Principal Consultant

Paul Berryman

Sydney-based. Governance, risk and security advisory for organisations that want the practical version.

Book a conversation

Background

Thirty years in IT, sixteen of them at CIO and director level. Every one of those senior roles has been the same job in a different setting: taking a technology function that was not serving the business and making it do so.

Twice that has meant building from the ground up. The first was a children’s services organisation I joined two weeks after a ransomware attack had destroyed its entire IT environment. There were no computing services running on the day I arrived. You learn quickly what actually mattered: which controls would have changed the outcome, which ones were theatre, and how an organisation behaves when the systems its people depend on are simply gone. The second was a build where no IT structure existed at all, which turns out to be a different kind of difficult.

Both taught the same lesson, and it is why Governance Works exists. The organisations that recover fastest, and the ones that never need to, are not the ones with the most controls. They are the ones where somebody had already decided which risks mattered and who was accountable. That is governance, and it is worth considerably more than the framework it happens to be written in.

Paul Berryman Principal Consultant Certified Professional in AI Governance, ISO42001 Senior Lead Implementor

Right Fit for Risk, from the inside

For four years I was the person responsible for Right Fit for Risk accreditation at a large Disability Employment Services provider, through its transition to Inclusive Employment Australia. Initial certification, recertification every year after that, and the RFFR work behind a successful IEA bid when the DES contracts ended and the tenders opened.

That is a different job from advising on it. When an assessor asks a question there is nobody to hand it to. You are the one producing the evidence, explaining the gap, and saying what you intend to do about it, with a departmental contract sitting behind the answer. You also do it again the following year, and the year after, which changes what you build. Controls that look impressive once and cannot be sustained are worse than useless, because you have to keep proving them.

It means I read these frameworks the way a provider reads them, looking for what is genuinely required, what is merely recommended, and which of the two an assessor will treat as which. That distinction is most of the work and it is not written down anywhere.

The AI obligations now sit inside the same accreditation. Same assessor, same annual rhythm, same evidence burden, on a subject most providers have not had to think about before.

Credentials

Working with me

Direct. You get me, not a team you never meet. Engagements are scoped so you know what you are getting and when it ends.

Colleagues joking about human error, one pointing to his "Human Error" slogan t-shirt

If you're having a bad day, I can empathise, I've been there...

My second worst first day was walking in to an environment that had been destroyed by a ransomware attack only a couple of weeks before.

I had to work with the incident response teams to not only recover the environment, but to protect it as we went and prevent this from ever happening again. I got to meet the Board under some trying circumstances and rebuild their trust in the IT platforms.

A few months later, once the environment was rebuilt and hardened, I met Human Error in person. Not the concept: the character Mimecast built its awareness training around, whose whole job is to click the thing you asked people not to click. After the year we had just had, the introduction felt earned.

To hear about my worst first day... well that might need a chat over a coffee at the very least. 

Not sure where to start?

Tell me what you're facing. You'll get a straight answer on whether this is the right piece of work, and what it would involve.

Book a conversation