One principal signs every opinion. Tier-one experience, boutique speed.

Operational resilience · Information security · AI governance

Tier-one resilience, security and AI governance. One principal, fixed scope, written deliverables.

For boards and executives at APRA-regulated entities, market infrastructure, energy and government who have to evidence operational resilience, information security and responsible AI at the same time. You get the person who has built these inside tier-one institutions, not a team you never meet.

The challenge

Resilient, secure and responsible with AI, all at once.

Boards are being asked to demonstrate operational resilience, sound information security and responsible AI at the same time, under CPS 230, DORA, the EU AI Act, ISO 22301, ISO 27001 and ISO 42001. Generalist consultants know the frameworks. Few have run resilience, risk and security inside a tier-one financial institution. That gap is where the real exposure sits, and it is where we work.

What we do

Advisory, assurance and training, on the things that matter.

All capabilities

Fixed-scope engagements benchmarked against the intent of each framework, never sold as a compliance guarantee. Certification is issued by accredited certification bodies, not by us.

Operational and business resilience

Critical operations, impact tolerances, dependency mapping, scenario testing and service-provider arrangements, benchmarked against the intent of APRA CPS 230, ISO 22301, ISO 22361 and DORA.

CPS 230 · CPG 230 · ISO 22301 · ISO 22361 · DORA · SOCI Act 2018

Information security advisory and audit

Designing and maturing an ISMS aligned with the intent of ISO 27001 and the NIST CSF, plus independent ISMS and control audits with evidenced findings and a remediation path.

ISO 27001 · NIST CSF · Essential Eight · ISMS audit

AI governance, assurance and training

Governance that lets an organisation adopt AI deliberately: inventory, risk classification, controls and oversight benchmarked against the intent of the EU AI Act, ISO 42001 and the NIST AI RMF, with training for boards, executives and staff.

EU AI Act · ISO 42001 · NIST AI RMF · Board and staff training

The principal

One name on every opinion.

Ali Hussain has spent over 27 years in information technology, including 25 years in senior roles within global investment banks, across resilience, information security, audit, crisis management and Treasury and Global Markets technology.

From March to August 2026 he was Governance and Frameworks Manager, Business Resilience at the Australian Securities Exchange, where he authored its first Tier 1 Operational Resilience Framework. He is currently a Non-Executive Director on the Finance, Audit and Risk Committee of ADEC.

Read the full background

BasedMelbourne, Australia
MarketsAustralia and New Zealand, United Kingdom and EU, Singapore and Hong Kong, Middle East and GCC
CredentialsCISM, Certified AI Risk Manager, ISO 22301, ISO 27001 Lead Implementer (course), CEH, CHFI, and a legacy APRA CPS 232 certification (CPS 232 was revoked on 1 July 2025)
ModelOne principal, fixed scope, written deliverables

Free to use

Two readiness tools and three live boards.

CPS 230 readiness check

Twelve questions across critical operations, impact tolerances, scenario testing, service-provider management, incident notification and governance. You get an indicative readiness view by domain, with nothing stored and nothing sent anywhere.

Start the check

EU AI Act risk-tier classifier

Answer a short branching set of questions about one AI use case and see the risk tier it indicatively falls into, and what obligations tend to follow at that tier.

Classify a use case

Live monitors

Regulatory announcements for your region, vulnerabilities carrying NIST's own published severity rating, and what the major AI labs shipped. Every row comes from the publisher's own feed, with markup stripped and long descriptions truncated so it displays safely. Nothing here is written, summarised, rated or interpreted by us or by any AI.

Open the boards

Book a 30-minute conversation on resilience, security or AI governance. We will follow up with a short written read on the one or two things worth doing first. No obligation, and no charge for that first read.

Start the conversation