Practice
Services
Two divisions under a single accountable practitioner. AI Security tests, secures and contains the AI systems you have deployed. Risk and Governance carries the accountability and turns technical findings into a position your board and your regulator can act on. Most clients enter through one and add the other.
Division one
AI Security
Testing, securing and containing the AI systems you have already deployed. This is where the practice leads.
AI Offensive Security Review
AUD 18,000 to 75,000 by scope
We attack your AI system the way an adversary would, then tell you what broke and how to fix it.
For Security and technology leaders with AI already in production and a board asking who tested it.
- Direct and indirect prompt injection through the channels your system reads
- Tool and function-call abuse, and agent privilege escalation
- RAG and memory poisoning, model and supply chain tampering
- Exfiltration through model output, and identity abuse for non-human actors
- Findings mapped to OWASP Top 10 for LLMs, MITRE ATLAS and CVSS v3.1
- CPS 234 reporting mapping for APRA-regulated clients
Secure AI Enablement
From AUD 8,000 per tool
We design and deploy AI tools, agents and integrations with the security controls already in place.
For Organisations about to deploy, or running on vendor defaults and wanting it done properly.
- Identity and scoped credentials for agents, never a borrowed human account
- Data boundaries enforced at retrieval, not at presentation
- Tool permissions, logging and audit export into your existing SIEM
- DLP and sensitivity labelling wired into AI inputs and outputs
- Microsoft 365 Copilot, ChatGPT, Claude, GitHub Copilot and Gemini rollout
- Custom agent build with an evaluation harness and documented handover
AI Defence and Agent Containment
Scoped per engagement
The environment an agent runs inside, so that a manipulated agent is a contained event rather than an incident.
For CTOs about to give an agent access to production systems.
- Guardrails, input and output filtering, with the residual rate stated honestly
- Monitoring and detection for AI workloads, into tooling you already run
- Isolated execution, default-deny egress and scoped per-agent credentials
- Tamper-evident action logs and tested kill switches
- Human approval for irreversible actions
- Mapped to ASD Essential Eight and NIST CSF 2.0
Digital CISO Agent
In development
A continuously running security agent that tracks platform health, control drift and board reporting.
For Existing fractional officer clients, and design partners who want to shape it.
- Continuous platform health checks against your configuration baselines
- Live attack and misconfiguration surfacing from tooling you already have
- Control drift detection between assessments
- Monthly governance reporting drafted from evidence
- A named human remains accountable. The agent reports, it does not remediate
Division two
Risk and Governance
The accountable officer seat, the posture assessments, and conventional offensive security. The work that turns technical findings into a defensible position.
Fractional AI and Information Risk Officer
From AUD 8,000 per month
Named individual carrying accountability for AI and information risk to the board.
For Organisations that need accountable risk leadership without a full-time hire.
- Quarterly posture re-assessment and gap closure tracking
- Maintenance of acceptable use, data classification, and vendor risk policies
- Monitoring and audit log review against agreed control objectives
- Vendor risk reviews for new AI tooling under consideration
- AI incident response support, including playbook activation
- Monthly governance operations report and quarterly board update
AI Governance Posture Assessment
AUD 15,000 to 25,000 fixed fee
Two-week, fixed-price posture report against the NIST AI Risk Management Framework.
For Boards and risk committees that need to know where their AI exposure actually is.
- Discovery of AI tooling in use, including shadow AI on personal devices
- Review of policies, contracts, and admin configurations for managed tools
- Control gap analysis against NIST AI RMF and APRA prudential standards
- Threat modelling using OWASP Top 10 for LLMs and MITRE ATLAS
- Board-ready findings report with prioritised remediation roadmap
- Pairs with an AI Offensive Security Review for the technical evidence
Security Posture Assessment
AUD 18,000 to 30,000 fixed fee
Two-week, fixed-price information security assessment against ISO 27001, NIST CSF 2.0 and Essential Eight.
For Organisations that need a defensible baseline before an audit or a client review.
- External attack surface, cloud and SaaS, identity, and EDR coverage review
- Document and configuration review against the relevant control framework
- Stakeholder interviews built around evidence, not policy claims
- Threat modelling against MITRE ATT&CK for the realistic adversary
- ASD Essential Eight maturity scoring with evidence
- Posture report, prioritised roadmap, and optional board briefing
Penetration Testing
AUD 12,000 to 90,000 by engagement type
Manual penetration testing delivered by a certified offensive practitioner, with no automated scans rebranded as pen tests.
For Anyone needing adversary-grade testing of conventional applications, cloud or networks.
- Web application, API, cloud configuration, network, and red team scopes
- Methodology aligned to OWASP, PTES, NIST SP 800-115, and MITRE ATT&CK
- CVSS-rated findings with reproduction steps and evidence
- Continuous reporting on critical issues during the engagement
- Free retest of all findings within 60 days of report delivery
- The AI Offensive Security Review is the AI extension of this practice
Get started
Not sure which one you need?
A thirty-minute discovery call costs nothing. We confirm fit, scope and timing, then issue a fixed-fee statement of work within two business days.