Partners

I can’t do everything, but I probably know someone who can.

Book a conversation

The work I do not do myself

Advisory only goes so far. Some problems need tooling, some need specialists, and certification auditing needs independence.

I am a governance and risk advisor. That is deliberately a narrow thing to be good at.

Governance decisions often need something built, monitored or measured before they mean anything. Rather than pretend otherwise, or hand you a vendor list and wish you luck, I work with a small number of partners whose work I am willing to stand behind.

Of course, I’m happy to work with your existing partners, but in cases where you need a trusted recommendation, or someone to add to your shortlist for evaluations, I’m happy to help.

With 30+ years in IT and more than half of that in CIO or Director level roles, I’ve seen quite a few vendors.

My Partners

SAICAP - SAI Global

SAI Global Consultants and Affiliates Program member logo

 

Governance Works is a member of the SAI Global Consultants and Affiliates Program (SAICAP).

Here is why that matters to you. A certification body cannot audit a management system that it built itself, and nor should it. That independence is the whole point of certification. It does mean, though, that most organisations end up managing two relationships and hoping the work one produces is what the other expects.

Being in the SAICAP program means those two relationships already understand each other. I build it, they audit it, and neither of us marks our own homework.

Enablis

Enablis logo, managed security and network services partner


Managed security and network services

Governance decides what needs to be true. Someone still has to run it.

Enablis are a Sydney managed security service provider covering the operational
side: 24/7 SOC monitoring, endpoint and email security, SASE and secure browsing,
and carrier-agnostic connectivity across multiple sites. Their controls map to
Essential Eight, ISO 27001 and CPS 234, which is the same ground my ISO 27001 and
RFFR work covers from the governance end.

I have been their client as well as their partner. They built the secure network and SASE framework at a disability services provider I was IT Director for, so this is a recommendation based on having lived with the result.

More to come

I am in conversation with a small number of other specialists, in areas where I
would rather refer than pretend. When those firm up they will appear here, named.

If you need something I do not cover, ask anyway. I would rather point you
somewhere good than take work I am not the right person for.

How it works

I may introduce partners who I work with, but of course if you already have someone in mind I can work with them. Ensuring that governance is embedded and maintainable requires cooperation between your vendor partners. 

I will work with your partners or mine to ensure tooling is appropriate and meets business objectives set out by your organisation.

Not sure where to start?

Tell me what you're facing. You'll get a straight answer on whether this is the right piece of work, and what it would involve.

Book a conversation