The platform layer.
Purpose-built platforms that give our risk operations continuous evidence, structure and objectivity: the tooling beneath vCISO-led delivery.
A purpose-built platform for running and evidencing a cyber security program end to end: assessments, roadmaps and reporting in one place. It gives our vCISO-led delivery a consistent, auditable backbone.
Visit MyCISO →A continuous, evidence-led platform for proving trust across supply chain, people and technology, replacing static questionnaires with objective, independently validated evidence and a risk position that recalculates as things change.
Visit Tracery →Independent practices, aligned on how risk should run.
BayRisk works with a group of independent, senior cyber practices that have aligned around how we approach the operation of risk inside regulated businesses. Each is its own firm, engaged as a partner rather than staff, and each brings deep experience in the sectors where the obligations bite hardest.
Darren Shearsby leads CISO52, providing CISO and virtual CISO leadership to critical infrastructure and heavy industry. His focus is driving SOCI and Enhanced CIRMP programs through to completion: holding the senior security judgement for organisations across telco, financial services and critical infrastructure, and coordinating specialist vendors and independent reviews where the program needs them. As a BayRisk partner, Darren works on engagements that need a senior CISO to own the security position and move a SOCI program forward.
Hank Opdam runs Cyber Matters, a fractional CISO and cyber risk practice built on more than twenty-five years in technology and over a decade in senior CISO roles, including cyber leadership for a critical-infrastructure provider. His approach is pragmatic and outcome-focused, and he is as comfortable in the boardroom as the operations centre, educated in enterprise security across CISSP, CISM and SABSA, and in IEC 62443 for the operational-technology and safety domains that energy and utilities depend on. As a BayRisk partner, Hank works with energy, utilities and critical-infrastructure clients who need senior cyber leadership across both IT and OT.
Michael Wicks leads MW Cyber Consulting, a Sydney cyber governance, risk and compliance practice working with organisations accountable to regulators, boards and enterprise customers. The practice is principal-led, so clients get senior judgement on the work itself, and programs are built to hold up under regulator, auditor and board review.
He works across the tooling as well as the obligations, running GRC platform instances in live delivery and shaping vendor reporting so the output answers what a board or regulator will ask. MW Cyber operates as an independent partner to BayRisk, engaged on SOCI and CIRMP work, regulatory readiness and fractional GRC leadership.
Get the Tracery datasheet.
A concise overview of Tracery's continuous, evidence-led approach to enterprise trust management. Enter your work email and it'll download straight away.
Download the datasheet
Interested in working together?
If you're a platform or specialist whose work complements continuous risk operations, we'd like to hear from you.
Get in touch