For Australian law firms and boutique consultancies

Bring GRC, cybersecurity and AI governance into one accountable program.

Start with the client or insurer request, deadline, cyber concern or AI rollout already on your desk. Work directly with Michael on the agreed scope to set one priority order, coordinate existing providers and advisers, put controls into practice and retain evidence your firm can use.

Speak directly with Michael. Do not include privileged, sensitive or incident details in the booking form.

Scroll to explore

Selected experience

Trusted by

Selected organisations Michael has worked with across consulting, delivery and security engagements.

  • Microsoft
  • Formula 1 Australian Grand Prix 2024
  • Oracle
  • AFL
  • Nosworthy Group
02Start with what put this on your desk

Start with what put this on your desk

You do not need to choose the service first.

Bring the pressure already in front of you. Tier 1 will identify where it crosses GRC, cybersecurity and AI governance, then define the smallest responsible starting point.

A client or insurer wants evidence

A panel review, security questionnaire or PI renewal is sitting on the desk with a deadline, and the honest answer today is not the one the firm wants to give.

A new obligation has a deadline

A privacy change, contract clause or client security schedule now applies to the firm, and someone has to turn it into named owners, working controls and proof.

A cyber concern exposed uncertainty

A suspicious payment email, a compromised mailbox or a provider change just showed that nobody is certain which controls actually operate.

AI is moving faster than the rules

Staff are already putting real work into AI tools. Nobody has decided what is allowed, what is off limits and who checks the output before it is relied on.

03Three disciplines. Led as one.

Three disciplines. Led as one.

One issue can cross all three disciplines.

A client requirement can change a cyber control. A cyber weakness can undermine an assurance answer. An AI use case can affect both. Tier 1 keeps the requirement, control, owner and evidence connected, so leadership has one view of what matters and what happens next.

Translucent sheets aligned on a dark grid with a single amber marker.
04Why Tier 1

Why Tier 1

Senior accountability, backed by specific evidence.

You work directly with Michael Angelo on the agreed program, backed by more than 14 years in IT consulting and managed security.

One senior relationship

No junior hand-off, rotating account team or call centre. Michael stays accountable for the work.

Assurance credentials

Lead Auditor credentials across ISO 27001 information security, ISO 27701 privacy and ISO 42001 AI management, alongside CISSP, CISM and CISA.

Proven delivery

ISO 27001 certification programs led for Eftsure, Crypto Tax Calculator, Cloud Services Australia, LinkSafe and SupportFusion, including two programs certified with zero non-conformities. Incident response lead adviser to Ritchies IGA through a major data exposure event.

Discretion is the job

Ongoing security support to Australian law firms including Indigo Lawyers and LegalByte. Your information is treated with the care your own clients expect from you.

05Who we work with

Who we work with

Built for lean firms carrying serious trust.

Tier 1 is built for Australian law firms and boutique consultancies that handle confidential work, face serious assurance demands and need senior ownership without three separate internal functions. Selected family offices are supported through trusted referrals.

Closed charcoal folios on a boardroom table at night, lit by a single warm lamp.
06One connected program

One connected program

From requirement to working control to usable evidence.

Start with the most material issue in any pillar. Tier 1 maps where it overlaps with the others, sets one priority order and keeps owners, providers and evidence moving together.

Map

Identify the obligations, information, systems, AI uses, providers and decisions that shape the exposure.

Decide

Separate urgent gaps from longer-term improvement and name the decisions leadership must own.

Implement

Coordinate staff, technology providers and specialist advisers around the controls and outcomes agreed.

Test and prove

Confirm that controls operate in practice and retain evidence for clients, insurers, audits and future decisions.

07Questions

Straight answers

Common questions

Can one engagement cover GRC, cybersecurity and AI governance?

Yes. They can be scoped as one risk and control program. Tier 1 can map the obligations, set priorities, coordinate cyber and AI controls, test what is operating and maintain the evidence, while legal and other regulated advisers remain responsible for advice in their fields.

We are only a few people. Are we really a target?

Yes. Small firms can still hold valuable information and move significant payments. Good basic security reduces the opportunity for an attacker without forcing a small team into an enterprise-sized program.

Do we need an expensive certification?

Usually not to start. Most firms gain more by getting the fundamentals right first. We help you decide whether a formal standard is worthwhile based on your risks, client expectations, contracts and insurer requirements.

We already have an IT provider. Why do we need you?

General IT keeps systems running. Security governance sets priorities, tests whether controls are effective and gives leadership a clear view of risk. We work alongside your existing provider and make the boundaries visible.

How much of our time will this take?

As little as practical. We do the heavy lifting and ask for input where leadership context or a business decision is required. The aim is to take security work off your plate, not create another reporting burden.

Where should we start?

Start with a short review of the information, payments, systems and obligations that matter most. You will receive a prioritised view of the urgent gaps, the sensible next steps and which work can wait.

A quiet first step

Bring the issue already on your desk

Tell Michael what changed, who is asking and when a decision is needed. The first conversation will identify whether Tier 1 fits and the smallest responsible next step.

Book a confidential first call