
For much of its history, cybersecurity has been discussed in a language that makes sense to the people working directly with technology. Vulnerabilities, controls, systems and frameworks dominate the conversation.
Luke Irwin, Cybersecurity Strategist & Advisor, and Expert in Cyber Risk, GRC, BCP & DR, believes that language becomes less useful once cyber risk reaches the boardroom.
After more than 25 years working across technology, cybersecurity, risk and governance, the founder of Aegis Cybersecurity has increasingly focused his career on a different question: how can an organisation make sensible business decisions about a risk that is often difficult to understand, quantify and prioritise?
It is a question that has become more important as cybersecurity has moved beyond the remit of IT teams. Boards and executives are now expected to understand their organisation’s exposure, oversee resilience, navigate regulatory expectations and decide how much to invest in reducing risk.
For Irwin, the answer isn’t to turn executives into cybersecurity specialists. It is to make cybersecurity understandable enough that they can govern it well.
From Technology to Business Risk
Irwin’s perspective has been shaped by a career spanning enterprise technology environments, military service, cybersecurity advisory and senior security leadership.
He also holds CISSP, CISM and ISSMP credentials, but his work today is deliberately less concerned with explaining the technical mechanics of cybersecurity than with interpreting what they mean for an organisation.
Through Aegis Cybersecurity, the independent Australian advisory firm he founded, Irwin works across cyber risk quantification, governance, compliance and fractional CISO services.
Central to that work is the idea that cybersecurity decisions should be connected to the same considerations that influence other significant business investments: likelihood, consequence, priorities, available resources and expected outcomes.
Cyber risk quantification is particularly important to that approach. Rather than relying exclusively on broad labels such as “high”, “medium” or “low” risk, quantification attempts to give organisations a clearer picture of their potential exposure and the value of different interventions.
That can change the nature of a boardroom discussion.
The question becomes less about whether the business is spending enough on cybersecurity in the abstract and more about what a particular investment is expected to protect, which risks it reduces and whether that reduction justifies the cost.
The Case for Independent Advice
That philosophy has also influenced how Aegis Cybersecurity itself has been structured.
The firm doesn’t sell managed IT services, cybersecurity products or software. Its work instead centres on advisory services, including fractional CISO leadership, governance and risk management, cyber risk quantification and programs involving ISO 27001, SOC 2, SMB1001 and the Essential Eight.
The distinction matters because cybersecurity advice can easily become intertwined with technology purchasing decisions.
Aegis’ independent model is intended to separate the two. Recommendations can begin with the organisation’s risk profile and commercial priorities rather than a particular product that needs to be implemented.
It is an approach particularly relevant to small and mid-sized organisations, where the challenge is often deciding what not to do.
Few businesses have unlimited cybersecurity budgets. The practical task is determining which risks matter most, which controls are proportionate and where limited resources will have the greatest effect.
Making Cybersecurity Proportionate
Irwin has also become involved in the discussion around what appropriate cybersecurity looks like outside Australia’s largest enterprises.
One milestone came through Aegis’ work with SMB1001, a cybersecurity standard developed with small and medium businesses in mind. Aegis became the first organisation globally to achieve Diamond certification under the standard and later the first to successfully complete a re-audit.
That experience gave the firm exposure to the framework from two perspectives: advising organisations about cybersecurity standards while also having to implement and maintain one internally.
It reflects a broader theme in Irwin’s work. Compliance can provide structure, but completing a checklist is different from understanding whether an organisation has meaningfully reduced its risk.
Frameworks such as ISO 27001, SMB1001 and the Essential Eight therefore sit within a larger conversation about governance and resilience rather than functioning as the end goal.
Giving Boards Better Questions to Ask
As cybersecurity has risen on corporate agendas, Irwin has increasingly taken that conversation beyond individual client engagements.
He contributes to industry research, conferences, panels and discussions around cyber governance, risk quantification and Australia’s changing cybersecurity environment. His positioning as a speaker follows naturally from the work he does as an adviser: translating a specialised subject for people whose responsibility is to make decisions about it.
The distinction is important.
A board member doesn’t necessarily need to understand how every security control works. A CEO doesn’t need to become an expert in cyber architecture. But both need to know whether the organisation understands its most significant risks, who owns them, what is being done about them and whether those measures are working.
Those are ultimately governance questions.
A Different Measure of Cybersecurity Maturity
There is an understandable tendency for cybersecurity conversations to gravitate towards threats. Breaches are visible. New forms of attack generate headlines. Fear can make investment feel urgent.
Irwin’s work suggests another way to judge progress: by the quality of the decisions an organisation is capable of making.
A mature organisation should be able to explain its cyber exposure in terms its leadership understands. It should know why particular investments have been prioritised. Its security program should reflect the scale and circumstances of the business, and its leaders should be able to defend the choices they have made.
That doesn’t make cybersecurity simple. It makes the complexity more manageable.
After more than two decades in the field, that translation has become the defining thread running through Irwin’s work at Aegis Cybersecurity: moving cyber risk out of a specialist conversation and into the wider business decisions that determine how organisations prepare, invest and respond.
To learn more about the Aegis Cybersecurity way and their services, visit aegiscyber.com.au.
