



WHO WE WORK WITH
Law firms. You hold privileged client matters, trust account funds, and a name built over years. We protect all three. We already do this for Australian law firms.
Bespoke consulting firms. Small advisory firms trade on reputation and hold sensitive client material. Big enough to be a target, too small for a security hire. We fit that gap exactly.
Family offices. Private wealth attracts targeted attacks, and discretion is the whole point. We keep what matters out of the wrong hands, quietly.

We focus on the controls that actually protect a small, high-trust firm, not a long list that drains your budget.
Email security, multi-factor login, device protection, and reliable backups. The controls your clients and your insurer now expect, done properly. We also put checks in place to stop payment and trust account fraud, the most expensive attack hitting firms right now.
We get you across the Privacy Act, the basics of the Essential Eight, and the security controls your insurer asks about, so a claim is not refused when you need it most.
Your people are already using AI tools on client work. We set clear rules and train your team so confidential information does not leak into public AI tools.
SAFE USE OF AI
Your staff are already pasting client emails, contracts, and case notes into ChatGPT and similar tools to save time. The moment confidential information goes into a public AI tool, it has, in effect, left your firm. For a business built on confidentiality, that is a serious gap, and almost no one is helping small firms close it.
We fix it without banning the technology: simple rules, safer alternatives, and a short training session for the whole team. Quick to put in place, and it puts you ahead of where the rules are heading.
When you engage Tier 1 you work directly with Michael, a cybersecurity and GRC specialist. No graduate learning on your matters, no hand-off, no call centre.
We embed like internal staff. Michael works as if he were your in-house security lead, the same way he already operates for established consultancies and enterprise teams, scaled to a small firm and available only when you need it.
We treat your information the way you treat your clients'. We work quietly and we keep what we see to ourselves.
Proven credentials. Michael holds Lead Auditor credentials covering information security (ISO 27001), privacy (ISO 27701) and AI management (ISO 42001), alongside CISSP, CISM and CISA. He has led ISO 27001 certifications for Australian companies, including two documented programs completed with zero non-conformities, and served as incident response lead for a major Australian retailer during a serious data exposure event. The advice rests on proven practice, not theory.
CONTACT