Ian Hughes
INFORMATION SECURITY PROFESSIONAL
- PERSONAL SUMMARY -
I have over twenty five years of experience in the Australian IT industry with the last fifteen years focused heavily on information security. I have extensive experience in security architecture and design and a strong background in GRC, implementation of ISO 27001 compliant ISMS and have been heavily involved with Australian government and associated regulated environments for the last 10 years. I have built a successful business and been a director in Sydney for twelve years and subsequently developed and built a successful security practice in Brisbane before relocating to Melbourne in June 2020 as a principal national GRC consultant for CyberCX to assist the new organisation to develop a national GRC capability.
Additionally, I have a broad technical background in switching, routing, firewall, IPS, Windows, Unix and Linux platforms and have managed a small business and various teams in general IT and specialist security roles. I have worked extensively in both the private and public sector for organisations including Australian Government Agencies, several Critical Infrastructure Providers, the Internal Audit Bureau of NSW, the Cancer Institute of NSW, the University of NSW, NSW Dept of Commerce, Panaseer, St George Bank and Hunterlink.
- PROFESSIONAL EXPERIENCE -
PREVIOUS EXPERIENCE
7/24 - Present: Independent Consultant
4/23 - 6/24: GRC and Advisory Practice Lead for ITSec Australia
5/20 - 3/23: Principal Consultant, GRC National Practice for CyberCX
11/16 - 5/20: Security Practice Lead for Yell IT Group
11/15 - 11/16: Contract Consultant for Cyber Research Ltd
2003 - 2015: Director/Consultant for Swarm Logic P/L
Major Clients included;
IAB Services
Cancer Institute of NSW
University of NSW
NSW Dept. Commerce
ServiceFirst NSW
NSW Central Corporate Services Unit
SPECIALTIES
Information Security Architecture
Information Systems Audit
Information Security Training
Information Systems Governance, Risk and Compliance (GRC)
ICT and Business Resilience
ICT Business Continuity and Disaster Recovery
Information Technology and Security Management
Project and Implementation Management
- CERTIFICATIONS -
- ASSOCIATIONS -
ASD/ACSC InfoSec Registered Assessors Program (IRAP)
ISACA Certified Information System Auditor (CISA)
ISACA Certified in Risk and Information Systems Control (CRISC)
ISACA Certified Information Security Manager (CISM)
ISA/IEC 62443 Cybersecurity Fundamentals Specialist
OSTMM Professional Security Tester (OPST)
Bachelor of Computer Science (BSC University of New England)
Member of Information Systems Audit and Control Association (ISACA)
Member of the Australian Information Security Association (AISA)
Member of the Open Compliance and Ethics Group (OCEG)
Member of the Factor Analysis of Information Risk Institute (FAIR Institute)