For Australian law firms and boutique consultancies

Bring GRC, cybersecurity and AI governance into one accountable program.

Start with the client or insurer request, deadline, cyber concern or AI rollout already on your desk. Work directly with Michael on the agreed scope to set one priority order, coordinate existing providers and advisers, put controls into practice and retain evidence your firm can use.

Speak directly with Michael. Thirty minutes, no charge, no preparation. Do not include privileged, sensitive or incident details in the booking form.

Scroll to explore

Selected experience

Trusted by

Selected organisations Michael has worked with across consulting, delivery and security engagements. Today: ISO 27001 programs for Eftsure, Crypto Tax Calculator, Cloud Services Australia, LinkSafe and SupportFusion, incident response lead for Ritchies IGA, and ongoing security for Indigo Lawyers and LegalByte.

  • Microsoft
  • Formula 1 Australian Grand Prix 2024
  • Oracle
  • AFL
  • Nosworthy Group
02Start with what put this on your desk

Start with what put this on your desk

You do not need to choose the service first.

Bring the pressure already in front of you. Tier 1 will identify where it crosses GRC, cybersecurity and AI governance, then define the smallest responsible starting point.

A client or insurer wants evidence

A panel review, security questionnaire or PI renewal is sitting on the desk with a deadline, and the honest answer today is not the one the firm wants to give.

A new obligation has a deadline

A privacy change, contract clause or client security schedule now applies to the firm, and someone has to turn it into named owners, working controls and proof.

A cyber concern exposed uncertainty

A suspicious payment email, a compromised mailbox or a provider change just showed that nobody is certain which controls actually operate.

AI is moving faster than the rules

Staff are already putting real work into AI tools. Nobody has decided what is allowed, what is off limits and who checks the output before it is relied on.

03Three disciplines. Led as one.

Three disciplines. Led as one.

One issue can cross all three disciplines.

A client requirement can change a cyber control. A cyber weakness can undermine an assurance answer. An AI use case can affect both. Tier 1 keeps the requirement, control, owner and evidence connected, so leadership has one view of what matters and what happens next.

Translucent sheets aligned on a dark grid with a single amber marker.
04Why Tier 1

Why Tier 1

Senior accountability, backed by specific evidence.

You work directly with Michael Angelo on the agreed program, backed by more than 14 years in IT consulting and managed security.

One senior relationship

No junior hand-off, rotating account team or call centre. Michael stays accountable for the work.

Assurance credentials

Lead Auditor credentials across ISO 27001 information security, ISO 27701 privacy and ISO 42001 AI management, alongside CISSP, CISM and CISA.

Proven delivery

ISO 27001 certification programs led for Eftsure, Crypto Tax Calculator, Cloud Services Australia, LinkSafe and SupportFusion, including two programs certified with zero non-conformities. Incident response lead adviser to Ritchies IGA through a major data exposure event.

Discretion is the job

Ongoing security support to Australian law firms including Indigo Lawyers and LegalByte. Your information is treated with the care your own clients expect from you.

05How engagements work

How engagements work

Three ways to work with Tier 1. Each one is agreed before it starts.

Most firms begin with a short call, then a bounded first review. Ongoing leadership is only scoped once the review has shown what the firm actually needs, so nobody is asked to commit to a program before they can see the gaps.

1. A confidential first call

Thirty minutes with Michael, no charge and no preparation. Describe what prompted the call. You leave knowing whether Tier 1 fits and what the smallest responsible next step is.

2. A scoped first review

A bounded review of the pathways that matter most: identity, email, devices, payments, obligations and the evidence behind the answers the firm currently gives. Fixed scope and fixed fee agreed in writing, from $7,500 + GST.

3. Ongoing security leadership

Senior ownership of priorities, providers, incidents and evidence on a monthly cadence. Scoped after the first review, so the retainer fits the firm rather than a template.

06Who we work with

Who we work with

Built for lean firms carrying serious trust.

Tier 1 is built for Australian law firms and boutique consultancies that handle confidential work, face serious assurance demands and need senior ownership without three separate internal functions. Selected family offices are supported through trusted referrals.

Closed charcoal folios on a boardroom table at night, lit by a single warm lamp.
07One connected program

One connected program

From requirement to working control to usable evidence.

Start with the most material issue in any pillar. Tier 1 maps where it overlaps with the others, sets one priority order and keeps owners, providers and evidence moving together.

Map

Identify the obligations, information, systems, AI uses, providers and decisions that shape the exposure.

Decide

Separate urgent gaps from longer-term improvement and name the decisions leadership must own.

Implement

Coordinate staff, technology providers and specialist advisers around the controls and outcomes agreed.

Test and prove

Confirm that controls operate in practice and retain evidence for clients, insurers, audits and future decisions.

08Questions

Straight answers

Common questions

Can one engagement cover GRC, cybersecurity and AI governance?

Yes. They can be scoped as one risk and control program. Tier 1 can map the obligations, set priorities, coordinate cyber and AI controls, test what is operating and maintain the evidence, while legal and other regulated advisers remain responsible for advice in their fields.

We are only a few people. Are we really a target?

Yes. Small firms can still hold valuable information and move significant payments. Good basic security reduces the opportunity for an attacker without forcing a small team into an enterprise-sized program.

Do we need an expensive certification?

Usually not to start. Most firms gain more by getting the fundamentals right first. We help you decide whether a formal standard is worthwhile based on your risks, client expectations, contracts and insurer requirements.

We already have an IT provider. Why do we need you?

General IT keeps systems running. Security governance sets priorities, tests whether controls are effective and gives leadership a clear view of risk. We work alongside your existing provider and make the boundaries visible.

How much of our time will this take?

As little as practical. We do the heavy lifting and ask for input where leadership context or a business decision is required. The aim is to take security work off your plate, not create another reporting burden.

Where should we start?

Start with a short review of the information, payments, systems and obligations that matter most. You will receive a prioritised view of the urgent gaps, the sensible next steps and which work can wait.

What does a first engagement cost?

The first call is free. A scoped first review starts from $7,500 + GST, with the exact scope and fee agreed in writing before any work begins. Ongoing leadership is only priced after the review, once the firm's actual needs are clear.

How long does a first review take?

The review is bounded to an agreed scope and timeline set before it starts, and is designed to fit around billable work rather than interrupt it. Partner and staff time is limited to the decisions only they can make. Tier 1 handles the assessment, coordination and evidence work.

A quiet first step

Bring the issue already on your desk

Tell Michael what changed, who is asking and when a decision is needed. Thirty minutes, no charge. The first conversation will identify whether Tier 1 fits and the smallest responsible next step, and if another specialist is the better fit you will hear that on the call.

Book a confidential first call