About Tier 1

The person you meet is the person who does the work.

Tier 1 is led by Michael Angelo, with more than 14 years in IT consulting and managed security and Lead Auditor credentials across information security, privacy and AI management systems.

Scroll to explore
02Tier 1

Section 02

The breadth is real. The accountability stays personal.

One person stays close enough to see how a requirement affects technical controls, how those controls affect assurance and where AI changes the decision. Michael remains directly involved from the first conversation through the work included in the agreed scope.

There is no junior analyst learning on your account and no rotating team that needs to be briefed again. Michael works with the firm's existing staff, IT providers and specialist advisers, with one clear line of accountability for the agreed program.

Discretion is part of the job. Tier 1 treats client information with the care expected in legal, advisory and private-wealth environments.

03Tier 1

Section 03

Credentials behind the advice

Michael holds Lead Auditor credentials covering ISO 27001 information security, ISO 27701 privacy and ISO 42001 AI management systems. He also holds CISSP, CISM, CISA, CEH, CCNA and Microsoft certifications across Microsoft 365 and Azure.

04Tier 1

Section 04

AI governance grounded in management-system discipline

Michael's ISO 42001 Lead Auditor credential sits alongside information security and privacy audit experience. The result is practical AI governance that connects policy, risk, suppliers, people, monitoring and evidence instead of treating AI as a stand-alone technology exercise.

05Tier 1

Section 05

Track record

The public proof points below are drawn from the approved Tier 1 claim register.

ISO 27001 certification

Led certification programs for Eftsure, Crypto Tax Calculator, Cloud Services Australia, LinkSafe and SupportFusion, including two documented programs with zero non-conformities.

Enterprise assurance

Guided Soprano Design and Whispir through SOC 2 Type II attestations, delivered DORA alignment for Soprano and supported Singapore IMDA requirements.

Incident response

Served as incident response lead adviser for Ritchies IGA during a major data exposure event, from board briefings through regulatory notifications.

Law firm security

Provides ongoing security support to Australian law firms including Indigo Lawyers and LegalByte.

06Tier 1

Section 06

Why Tier 1 exists

Law firms and boutique consultancies can be too lean for separate GRC, cybersecurity and AI governance leaders, yet too exposed to leave the connections between them unowned. Tier 1 fills that gap with direct senior judgement and coordinated delivery.

07Tier 1

Section 07

How the work is approached

The engagement is designed to help leadership make defensible decisions and help providers deliver the right controls. Complexity is reduced, but material risk is not softened or hidden.

Direct

Leadership hears what matters, why it matters and which decision is required in language the firm can use.

Proportionate

The scope follows the firm's risks and obligations rather than importing an enterprise program into a small team.

Evidence-led

A control is treated as complete when its operation and ownership can be shown, not simply because a policy exists.

Collaborative

Existing staff, IT providers and advisers remain part of the solution, with boundaries and accountability made explicit.

A quiet first step

Bring the issue already on your desk

Tell Michael what changed, who is asking and when a decision is needed. The first conversation will identify whether Tier 1 fits and the smallest responsible next step.

Book a confidential first call