• About Us
  • Contact Us
  • Terms of Use
  • Privacy Policy
  • Disclaimer
  • Sitemap
Friday, August 28, 2026
The AUSTRALIAN BUSINESS JOURNAL
  • Home
  • Business and Finance
  • Entertainment
  • Entrepreneurs
  • Lifestyle
  • Marketing
  • Tech
No Result
View All Result
  • Home
  • Business and Finance
  • Entertainment
  • Entrepreneurs
  • Lifestyle
  • Marketing
  • Tech
No Result
View All Result
Australian Business Journal
No Result
View All Result
Home Featured

Luke Irwin Wants Business Leaders to Stop Treating Cybersecurity Like an IT Problem

by ABJ Staff
August 28, 2026
in Featured
0
Share on FacebookShare on Twitter

For much of its history, cybersecurity has been discussed in a language that makes sense to the people working directly with technology. Vulnerabilities, controls, systems and frameworks dominate the conversation.

Luke Irwin, Cybersecurity Strategist & Advisor, and Expert in Cyber Risk, GRC, BCP & DR, believes that language becomes less useful once cyber risk reaches the boardroom.

After more than 25 years working across technology, cybersecurity, risk and governance, the founder of Aegis Cybersecurity has increasingly focused his career on a different question: how can an organisation make sensible business decisions about a risk that is often difficult to understand, quantify and prioritise?

It is a question that has become more important as cybersecurity has moved beyond the remit of IT teams. Boards and executives are now expected to understand their organisation’s exposure, oversee resilience, navigate regulatory expectations and decide how much to invest in reducing risk.

For Irwin, the answer isn’t to turn executives into cybersecurity specialists. It is to make cybersecurity understandable enough that they can govern it well.

From Technology to Business Risk

Irwin’s perspective has been shaped by a career spanning enterprise technology environments, military service, cybersecurity advisory and senior security leadership.

He also holds CISSP, CISM and ISSMP credentials, but his work today is deliberately less concerned with explaining the technical mechanics of cybersecurity than with interpreting what they mean for an organisation.

Through Aegis Cybersecurity, the independent Australian advisory firm he founded, Irwin works across cyber risk quantification, governance, compliance and fractional CISO services.

Central to that work is the idea that cybersecurity decisions should be connected to the same considerations that influence other significant business investments: likelihood, consequence, priorities, available resources and expected outcomes.

Cyber risk quantification is particularly important to that approach. Rather than relying exclusively on broad labels such as “high”, “medium” or “low” risk, quantification attempts to give organisations a clearer picture of their potential exposure and the value of different interventions.

That can change the nature of a boardroom discussion.

The question becomes less about whether the business is spending enough on cybersecurity in the abstract and more about what a particular investment is expected to protect, which risks it reduces and whether that reduction justifies the cost.

The Case for Independent Advice

That philosophy has also influenced how Aegis Cybersecurity itself has been structured.

The firm doesn’t sell managed IT services, cybersecurity products or software. Its work instead centres on advisory services, including fractional CISO leadership, governance and risk management, cyber risk quantification and programs involving ISO 27001, SOC 2, SMB1001 and the Essential Eight.

The distinction matters because cybersecurity advice can easily become intertwined with technology purchasing decisions.

Aegis’ independent model is intended to separate the two. Recommendations can begin with the organisation’s risk profile and commercial priorities rather than a particular product that needs to be implemented.

It is an approach particularly relevant to small and mid-sized organisations, where the challenge is often deciding what not to do.

Few businesses have unlimited cybersecurity budgets. The practical task is determining which risks matter most, which controls are proportionate and where limited resources will have the greatest effect.

Making Cybersecurity Proportionate

Irwin has also become involved in the discussion around what appropriate cybersecurity looks like outside Australia’s largest enterprises.

One milestone came through Aegis’ work with SMB1001, a cybersecurity standard developed with small and medium businesses in mind. Aegis became the first organisation globally to achieve Diamond certification under the standard and later the first to successfully complete a re-audit.

That experience gave the firm exposure to the framework from two perspectives: advising organisations about cybersecurity standards while also having to implement and maintain one internally.

It reflects a broader theme in Irwin’s work. Compliance can provide structure, but completing a checklist is different from understanding whether an organisation has meaningfully reduced its risk.

Frameworks such as ISO 27001, SMB1001 and the Essential Eight therefore sit within a larger conversation about governance and resilience rather than functioning as the end goal.

Giving Boards Better Questions to Ask

As cybersecurity has risen on corporate agendas, Irwin has increasingly taken that conversation beyond individual client engagements.

He contributes to industry research, conferences, panels and discussions around cyber governance, risk quantification and Australia’s changing cybersecurity environment. His positioning as a speaker follows naturally from the work he does as an adviser: translating a specialised subject for people whose responsibility is to make decisions about it.

The distinction is important.

A board member doesn’t necessarily need to understand how every security control works. A CEO doesn’t need to become an expert in cyber architecture. But both need to know whether the organisation understands its most significant risks, who owns them, what is being done about them and whether those measures are working.

Those are ultimately governance questions.

A Different Measure of Cybersecurity Maturity

There is an understandable tendency for cybersecurity conversations to gravitate towards threats. Breaches are visible. New forms of attack generate headlines. Fear can make investment feel urgent.

Irwin’s work suggests another way to judge progress: by the quality of the decisions an organisation is capable of making.

A mature organisation should be able to explain its cyber exposure in terms its leadership understands. It should know why particular investments have been prioritised. Its security program should reflect the scale and circumstances of the business, and its leaders should be able to defend the choices they have made.

That doesn’t make cybersecurity simple. It makes the complexity more manageable.

After more than two decades in the field, that translation has become the defining thread running through Irwin’s work at Aegis Cybersecurity: moving cyber risk out of a specialist conversation and into the wider business decisions that determine how organisations prepare, invest and respond.

To learn more about the Aegis Cybersecurity way and their services, visit aegiscyber.com.au. 

ABJ Staff

ABJ Staff

The ABJ Staff cover a variety of stories from Australia and beyond. The ABJ Staff enjoy highlighting the work of entrepreneurs, thought leaders, business owners, and creatives with branded content.

Please login to join discussion

Popular News

  • National Cabinet Agrees to New Rules for AI Data Centres

    National Cabinet Agrees to New Rules for AI Data Centres

    0 shares
    Share 0 Tweet 0
  • WA Government Appeals $150m Fortescue Native Title Compensation Ruling

    0 shares
    Share 0 Tweet 0
  • MyGov Not Working? Here’s How to Fix It Fast (2025 Guide)

    0 shares
    Share 0 Tweet 0
  • Sydney Airport Faces Two More Safety Investigations

    1 shares
    Share 0 Tweet 0
  • Australia Inflation Falls to 3.5%, But RBA Rate Hike Risk Returns

    0 shares
    Share 0 Tweet 0
  • About Us
  • Contact Us
  • Terms of Use
  • Privacy Policy
  • Disclaimer
  • Sitemap

© 2021 The ABJ -The Australian Business Journal. All Rights Reserved.

No Result
View All Result
  • Home
  • Business and Finance
  • Entertainment
  • Entrepreneurs
  • Lifestyle
  • Marketing
  • Tech

© 2021 The ABJ -The Australian Business Journal. All Rights Reserved.