“Establishing, maintaining and continually improving cybersecurity is essential to support business operations, increase resilience and protect profitability.”
Ian Simpson
About
An experienced and business orientated security professional with 27 years in information technology, including more than 25 years in security-related roles, Ian recognises the need for security controls and frameworks to be implemented in a pragmatic fashion, contextually aligned to an organisation’s strategy, operating model and threat environment.
An excellent problem solver, communicator, presenter and people leader, Ian strives for excellence whilst being cognizant of the fact that the path to great requires a structured and defined pathway of continuous improvement.
As a member of ISACA, Ian holds both the CGEIT (Certified in the Governance of Enterprise IT) and CISM (Certified Information Security Manager) certifications. Additionally, Ian holds a Master of Information Systems Security and is certified as a Lead Auditor in ISO/IEC 27001.
Expertise
- Information security governance and risk management
- Cyber security strategy
- Information security risk, compliance and maturity assessments
- Industry recognised frameworks including ISO 27001, the ASD Information Security Manual, CPS 234 and the NIST Cybersecurity Framework
Education and accreditations
- Masters Degree - Information Systems Security
- Certified in the Governance of Enterprise IT (ISACA CGEIT)
- Certified Information Security Manager (ISACA CISM)
- ISO 27001:2013 Lead Auditor
Memberships
- Information Systems Audit and Control Association (ISACA)
- Australian Information Security Association (AISA)
Significant Engagements
- Cybersecurity Partner responsible for strategy, policy development, vendor assessments and advisory services
- Undertake a privacy impact assessment of a cloud-based Customer Relationship Management system
- Develop a comprehensive information security policy framework aligned to operational capabilities and ISO/IEC 27001:2022
- Conduct a cybersecurity assessment baselined against the NIST Cybersecurity Framework and the Essential 8
- Develop and test cybersecurity incident response plans




