Home › About

About

Who you’ll be working with

A small Canberra-based team. Assessments are led by one person from first call to final report, with specialist advisers brought in when an engagement needs sector knowledge that a compliance background alone does not cover.

Background

My background is in IT operations and security compliance: running service management under ITIL, working in ServiceNow, and network security. That work comes down to one thing: knowing exactly what’s in place, what isn’t, and being able to prove it. I now do the same for small and mid-size businesses facing those questions from regulators, insurers and clients.

Most small businesses are not failing compliance on purpose. They are running a website, a booking system, a mailing list and a handful of cloud tools, each set up at a different time by a different person, and nobody has ever looked at the whole thing against what the standards actually require. That is the job.

You get one point of contact for the whole engagement, and where the work touches an industry with its own rules and its own way of doing things, I bring in an adviser who has actually worked in it. You are never handed to an account manager, and nothing is sent offshore.

We are not a law firm and we do not sell software. We assess, document, and hand you the evidence.

I assess your systems and documents against published standards, identify where the gaps are, and give you the documentation to show you have addressed them. This is not legal advice.

The wider team

Specialist advisers, brought in when the sector calls for it

Compliance work goes wrong when the person doing it has never worked a day in your industry. These are the people I call on so that does not happen.

Healthcare & clinical practice

A registered midwife with extensive clinical experience, who advises on engagements involving health practices and patient information.

Health data is the most sensitive category the Privacy Act recognises, and health practices run on systems an outsider rarely understands: patient records, referrals, third-party booking platforms, results delivery, consent at the point of care. Knowing how a clinic actually runs is the difference between findings a practice can act on and a generic checklist it quietly ignores.

Engineering & the built environment

A qualified structural engineer, who advises on engagements with engineering, construction and trades businesses.

Engineering and construction firms carry a particular mix of risk: tender and panel requirements, client and subcontractor data, drawings and documents moving between parties, and insurers asking harder questions every year. Someone who has sat on that side of the table knows which requests are routine and which ones actually cost you work.

Advisers contribute sector context on the engagements where it is relevant. They are not engaged on every assessment, and they are bound by the same confidentiality terms.

How I work

Four things you can rely on

Fixed price, quoted first

You know the number before work starts. If the scope changes, we agree the change in writing before I continue.

Published standards only

Every finding is tied to something you can look up: the Privacy Act, WCAG 2.2, the Essential Eight. No invented benchmarks.

What’s working, first

Every report opens by naming what you already have right. Most businesses have more right than wrong.

Evidence you can hand over

The deliverable is documentation, not a conversation. Something you can give a regulator, an insurer or a client.

Free resources

Plain-English guides

No sign-up, no email wall. Download it and go.

Guide · PDF

The 10 December 2026 Privacy Act changes: what applies to you

A short summary of what’s changing, which businesses it applies to, and how to check where you stand.

Find out where you stand

Send me your website address and I’ll run a short external check, then tell you what I find. No cost, no obligation.