Fractional RiskOps

Risk isn't a checkbox or an application.
It's an operation.

BayRisk runs continuous, vCISO-led risk management on your behalf, an operating function, not another platform to log into. You get the outcome: risk understood, prioritised, and actively worked, week after week.

Supply chain Cloud Ownership Systems OT Cyber People
Fluent in the obligations that matter APRA CPS 230 CPS 234 SOCI / CIRMP AESCSF AML/CTF Tranche 2 Essential Eight ISO 27001
Two RiskOps services

One operating model. Two services. Both run for you.

RiskOps is risk run as an operation, and it comes in two forms. Take one or both. Whichever you choose, we run it on your behalf and hand you a position you can prove.

RiskOps: GRC

Governance, risk & compliance, run for you

Continuous, vCISO-led cyber and enterprise risk management. We retire the annual scramble, track evidence-based maturity across every framework and obligation that applies to you, drive the uplift to closure, and keep a board-ready, provable position current on any day of the year.

  • Multi-framework maturity: CPS 230, SOCI / AESCSF, Essential Eight, ISO 27001
  • Evidence, validated, not self-attestation
  • Board-ready reporting and a live, provable position
See how RiskOps GRC works →
RiskOps: ETM

Enterprise Trust Management, run for you

Continuous, evidence-led proof of trust across your suppliers, your ownership and control, and your people. Intelligence-grade tradecraft that resolves the fourth-party and personnel exposure a questionnaire can't reach, maintained as a live position rather than a point-in-time attestation, and run on your behalf.

  • Fourth-party and concentration exposure behind your suppliers
  • Ownership, control and FOCI resolved across borders and registries
  • Personnel exposure held to an intelligence standard
Explore RiskOps ETM →
The approach

Risk is a spectrum — not a checkbox.

Most organisations buy fragmented point tools that return static, dead data. Cyber gets the budget while the risks that actually move the needle — supply chain, people, ownership and control — go unmanaged. And a platform, however good, just hands the work back to a team that doesn't have the capacity to do it. The tool becomes the job.

RiskOps is different. It's a continuous operating function, led by a virtual CISO and run for you: objective evidence in place of self-attestation, a risk position that's recalculated as things change, and clear decisions on what to fix first.

  • ISAn ongoing service that manages risk on your behalf
  • ISvCISO-led judgement, backed by continuous evidence
  • ISOutcome-focused: prioritised, worked, reported
  • NOTA SOC or a monitoring alert feed
  • NOTPen-testing or one-off project consulting
  • NOTA GRC platform you have to run yourself
Datasheet

RiskOps

Get the BayRisk RiskOps datasheet — a concise overview of how we run continuous, vCISO-led risk management as an ongoing operating service. Enter your work email and it downloads straight away.

Download the RiskOps datasheet

Business email required.

We'll use your details to send the datasheet and occasional relevant BayRisk updates. Personal email domains (Gmail, Outlook and similar) aren't accepted.

How it works

An operating rhythm, not a report on a shelf.

BayRisk plugs in as your fractional risk function — senior capability at a fraction of a full-time hire, working to a steady cadence.

1

Establish the picture

We map your real risk exposure across cyber, supply chain, people and controls — grounded in evidence, not a questionnaire.

2

Run it continuously

Your risk position is kept current as things change. We prioritise what matters, drive the work forward, and keep leadership informed.

3

Report with clarity

Board-ready reporting that answers the only questions that matter: where do we stand, what are we doing about it, and is it working.

How the evidence is collected

Yes, there's a platform underneath. You just don't have to run it.

A live, evidence-led risk position doesn't come from nowhere. It runs on real tooling: a vCISO delivery-and-reporting platform, paired with supply-chain and enterprise-trust intelligence, that gathers and validates the evidence and recalculates your position as your business and your obligations change. What makes RiskOps different from running that tooling yourself isn't that there's no platform. It's who operates it.

The platform is real

Continuous evidence collection and validation, multi-framework maturity tracking, and a position that recalculates as things change. It runs on a proper delivery-and-reporting platform and intelligence-grade supply-chain and trust data, not a questionnaire filled in from memory.

You own it, we operate it

The platform is licensed in your name, so the tooling is yours, with no lock-in to us. What we take off your plate is running it: the configuration, the tuning, the evidence-gathering, the day-to-day. You get the outcome the tooling always promised, without a console your team has to learn, staff and answer for.

You choose how close you get

Have as much or as little to do with the tooling as you like. Stay fully hands-off and simply receive the proven position and board-ready reporting, or have your team log in and work alongside us. Your call, and it can change as your capacity does.

What it replaces

The outcome of a full-time hire, for less than the cost of one.

Running a credible GRC function in-house means hiring for it, and in Australia that is not a small line item.

Current 2026 salary guides put a risk and compliance manager at $135,000 to $170,000 base, a cyber-security manager at $160,000 to $205,000, and a full CISO at $220,000 to $305,000. None of those figures include the 12% superannuation guarantee or the payroll tax, workers' compensation, leave, tooling and recruitment that sit on top, which carry a mid-level hire past $200,000 fully loaded and a CISO well beyond $330,000. Every one of those numbers buys you a single person, with one person's capacity and one person's knowledge.

Hiring a GRC manager in-houseRiskOps: GRC
Annual cost$200,000 or more fully loaded for one mid-level hire, and $330,000 or more for a CISO-grade one.Less than the cost of a single full-time hire.
Cyber and CISO expertiseA governance manager is rarely a CISO, so deep cyber judgement is a second hire or a consultant on top.Senior CISO and cyber expertise embedded and contracted in, baked into the cost rather than a separate line item.
Capacity and coverOne person, who takes leave, gets sick, and can only be in one place at a time.An operating layer and a bench of senior practitioners, so there is no single point of failure.
Key-person riskWhen they resign, the corporate memory and the current position can walk out with them.The operation, the evidence and the position stay with you, kept current whoever is on the team.
The platformYou still have to select, license and run a GRC platform on top of the salary.The platform is licensed in your name and operated for you, with no lock-in.
Board reportingProduced when there is capacity, often in a pre-audit scramble.A board-ready, provable position kept current on any ordinary day.

Salary ranges: Robert Half Australia and Morgan McKinley 2026 salary guides, base salary excluding superannuation and on-costs. Fully-loaded figures add the 12% superannuation guarantee and employer on-costs such as payroll tax, workers' compensation, leave, tooling and recruitment.

Because BayRisk is independent and not tied to any single platform, what you hear on where your real risk sits and what to fix first is senior judgement, not a pitch for a product. You get the outcome a full-time hire would deliver, and the cyber expertise a full-time hire usually would not, inside one accountable programme that costs less than the salary alone.

Read more: How to run a GRC function without hiring a cyber consultant →

See the numbers for your organisation.

We will build you a specific business case, comparing RiskOps against the fully-loaded cost of hiring for the role, sized to your headcount, your sector and the obligations you carry, whether that is CPS 230, SOCI and AESCSF, Essential Eight or ISO 27001.

The founder
Mike Saxton, Founder of BayRisk
Mike Saxton
Founder, BayRisk
Qualified company director (AICD) · LinkedIn →

Thirty years where cyber risk meets the boardroom.

BayRisk was founded by Mike Saxton, and it exists because of what he has seen over a career spent helping regulated organisations manage technology risk.

Across thirty years, Mike has worked where technology risk meets the boardroom, bringing enterprise software, data security and cyber capability to heavily regulated industries across Australia, Asia, Europe and the Middle East. At OpenText he took data security and information governance into banks, insurers and other regulated organisations, and most recently he has worked at the centre of the virtual CISO and cyber advisory market. The pattern he watched repeat became the reason for BayRisk: the organisations most exposed to cyber and regulatory risk are so often the least resourced to meet it, and the market's reflex is always another tool handed to a team already at capacity.

What he brings to it is a career built on one discipline, listening closely, understanding the business behind the risk, and turning it into insight a client can act on. Mike leads BayRisk's senior client relationships and stands behind its promise, that your risk is run as a continuous operation and your position is one you can prove, while ownership and the decision stay where they belong, with your board. Behind him BayRisk fields a bench of CISOs and senior practitioners for the deep delivery, so what you get is board-grade judgement and hands-on capability inside one accountable programme.

FAQ

Fractional RiskOps, explained.

What is RiskOps?

RiskOps is a continuous operating function that manages an organisation's cyber and enterprise risk on an ongoing basis, led by a virtual CISO (vCISO). Instead of a one-off assessment or a platform you run yourself, it maintains a live, evidence-based view of risk and actively works to reduce it.

How is BayRisk different from a SOC, penetration test, or GRC platform?

A SOC watches for security alerts, a penetration test is a point-in-time check, and a GRC platform is software you operate yourself. BayRisk is none of these — it is an outsourced operating function that runs the risk-management work on your behalf, using vCISO judgement backed by continuous evidence, and reports on outcomes.

What does “fractional” mean?

Fractional means you get senior risk leadership — vCISO-level capability — for a fraction of the cost and commitment of a full-time hire. BayRisk plugs in as your part-time, ongoing risk function rather than a permanent executive.

Who is BayRisk for?

BayRisk suits Australian organisations that need to manage cyber and enterprise risk credibly but do not have, or do not need, a full-time CISO — including mid-sized businesses, scale-ups and regulated firms standing up a risk function.

What types of risk does BayRisk manage?

Beyond cyber security, BayRisk manages risk across supply chain, people, and ownership and control — the areas that materially affect an organisation but often go unmanaged when budget is focused on cyber tooling alone.

Where is BayRisk based?

BayRisk is an Australian fractional RiskOps practice, working with organisations across Australia.

Why now

The obligations arrived. The capacity didn't.

The risk and the regulation grow daily, while the resources to meet them stay scarce and shrinking. For three of Australia's most exposed sectors, the clock is already running.

Financial services · live now

APRA CPS 230

Operational-resilience accountability now sits with the board, and it has to be provable on any ordinary day, not just reconstructed for the annual audit.

Energy & utilities · by 2028

SOCI & AESCSF SP-2

Enhanced SOCI obligations require AESCSF Security Profile 2 across eleven domains by mid-2028, with only about two assessment cycles left to prove it.

Professional services · from July 2026

AML/CTF Tranche 2

Anti-money-laundering obligations now reach law, accounting, conveyancing and real-estate firms that have never carried a compliance function before.

Get in touch

Book a short, private briefing.

Thirty minutes, no obligation. We pinpoint where your risk actually sits against your obligations, and you leave with a clear read and a recommendation, whether or not we go further.

Book a 30-minute briefing