"Cybersecurity isn’t just a technical issue." In my conversation with Luke Irwin, he made a powerful analogy: 𝐈𝐓 𝐚𝐧𝐝 𝐜𝐲𝐛𝐞𝐫 𝐚𝐫𝐞 𝐜𝐨𝐮𝐬𝐢𝐧𝐬, 𝐧𝐨𝐭 𝐭𝐰𝐢𝐧𝐬. They might work side-by-side, but cybersecurity requires its own specialist skill set. This is especially so when framed through governance, leadership, and culture. For executives and boards, this isn’t optional. Under the Corporations Act, you have an obligation to consider cyber risk as part of your overall risk portfolio. And it’s not enough to say “we’re covered.” You need evidence that your frameworks, policies, and controls are actually working. What really stood out was Luke’s perspective on right-sizing cybersecurity: 👉 Banking-grade security on a 10-person SMB is overkill. 👉 But as you scale, so too must your security posture. It’s about matching governance, risk, and compliance to your organisation’s size, maturity, and risk profile so security enables growth instead of stifling it. #cybersecurity #fractionalCISO #virtualCISO #vCISO #riskmanagement #cyberresilience #governance #TechExecInsights
Darren Smith - FYI
Very well put Luke Irwin - CISSP, CISM, GCERT Cybersecurity. The right tool for the right job is key. No difference when talking about cyber frameworks and standards as a tool. #goodgovernance #smb1001 #functionaloutcomes
I help B2B tech companies go to market faster. Founder with 1 exit.
4wPrefer to watch the full 20 minute conversation? It's here on YouTube https://www.youtube.com/watch?v=wIKRmycIWzs