Operational resilience · Information security · AI governance
Tier-one resilience, security and AI governance. One principal, fixed scope, written deliverables.
For boards and executives at APRA-regulated entities, market infrastructure, energy and government who have to evidence operational resilience, information security and responsible AI at the same time. You get the person who has built these inside tier-one institutions, not a team you never meet.
The challenge
Resilient, secure and responsible with AI, all at once.
Boards are being asked to demonstrate operational resilience, sound information security and responsible AI at the same time, under CPS 230, DORA, the EU AI Act, ISO 22301, ISO 27001 and ISO 42001. Generalist consultants know the frameworks. Few have run resilience, risk and security inside a tier-one financial institution. That gap is where the real exposure sits, and it is where we work.
What we do
Advisory, assurance and training, on the things that matter.
Fixed-scope engagements benchmarked against the intent of each framework, never sold as a compliance guarantee. Certification is issued by accredited certification bodies, not by us.
Operational and business resilience
Critical operations, impact tolerances, dependency mapping, scenario testing and service-provider arrangements, benchmarked against the intent of APRA CPS 230, ISO 22301, ISO 22361 and DORA.
CPS 230 · CPG 230 · ISO 22301 · ISO 22361 · DORA · SOCI Act 2018
Information security advisory and audit
Designing and maturing an ISMS aligned with the intent of ISO 27001 and the NIST CSF, plus independent ISMS and control audits with evidenced findings and a remediation path.
ISO 27001 · NIST CSF · Essential Eight · ISMS audit
AI governance, assurance and training
Governance that lets an organisation adopt AI deliberately: inventory, risk classification, controls and oversight benchmarked against the intent of the EU AI Act, ISO 42001 and the NIST AI RMF, with training for boards, executives and staff.
EU AI Act · ISO 42001 · NIST AI RMF · Board and staff training
The principal
One name on every opinion.
Ali Hussain has spent over 27 years in information technology, including 25 years in senior roles within global investment banks, across resilience, information security, audit, crisis management and Treasury and Global Markets technology.
From March to August 2026 he was Governance and Frameworks Manager, Business Resilience at the Australian Securities Exchange, where he authored its first Tier 1 Operational Resilience Framework. He is currently a Non-Executive Director on the Finance, Audit and Risk Committee of ADEC.
Free to use
Two readiness tools and three live boards.
CPS 230 readiness check
Twelve questions across critical operations, impact tolerances, scenario testing, service-provider management, incident notification and governance. You get an indicative readiness view by domain, with nothing stored and nothing sent anywhere.
EU AI Act risk-tier classifier
Answer a short branching set of questions about one AI use case and see the risk tier it indicatively falls into, and what obligations tend to follow at that tier.
Live monitors
Regulatory announcements for your region, vulnerabilities carrying NIST's own published severity rating, and what the major AI labs shipped. Every row comes from the publisher's own feed, with markup stripped and long descriptions truncated so it displays safely. Nothing here is written, summarised, rated or interpreted by us or by any AI.
Book a 30-minute conversation on resilience, security or AI governance. We will follow up with a short written read on the one or two things worth doing first. No obligation, and no charge for that first read.
Start the conversation