InfoSek.Melbourne · Independent advisory

Independent advisory

Information security, cyber security, and privacy advisory for small and medium businesses.

I'm Ben Jackson, a Melbourne-based security and technology leader. I design, implement, and run certified information and cyber security programs for a living: ISO 27001, SOC 2, PCI DSS, and Australian privacy compliance. InfoSek is the independent version of that work, for small and medium businesses that need it sized to fit.

Get in touch

ISO 27001SOC 2PCI DSSAustralian privacyFractional CISO

Services

What I do

Information security and ISO 27001 advisory

Risk assessments, readiness, implementation, and internal audit for businesses that want a security program which holds up: to auditors, to customers, and to actual incidents. I build programs to be certified, and to keep passing the audits that follow.

Privacy and data protection

Privacy Act and APP compliance for Australian businesses, privacy policies that describe what you actually do, and straight answers on GDPR exposure when your customers ask. Advice grounded in current law, written so your team can apply it.

Fractional CISO

Ongoing part-time security leadership, sometimes called a virtual CISO or vCISO: strategy, governance, and audit-facing accountability from someone who has held the executive seat, sized and priced for a small or medium business.

Approach

How I work

I don't do over-the-fence consulting, and I don't sell through fear: if you don't need something, I'll tell you. You won't get a hundred-page report, an invoice, and silence. I don't catch you a fish. I teach you to fish, and if you don't live near water, I notice, and teach you to hunt instead. Engagements end with your people able to run things without me.

Track record

Why InfoSek

  • You get the person who does this for a living, and has for more than a decade, inside payments and financial technology businesses where regulators pay close attention.
  • The programs I build get certified and stay certified. External auditors have examined my work year after year, and every audit has passed.
  • I've carried Australian regulatory obligations from the inside, including for designated critical infrastructure, so my advice starts from what regulators actually expect.
  • Everything is sized for a small or medium business: the controls that matter, and none of the enterprise theatre.
  • Professional indemnity insurance in place, and engagement terms in writing before any work begins.

Contact

Get in touch

To discuss an engagement, or to ask whether I'm the right person for a problem, send the details through below.

Details you submit come directly to me. How they reach me is described in the privacy policy.