Experienced cyber GRC and IRAP leadership.

Cyber AF is led by Michael Farlow, an ASD-endorsed IRAP Assessor with more than a decade of IT, cyber security and management experience across the public and private sectors.

Practical experience across government and industry

Michael has delivered cyber security consulting, assessment and security leadership services across dozens of federal government departments and agencies and private large, medium and small businesses located in both Australia and overseas.

His experience spans IRAP assessments, ISM and PSPF guidance, security risk management, system security documentation, gap analysis, stakeholder engagement and remediation planning.

Cyber AF is designed for organisations that want thoughtful guidance, strong communication and security work that is practical, defensible and commercially grounded.

Trust signals that support serious engagements

  • ASD-endorsed IRAP Assessor
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • PRINCE2 Practitioner
  • AgilePM and SAFe background
  • More than a decade of IT, cyber security and management experience

Well suited to organisations where trust, assurance and documentation quality matter

Government suppliers

Organisations that need credible security governance and stronger assurance readiness in public-sector environments.

Cloud and technology providers

Service providers that need stronger control narratives, evidence and documentation to support customer trust.

Professional services firms

Firms that need external expertise to sharpen security governance, structure uplift activity and improve risk visibility.

Security-conscious businesses

Organisations that want a practical, low-noise approach to cyber security governance, risk and assurance.

Representative experience

Representative experience across dozens of federal government departments and agencies and private large, medium and small businesses located in both Australia and overseas.

Want to discuss whether Cyber AF is the right fit for your environment?

Start with a straightforward introduction and a high-level discussion of your security objectives and assurance needs.

Request an introduction