Josh specialises in leading complex cybersecurity assessments and transformations for organisations across sectors including financial services, government, education and consumer. With extensive experience in cyber strategy, uplift programmes, and regulatory alignment, he is recognised for rapidly improving organisational maturity.

Josh regularly advises boards, executives and risk committees, helping them navigate cyber investment decisions, emerging threats and compliance requirements across cyber frameworks such as NIST, ISO27001, ISM, Essential 8 and CPS 234.

Josh is known for translating technical risk into clear insights for senior leaders and boards, enabling pragmatic decisions. His strengths in stakeholder engagement, programme leadership and future focused solution design ensure that clients not only address current vulnerabilities but build long term, sustainable cyber maturity. 

FSI Organisation – Cyber Assessment, Strategy Design & Uplift

Advising a financial services client by leading an enterprise wide cyber assessment and designing a new cyber strategy aligned to NIST & ISM. Delivering a multi-stream uplift programme that significantly increases maturity and reduces regulatory risk. Driving executive alignment and securing investment to embed sustainable resilience.

Healthcare Organisation – Multinational Cyber Assessment & Uplift Roadmap

Acting for a global healthcare group by conducting a multinational cyber assessment across Europe, the Americas and APAC. Producing a unified uplift roadmap that clarifies priority risks, streamlines investment decisions and strengthens cyber capability across diverse regulatory environments. Achieving clear executive visibility of enterprise risk posture.

University Merger – Cyber Programme Director

Acting as Programme Director & Programme vCISO for the cyber transformation arising from the merger of two major Australian universities. Leading over 20 streams of work to integrate systems, rationalise risk, and establish a unified security posture. Enabling a smooth transition and delivering a measurable uplift in cyber maturity across the new university.

University – Cyber Operating Model Design

Advising a large university on the design of its future-state cyber operating model, including capability definition, role structure, and sourcing strategy. Creating a practical, scalable model that supports long-term uplift and improves operational clarity between central IT, faculties, and external providers.

Government Corporation – Cyber Risk Register & Board Reporting

Advising a government owned corporation on the definition of its cyber risk register, controls library and the creation of a new cyber board reporting framework. Establishing clear risk ownership, consistent control definitions and executive ready reporting that enhances decision making and strengthens governance alignment.

Areas of Expertise
  • WK Advisory
  • Cyber Architecture
  • Cyber Assessment
  • Cyber Strategy
  • Cyber Transformation

Industry Representation
  • Financial Services 
  • Healthcare and Life Sciences 
  • Government 
  • Technology and Cyber