Software Partners

The platform layer.

Purpose-built platforms that give our risk operations continuous evidence, structure and objectivity: the tooling beneath vCISO-led delivery.

MyCISO logo
Security management platform

A purpose-built platform for running and evidencing a cyber security program end to end: assessments, roadmaps and reporting in one place. It gives our vCISO-led delivery a consistent, auditable backbone.

Visit MyCISO →
TRACERY
Enterprise trust management

A continuous, evidence-led platform for proving trust across supply chain, people and technology, replacing static questionnaires with objective, independently validated evidence and a risk position that recalculates as things change.

Visit Tracery →
Partner practices

Independent practices, aligned on how risk should run.

BayRisk works with a group of independent, senior cyber practices that have aligned around how we approach the operation of risk inside regulated businesses. Each is its own firm, engaged as a partner rather than staff, and each brings deep experience in the sectors where the obligations bite hardest.

Darren Shearsby
Darren Shearsby
CISO52 · CISO & vCISO leadership
When Darren gets engaged
When you need a senior CISO or vCISO to own the security position and drive a SOCI or Enhanced CIRMP program through to completion, in telco, financial services or critical infrastructure.
Industry focusFinancial services, telco and critical infrastructure.
Cyber focusCISO and vCISO leadership, driving SOCI and Enhanced CIRMP programs through to completion, with specialist vendor coordination and independent review where the program needs it.
Regulatory focusAPRA CPS 230 and CPS 234, SOCI Act and CIRMP, and telecommunications security.

Darren Shearsby leads CISO52, providing CISO and virtual CISO leadership to critical infrastructure and heavy industry. His focus is driving SOCI and Enhanced CIRMP programs through to completion: holding the senior security judgement for organisations across telco, financial services and critical infrastructure, and coordinating specialist vendors and independent reviews where the program needs them. As a BayRisk partner, Darren works on engagements that need a senior CISO to own the security position and move a SOCI program forward.

Visit CISO52 →
Hank Opdam
Hank Opdam
Cyber Matters · Fractional CISO
When Hank gets engaged
When an energy, utilities or critical-infrastructure business needs fractional CISO leadership across both IT and operational technology, or board-level cyber risk explained in terms directors can act on.
Industry focusEnergy and utilities, and critical infrastructure.
Cyber focusFractional CISO leadership, OT and industrial control security aligned to IEC 62443, and board-level cyber risk.
Regulatory focusSOCI Act and Enhanced CIRMP, AESCSF, and IEC 62443 for operational technology.

Hank Opdam runs Cyber Matters, a fractional CISO and cyber risk practice built on more than twenty-five years in technology and over a decade in senior CISO roles, including cyber leadership for a critical-infrastructure provider. His approach is pragmatic and outcome-focused, and he is as comfortable in the boardroom as the operations centre, educated in enterprise security across CISSP, CISM and SABSA, and in IEC 62443 for the operational-technology and safety domains that energy and utilities depend on. As a BayRisk partner, Hank works with energy, utilities and critical-infrastructure clients who need senior cyber leadership across both IT and OT.

Visit Cyber Matters →
Michael Wicks
Michael Wicks
MW Cyber · GRC & regulatory advisory
When Michael gets engaged
When a regulated organisation needs SOCI and CIRMP delivery, a regulatory readiness audit, or fractional GRC leadership that will stand up to regulator, auditor and board review.
Industry focusCritical infrastructure and regulated organisations across telco, energy and utilities, financial services, government and professional services.
Cyber focusRegulatory readiness audits, SOCI CIRMP gap analysis and build, operationalised cyber programs, fractional GRC leadership, and board attestation.
Regulatory focusSOCI Act and CIRMP, telecommunications security (TSRMP), ISO 27001, APRA CPS 234 and CPS 230, Essential Eight, DISP, IRAP and PSPF.

Michael Wicks leads MW Cyber Consulting, a Sydney cyber governance, risk and compliance practice working with organisations accountable to regulators, boards and enterprise customers. The practice is principal-led, so clients get senior judgement on the work itself, and programs are built to hold up under regulator, auditor and board review.

He works across the tooling as well as the obligations, running GRC platform instances in live delivery and shaping vendor reporting so the output answers what a board or regulator will ask. MW Cyber operates as an independent partner to BayRisk, engaged on SOCI and CIRMP work, regulatory readiness and fractional GRC leadership.

Visit MW Cyber →
Resource

Get the Tracery datasheet.

A concise overview of Tracery's continuous, evidence-led approach to enterprise trust management. Enter your work email and it'll download straight away.

Download the datasheet

Business email required.

We'll use your details to send the datasheet and occasional relevant BayRisk updates. Personal email domains (Gmail, Outlook and similar) aren't accepted.

Partner with BayRisk

Interested in working together?

If you're a platform or specialist whose work complements continuous risk operations, we'd like to hear from you.

Get in touch