gap our vCISO service is built for. Engagement starts in weeks. No recruiter fees. Billed by retainer instead of salary. A practice behind one practitioner, with continuous coverage across leave, departures, and escalations.

Find out more: riskprofs.com/virtual-chief-information-security-officer/

Most growing organisations hit a moment where the security function clearly needs an owner. Customers are asking for ISO...
16/06/2026

Most growing organisations hit a moment where the security function clearly needs an owner. Customers are asking for ISO 27001 evidence. The board is asking about cyber risk by name. AI is in production with nobody owning the governance. Insurance underwriters are asking detailed control questions. The work is real, and the work has outgrown what any one person can carry on goodwill.

The full-time CISO option has its own friction though. In Sydney, the total package for a competent CISO sits around AUD 250 to 400 thousand base, plus super, equity, and 25 to 30 percent recruiter fees on first-year salary. Four to six months to hire. Single point of failure once they start. For most mid-market organisations, the function is real but the full-time hire isn't realistic yet.

That's the gap our new Virtual CISO (vCISO) service is built for.

Risk Professionals' vCISO service gives growing organisations executive-level cyber security leadership on retainer. Strategic direction and hands-on delivery, billed monthly instead of as a salary. Three pillars of focus: security strategy and roadmap, ISO 27001 implementation, and risk management. Eight ongoing deliverables: information security policy suite development, security architecture review, incident response planning and tabletop exercises, vendor security assessment program, security awareness training, compliance monitoring and reporting, security metrics and board reporting, and pe*******on testing coordination.

Built for SMEs needing CISO-level expertise without the full-time hire, organisations on the path to ISO 27001 certification, rapidly growing companies that need security maturity to keep up, and businesses handling sensitive data with compliance oversight obligations.
Read the full service description: riskprofs.com/virtual-chief-information-security-officer/

The honest answer to "do we need a CISO yet" rarely lands well in board conversations. It depends on what's actually hap...
15/06/2026

The honest answer to "do we need a CISO yet" rarely lands well in board conversations. It depends on what's actually happening in the business right now, and most leadership teams are looking for clearer criteria than "trust me, we're getting close."

Six conditions worth checking against your own organisation.

A customer is asking for an ISO 27001 certificate as a condition of the contract. A breach or near-miss in the last 12 months has someone in leadership asking questions that resourcing can't answer. The board has moved from asking what training was delivered to asking about actual cyber risk exposure. AI is running in production and nobody owns the AI security or governance risk. M&A activity is putting cybersecurity maturity onto the deal terms. Cyber insurance underwriters are asking detailed security control questions and vague answers are pushing premiums up.

Count how many apply. One or two and current discipline probably gets you through. Three or more and the security function has outgrown the ad-hoc model. The work needs an owner, structure, and a reporting cadence the board can rely on.

The conditions don't ask permission. They show up on their own timeline, often during a quarter when nobody has the bandwidth to respond properly.

There's a particular shape that security programs in mid-market organisations take when nobody's properly running them. ...
14/06/2026

There's a particular shape that security programs in mid-market organisations take when nobody's properly running them. One person knows where everything is. They handle the customer questionnaires when sales escalates them. They show up to the audit when renewal comes around. They've written the policies, which is also why nobody else has read them.

The arrangement works until the person it depends on isn't there.
Three patterns we see often enough to write down.

The same individual handles questionnaires, incident response, audit liaison, vendor reviews, and board updates. Documented role assignments and named backups separate a program from a person.

Information security policies haven't been formally reviewed for 12 to 18 months. ISO 27001, SOC 2, and the Essential Eight all expect periodic review. A policy register that hasn't been touched reads as an audit finding to an external auditor and as a management gap to anyone paying attention internally.

Board reports describe activity rather than progress against a framework. "We patched X" and "we ran training Y" tell the board what happened. Reporting against a maturity model tells them whether the security posture is improving.
Each of these patterns is survivable alone. Found together, they describe a function held by goodwill rather than structure.

ISO/IEC 27701 sits on top of ISO/IEC 27001 as the privacy information management extension. If your ISMS is solid, the P...
10/06/2026

ISO/IEC 27701 sits on top of ISO/IEC 27001 as the privacy information management extension. If your ISMS is solid, the PIMS becomes the natural next step for stronger privacy governance, privacy compliance, and data protection management.

PECB runs two tracks. Lead Implementer for professionals building and integrating the PIMS into an existing management system. Lead Auditor for professionals verifying that the PIMS operates effectively and meets certification requirements.

Both tracks align with major global privacy regulations and frameworks including GDPR, the Australian Privacy Act, APPs, POPIA, and LGPD. Ideal for organisations operating across multiple jurisdictions that need one privacy framework capable of supporting international compliance requirements.

US$599 per track. Self-paced delivery. Certification exam included with two attempts. PECB registration handled by us.

Available through Risk Professionals as a PECB Authorised Platinum Partner.

ISO/IEC 42001 is becoming the global standard for AI governance, AI compliance, and responsible AI management. Organizat...
09/06/2026

ISO/IEC 42001 is becoming the global standard for AI governance, AI compliance, and responsible AI management. Organizations building, deploying, or overseeing AI systems are rapidly moving toward ISO 42001 certification to strengthen trust, accountability, and risk management.

PECB offers two professional certification tracks designed for different AI governance roles.

Lead Implementer for professionals responsible for designing, implementing, and managing an AI Management System (AIMS)

Lead Auditor for professionals responsible for auditing and evaluating AI governance frameworks and compliance controls

US$599 per credential

Self paced training

Certification exam included with two attempts

Registration support provided by Risk Professionals, a PECB Authorized Platinum Partner

Advance your expertise in AI governance, AI risk management, and ISO 42001 compliance with globally recognized PECB certification.

ISO 27001 and ISO 42001 are easier to learn together than apart.They sit on the same management system spine. Both follo...
08/06/2026

ISO 27001 and ISO 42001 are easier to learn together than apart.

They sit on the same management system spine. Both follow Annex SL, so context, leadership, planning, support, operation, performance evaluation, and improvement work the same way in each. Both use risk-based thinking. Both produce a Statement of Applicability. Both run on an internal audit programme. Both certify on the same cycle.

The unique territory is genuinely unique. ISO 27001 brings 93 Annex A controls, information security risk management, and two decades of audit precedent. ISO 42001 brings AI impact assessments, model lifecycle controls, AI governance frameworks, AI-specific data governance, and alignment with evolving regulations such as the EU AI Act.

But the shared spine is most of the work. Learn ISO 27001 first and the second credential takes a fraction of the effort. The principles, the structure, the documentation patterns, the audit logic, and compliance methodology are already in your hands.

Two PECB Lead Implementer credentials at US$599 each. Online and self-paced. Exam included with two attempts and a free retake within 12 months.

Available through Risk Professionals as a PECB Authorised Platinum Partner.

Most organisations implementing ISO 42001 already have an ISO 27001 ISMS in place, or they're planning one. Running them...
04/06/2026

Most organisations implementing ISO 42001 already have an ISO 27001 ISMS in place, or they're planning one. Running them as parallel programs is the default move. It's also the slowest, most expensive way to do it.

ISO 42001 was designed to integrate. Both standards sit on the Annex SL spine, which means the management system structure is identical: context, leadership, planning, support, operation, performance evaluation, improvement. The information security controls in ISO 27001 underwrite a good chunk of what ISO 42001 needs anyway. Building two separate programs duplicates policies, audit cycles, training, and the documentation effort that comes with all of it.

The integrated approach is faster to build, cleaner to audit, and easier to maintain. One IMS Manual instead of two. One set of policies covering both AI and information security. One management review cycle. Two Statements of Applicability, but documented in one place.

Our new IMS (ISO 42001 + ISO 27001) Document Kit gives you the integrated foundation. 120+ editable documents including the IMS Manual, an alignment guide, 24 integrated policies, 23 procedures, both Statements of Applicability, three years of implementation training decks, and a combined library of 50 incident playbooks (26 AI scenarios and 24 cyber scenarios). One-time AUD $999, instant download.

Available through Risk Professionals: riskprofs.com/templates

Most organisations implementing ISO 42001 stall on the same question: who, specifically, is accountable for what?The sta...
03/06/2026

Most organisations implementing ISO 42001 stall on the same question: who, specifically, is accountable for what?

The standard doesn't hand you four ready-made job titles. What it does require is that the roles and responsibilities for managing AI are defined, allocated, and documented under Annex A.3.2, with final accountability sitting at the top with management under Clause 5.3.

That translates, in practice, to four roles you need to define for your organisation:
An AI system owner, accountable end-to-end for one specific AI system, with the authority to halt it. An AIMS coordinator, who maintains the management system, owns the register of AI systems, and escalates non-conformities. An AI reviewer, who provides independent oversight of individual AI system decisions against defined acceptance criteria. And top management, who set policy, accept residual AI risk, and sign the management review.

The audit-failing pattern is consistent. The roles exist on paper. The authority to act on them doesn't. An owner who can't actually halt a system. A coordinator without the authority to enforce anything. A reviewer with no defined trigger events. A board that signs cyber risk minutes but never AI risk minutes.
Evidence the assignments through job descriptions, RACI matrices, or appointment letters. Verbal arrangements fail audits.

Available through Risk Professionals as a PECB Authorised Platinum Partner.

Address

Level 3, 478 George Street
Sydney, NSW
2570

Alerts

Be the first to know and let us send you an email when Risk Professionals posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Risk Professionals:

Share