Consulting Practice — Enterprise · Critical Infrastructure · Government

Principal-level consulting across cyber security and AI.

Engagements for CISOs, CIOs and program leaders who need senior, sovereign capability — strategy through delivery, with the framework fluency Australian obligations demand. Available for contract, statement-of-work and advisory engagements.

Practice domains

Six domains. One practitioner. No handoffs.

Each domain is backed by delivered engagements, not capability statements — and cyber security and AI carry equal weight across all of them.

01

AI Security & Governance

Secure AI adoption, shadow AI discovery, AI data security posture, governance aligned to Australia's Guidance for AI Adoption, Privacy Act automated decision-making readiness, and continuity for AI-dependent processes.

AI governanceShadow AIAI DSPMPrivacy Act ADM
02

Cyber Security Consulting

Security strategy and roadmap development, risk and maturity assessment, governance and compliance uplift, and executive advisory — framework-aligned consulting that turns obligations into a defensible, funded program of work.

NIST CSFISO 27001APRA CPS 234GRC
03

Cyber Resilience & Recovery

DR and BCP program development, cyber recovery capability, ransomware readiness, exercising programs and board-level resilience reporting — from business impact analysis through witnessed restore testing.

DR / BCPISO 22301ExercisingBoard reporting
04

Human Risk Management

Trust-centric insider risk programs built on original practice IP — behavioural risk intelligence that protects people and information without surveillance-first thinking. Non-punitive by design, privacy-preserving by architecture — including the new human-risk surface created by everyday AI use.

BRIMTRUST-RInsider riskDLP strategySecurity culture
05

Enterprise Security Architecture

Architecture frameworks, security pattern suites, Zero Trust and identity strategy, cloud and integration security standards — adopted by engineering teams, aligned to your architecture practice, and defensible in review.

Zero TrustIdentityCloudOT / IEC 62443
06

Australian Government Assurance

ISM and PSPF alignment, Essential Eight uplift to target maturity, and SOCI/CIRMP compliance for critical infrastructure entities. Assurance work that anticipates the assessor.

ISMPSPFEssential EightSOCI / CIRMP
Engagement models

Engage the way your program needs.

Contract & interim roles

Principal consultant, security architect or program lead engagements — daily rate, direct or through recruitment partners, security-cleared work considered.

Statement of work

Defined outcomes delivered end to end: architecture frameworks, assessments, uplift programs, migration and platform security workstreams.

Executive advisory

Standing advisory to CISOs, CIOs and boards — roadmap ownership, assurance oversight, deal and RFP support, and a senior sounding board on retainer.

Delivery record

Selected engagements.

Client names available in conversation where confidentiality allows.

State road authorityGovernment · WA

Designed the full enterprise Cyber Security Architecture Framework and security pattern suite — IAM, cloud, OT/ITS, integration, remote access and supply chain assurance — with Essential Eight uplift consulting and privileged access guidance.

National packaging manufacturerCritical manufacturing

Delivered disaster recovery and business continuity capability for a critical manufacturing execution system — safeguarding production infrastructure of national significance.

State justice agencyGovernment · NSW

Delivered cyber transformation across the agency, spanning risk, governance and security operations uplift.

Global technology enterpriseHPE · Asia Pacific

Led the APAC Integrated Risk Management capability and served as global lead for PCI DSS data centre compliance — enterprise risk, compliance and resilience programs across the region, alongside 10,000+ and 100,000+ user transformation programs at HPE and IBM.

Principal

Leon Hutcheson

Principal cyber security consultant with deep senior practitioner delivery across Government, critical infrastructure and enterprise — HPE as IRM Director Asia Pacific and global PCI DSS lead, IBM Asia Pacific, Sun Microsystems and CSO Group Australia.

Trusted advisor to CIOs, CISOs and executive stakeholders — known for translating complex technical issues into clear business value, and for combining strategy, governance and delivery to win and execute complex engagements with measurable outcomes.

Trained at the Massachusetts Institute of Technology (MIT) in applied generative AI, with the practice deliberately positioned where the risk now lives: the intersection of cyber security, AI adoption and human behaviour.

  • Massachusetts Institute of Technology (MIT) — Applied Generative AIAI security & governance
  • ISM · Essential Eight · PSPFAustralian Government frameworks
  • SOCI / CIRMP · ISO 22301 · NIST CSF · IEC 62443Critical infrastructure & resilience
  • University of Oxford (Saïd Business School) — Cyber Security for Business LeadersExecutive education