About Tier 1

The person you meet is the person who does the work.

Tier 1 is led by Michael Angelo, a cybersecurity and GRC specialist with more than 14 years in IT consulting and managed security.

Scroll to explore
02Tier 1

Section 02

Senior ownership from the first conversation

Michael embeds as a senior security lead, similar to an in-house head of security but scaled to the needs of a smaller firm. There is no junior analyst learning on your account and no rotating team that needs to be briefed again.

Discretion is part of the job. Tier 1 treats client information with the care expected in legal, advisory and private-wealth environments.

03Tier 1

Section 03

Credentials behind the advice

Michael holds Lead Auditor credentials covering ISO 27001 information security, ISO 27701 privacy and ISO 42001 AI management systems. He also holds CISSP, CISM, CISA, CEH, CCNA and Microsoft certifications across Microsoft 365 and Azure.

04Tier 1

Section 04

Track record

The public proof points below are drawn from the approved Tier 1 claim register.

ISO 27001 certification

Led certification programs for Eftsure, Crypto Tax Calculator, Cloud Services Australia, LinkSafe and SupportFusion, including two documented programs with zero non-conformities.

Enterprise assurance

Guided Soprano Design and Whispir through SOC 2 Type II attestations, delivered DORA alignment for Soprano and supported Singapore IMDA requirements.

Incident response

Served as incident response lead adviser for Ritchies IGA during a major data exposure event, from board briefings through regulatory notifications.

Law firm security

Provides ongoing security support to Australian law firms including Indigo Lawyers and LegalByte.

05Tier 1

Section 05

Why Tier 1 exists

Law firms, boutique consultancies and family offices can be too small for a full-time security hire and too exposed to leave security between general IT support and chance. Tier 1 fills that gap with direct senior ownership.

06Tier 1

Section 06

How the work is approached

The engagement is designed to help leadership make defensible decisions and help providers deliver the right controls. Complexity is reduced, but material risk is not softened or hidden.

Direct

Leadership hears what matters, why it matters and which decision is required in language the firm can use.

Proportionate

The scope follows the firm's risks and obligations rather than importing an enterprise program into a small team.

Evidence-led

A control is treated as complete when its operation and ownership can be shown, not simply because a policy exists.

Collaborative

Existing staff, IT providers and advisers remain part of the solution, with boundaries and accountability made explicit.

A quiet first step

Book a confidential call

Talk directly with Michael about what your firm needs to protect and the practical next step.

Book a confidential call