GRC, cybersecurity and AI governance

Start with one pressure point. Keep the whole risk picture connected.

Bring the requirement, control concern or AI use case already in front of you. Tier 1 defines the boundary, connects the related risks and carries the agreed work through assessment, remediation, evidence and ongoing leadership where needed.

You do not need to diagnose the service first. A thirty minute call, no charge, starts with the issue that has urgency.

Scroll to explore
02One accountable specialist
03Choose your starting point

Choose your starting point

Which question are you trying to answer?

If the question is what the firm must do or prove, start with GRC. If it is whether important controls work, start with cybersecurity leadership. If it is how people can use AI without crossing the line, start with AI governance. If it crosses all three, Tier 1 will build one connected scope.

04What useful work leaves behind

What useful work leaves behind

Useful work should leave your firm easier to govern.

A useful engagement should make the next decision easier. The exact documents depend on scope, but the work is organised around practical outcomes rather than a report that sits unread.

A prioritised risk view

A short account of the material gaps, their business effect and the order in which they should be addressed.

Named ownership

Clear responsibility across leadership, staff, IT providers and other advisers, including decisions that cannot be delegated.

Control evidence

Records that show what is configured, approved, tested or still accepted as a visible risk.

A workable cadence

A review rhythm that matches the firm, with changes, exceptions and overdue actions brought back to leadership.

05How engagements work

How engagements work

Three ways to work with Tier 1. Each one is agreed before it starts.

Most firms begin with a short call, then a bounded first review. Ongoing leadership is only scoped once the review has shown what the firm actually needs, so nobody is asked to commit to a program before they can see the gaps.

1. A confidential first call

Thirty minutes with Michael, no charge and no preparation. Describe what prompted the call. You leave knowing whether Tier 1 fits and what the smallest responsible next step is.

2. A scoped first review

A bounded review of the pathways that matter most: identity, email, devices, payments, obligations and the evidence behind the answers the firm currently gives. Fixed scope and fixed fee agreed in writing, from $7,500 + GST.

3. Ongoing security leadership

Senior ownership of priorities, providers, incidents and evidence on a monthly cadence. Scoped after the first review, so the retainer fits the firm rather than a template.

06Questions

Straight answers

Common questions

Can one engagement cover GRC, cybersecurity and AI governance?

Yes. They can be scoped as one risk and control program. Tier 1 can map the obligations, set priorities, coordinate cyber and AI controls, test what is operating and maintain the evidence, while legal and other regulated advisers remain responsible for advice in their fields.

We are only a few people. Are we really a target?

Yes. Small firms can still hold valuable information and move significant payments. Good basic security reduces the opportunity for an attacker without forcing a small team into an enterprise-sized program.

Do we need an expensive certification?

Usually not to start. Most firms gain more by getting the fundamentals right first. We help you decide whether a formal standard is worthwhile based on your risks, client expectations, contracts and insurer requirements.

We already have an IT provider. Why do we need you?

General IT keeps systems running. Security governance sets priorities, tests whether controls are effective and gives leadership a clear view of risk. We work alongside your existing provider and make the boundaries visible.

How much of our time will this take?

As little as practical. We do the heavy lifting and ask for input where leadership context or a business decision is required. The aim is to take security work off your plate, not create another reporting burden.

Where should we start?

Start with a short review of the information, payments, systems and obligations that matter most. You will receive a prioritised view of the urgent gaps, the sensible next steps and which work can wait.

What does a first engagement cost?

The first call is free. A scoped first review starts from $7,500 + GST, with the exact scope and fee agreed in writing before any work begins. Ongoing leadership is only priced after the review, once the firm's actual needs are clear.

How long does a first review take?

The review is bounded to an agreed scope and timeline set before it starts, and is designed to fit around billable work rather than interrupt it. Partner and staff time is limited to the decisions only they can make. Tier 1 handles the assessment, coordination and evidence work.

A quiet first step

Bring the issue already on your desk

Tell Michael what changed, who is asking and when a decision is needed. Thirty minutes, no charge. The first conversation will identify whether Tier 1 fits and the smallest responsible next step, and if another specialist is the better fit you will hear that on the call.

Book a confidential first call