Why Cybersecurity Is a Leadership Obligation, Not an IT Problem

Table of Contents

Why Cybersecurity Governance Is a Director-Level Obligation

Most executives treat cybersecurity as an IT problem. That assumption is creating real legal exposure. Directors and business owners have obligations under the Corporations Act to consider cyber risk as part of their risk portfolio. Not knowing those obligations exist does not make them go away. Luke Irwin, Fractional CISO at Aegis Cyber Security, spends his time helping leadership teams understand exactly that. Watch the conversation before reading further.

Aegis Cyber Security is a Brisbane-based independent boutique firm specialising in cybersecurity governance, risk, and compliance. Founded by Luke Irwin, Aegis works primarily with small to medium businesses, delivering practical solutions tailored to each organisation’s size and risk profile. Services span fractional and virtual CISO engagements, cybersecurity audits, resilience planning, and framework implementation across ISO 27001, SOC 2, SMB1001, and Essential Eight. The firm operates free from vendor incentives or commissions, meaning its advice is shaped only by the client’s needs.

Cybersecurity Is a Governance Obligation, Not an IT Function

Irwin draws a sharp line between IT and cybersecurity. They are cousins, not twins. Asking your IT team to own cybersecurity strategy is like asking your CFO to draft legal contracts. The skill sets overlap in places, but the domain knowledge required is entirely different.

The governance, risk, and compliance lens matters because directors carry legal obligations that exist whether or not they are aware of them. “There’s no judge that likes you coming before them going, oh sorry, your Honour, I didn’t know,” Irwin said. Evidence of compliance is not optional. Saying you have something without proof is, in his words, like claiming you have a pink unicorn in your garage.

He points to frameworks scaled to business size as a practical starting point. ISO 27001 and SOC 2 are risk and scope-based, suited to larger organisations. SMB1001 is prescriptive and purpose-built for businesses under 20 seats and AUD 10 million turnover. The principle is clear: the right amount of security for the organisation’s size and risk profile. Dropping banking-grade security on a ten-person florist, as Irwin puts it, breaks them and disengages them from cybersecurity entirely.

The Misconceptions Executives Still Hold

Three misconceptions come up repeatedly in Irwin’s advisory work, and each one creates genuine risk.

The first is that cybersecurity is set and forget. Once a framework is implemented, the work is not done. The framework is a foundation to build on, not a finish line. Like a car, it requires ongoing maintenance.

The second is that small businesses are not targets. They are. Modern cybercrime is highly automated. Organised criminal groups operate with HR departments, support lines, and monthly breach quotas. They are not handpicking targets. They are firing attacks at scale and seeing what sticks. The analogy Irwin uses is the Savannah: you do not need to outrun the lion, just the person next to you. Most Australian small businesses sit at a security level of three out of ten. Most attacks are landing on fours and fives. Getting to a five or six is achievable without significant cost.

The third and most alarming is the belief that cybersecurity insurance replaces cybersecurity practice. It does not. Insurance funds a recovery attempt. It does not guarantee one. Without the right backup configurations, access controls, and business continuity planning in place, a business may not be able to recover at all, regardless of what the insurer provides.

The Vendor Independence Problem

Irwin is direct about a structural conflict that exists in much of the managed services market. When the same organisation sells, implements, manages, and then audits the security of a client’s network, it is, in his words, the student marking their own homework.

The problem is not that MSPs act in bad faith. It is that the incentive structure makes objectivity structurally difficult. If a technical issue is found that conflicts with the vendor’s standard design, does the person advising the client have the independence to say so, or do they answer to whoever signs their paycheck?

His approach at Aegis is complete independence. When a client needs a new network, he identifies what is required and introduces three vendors who can deliver it. He does not implement it himself. The separation preserves the integrity of the advice. He draws the parallel directly to legal practice: in a small law firm, two lawyers from the same firm cannot work opposing sides of the same case.

Speaking the Language of the Business

One of the clearest points Irwin makes is about communication. Technical leaders have a tendency to speak tech to executives. CVE scores and firewall configurations mean nothing to a CEO. What matters to a business leader is risk, revenue, ROI, and reputation.

A fractional CISO bridges that gap. The role involves translating security posture into business language, setting a risk appetite, defining risk tolerance, and advising technical partners on what needs to change. It is part-time by design, structured as a fixed monthly engagement, and suited to the SMB market that cannot justify a full-time CISO salary, which in the Brisbane market sits north of AUD 200,000.

Irwin frames the function not as a department of no, but as a function that finds a way. When cybersecurity says no without offering an alternative, people work around it. That creates gaps. Gaps create alerts. Alerts create burnout. The cycle compounds.

How Filament Works with B2B Technology Organisations

The challenge Irwin describes, translating technical capability into business language, sits at the centre of how Filament works with B2B technology organisations. Building content and messaging that speaks to executives means understanding risk framing, governance obligations, and how buyers in this space actually make decisions. When a cybersecurity firm can articulate its value in those terms, it earns attention from the right people.

Start the Conversation

If your organisation is navigating how to position cybersecurity capability for a leadership or procurement audience, it is worth a direct conversation. Jeremy Balius works with B2B technology firms to build the kind of messaging that reaches and resonates with executive decision-makers. No obligation, no sales pitch. Book a strategy conversation to explore what is possible.

Book a strategy conversation with Jeremy

Share this article

Table of Contents

More insights