Cyber Risk Advisors
Cyber Risk Advisors is a boutique Australian cyber security and technology risk advisory firm founded in 2018, serving boards, C-suite executives, and transformation program leaders in financial services and critical infrastructure with governance, management, crisis risk, and privacy advisory services.
- Company typePrivate
- Founded2018
- HeadquartersPort Melbourne, Australia
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Cyber Risk Advisors does
Cyber Risk Advisors (CRA) is a privately held, boutique cyber security and technology risk advisory firm founded in 2018 by Michael Trovato, former EY Asia Pacific, Oceania, and Financial Services Organisation Cyber Security Leader. The firm is headquartered in Melbourne with additional full-time offices in Sydney and Brisbane following its 2018 merger with IIS Partners, and it serves boards, board risk committees, and C-suite executives (CEOs, CIOs, CISOs, CROs) along with transformation program leaders, primarily in Australia's financial services and critical infrastructure sectors. Core services span four areas: Governance (risk identification, assessment, and remediation planning for regulatory and policy compliance), Management and Transformation (security program design, capability assessments, and gap analyses), Crisis Risk Management (rapid-deployment advisory and seated-executive recovery leadership), and Privacy and Data Protection (delivered through the IIS Partners brand).
CRA has no proprietary software platform or productised technology; the offering is pure professional services delivered by senior advisors averaging 20+ years of experience, leveraging the founder's 30-year track record spanning EY, National Australia Bank, KPMG, MasterCard International, and Salomon Brothers. Revenue is generated through negotiated enterprise advisory engagements structured as multi-year contracts, with go-to-market executed via direct advisory relationships, the founder's professional network (ISACA Melbourne, Australian Information Security Association, auDA board role), and a hub function introducing market-leading US and Israeli cyber security solutions to Australian clients. The firm is a strategic collaborator with the Australian Government Cyber Security Growth Centre (AGCSC) and operates with no disclosed institutional capital, no public revenue figures, and undisclosed headcount consistent with a boutique consultancy.
Cyber Risk Advisors firmographics
Firmographics- Name
- Cyber Risk Advisors
- Legal name
- Cyber Risk Advisors
- Website
- https://cyber-risk-advisors.com
- Company type
- Private
- Founded year
- 2018
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Cyber Risk Advisors is a boutique Australian cyber security and technology risk advisory firm founded in 2018, serving boards, C-suite executives, and transformation program leaders in financial services and critical infrastructure with governance, management, crisis risk, and privacy advisory services.
- Ownership category
- akta.pro rank
Cyber Risk Advisors industry classification
Industry- Product category
- Cyber Security Advisory Services
- akta.pro primary industry
- Enterprise Security Strategy & Program Advisory (BPAKADAA)
- akta.pro secondary industries
- Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG), Executive/Board Security Advisory & Risk Briefings (BPAKADAK), Cybersecurity & Identity Consulting (BPAHAEAG), Privacy, Data Protection & Cyber Governance (GRC) (BPAHAFAF), Security Consulting, Risk Assessment & Security Program Design (BPABAMAE)
Keywords
Where Cyber Risk Advisors is headquartered
LocationHeadquarters
- HQ city
- Port Melbourne
- HQ country
- Australia
- HQ region
- Oceania
Offices3 records
Markets served
Cyber Risk Advisors business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Others
Revenue model
- Advisory and Consulting Services: Professional services revenue generated through cyber security and technology risk advisory engagements with boards, executive management, and transformation program leaders. Services include governance consulting, management and transformation advisory, crisis risk management, and privacy services. Engagement models appear to be project-based or retainer arrangements.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Enterprise advisory engagements |
Go-to-market motion2 records
Distribution channels1 record
Marketing channels5 records
Cyber Risk Advisors product offering
Product offeringCore offering
Cyber Risk Advisors is a boutique cyber security and technology risk advisory firm serving boards, board risk committees, executive management (CEOs, CIOs, CISOs, CROs), and transformation program leaders. It delivers advisory engagements across four core areas: Governance, Management and Transformation, Crisis Risk Management, and Privacy and Data Protection (via the merged IIS Partners brand). The firm also operates as a hub introducing market-leading US and Israeli cyber security solutions to Australian clients.
Product overview
Cyber Risk Advisors is a boutique cyber security and technology risk advisory consultancy serving boards, board risk committees, executive management (CEOs, CIOs, CISOs, CROs), and transformation program leaders. The firm operates as a single integrated advisory offering supplemented by IIS Partners (merged entity, 2018) for privacy services. Core service areas include Governance, Management and Transformation, Crisis Risk Management, and Privacy and Data Protection. The firm also acts as a hub connecting Australian clients to market-leading US and Israeli solutions across Network Protection, Phishing, Deception and Evasion, and Isolation categories.
Differentiator
Problem solved
Functional benefit
Products and services
- Governance
- Management and Transformation
- Crisis Risk Management
- Privacy and Data Protection
Quantifiable outcome
- The average cost of a data breach in Australia reached AUD $4.26 million (IBM 2024 Cost of a Data Breach Report), representing a 27% increase since 2020
- +3 more outcomes
Companies that use Cyber Risk Advisors
Customer profileNamed customers4 records
Segments6 records
Ideal customer profiles3 records
Cyber Risk Advisors technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Cyber Risk Advisors partnerships and signals
Strategic signalPartnerships
Two partnerships are on record, tiered core.
- IIS PartnerscoreEffective 1 January 2018, Cyber Risk Advisors merged with IIS Partners based in Sydney. This merger further strengthened CRA, provided critical privacy capabilities for clients, and established a full-time presence in Sydney and Brisbane, while complementing industry competencies. The merger also established a full-time presence in Melbourne for IIS. The entity continues to trade under the IIS brand.
- Australian Government Cyber Security Growth Centre (AGCSC)coreCyber Risk Advisors works with the industry-led Australian Government Cyber Security Growth Centre (AGCSC) to strengthen Australia's cyber security industry and help build national capabilities. The goal of the Centre is to ensure Australia is a global industry leader, able to export products and services while helping Australian businesses and governments address growing cyber-crime threats.
Scale indicators4 records
Recent moves6 records
Expansion highlights5 records
Cyber Risk Advisors competitors and assessment
Company assessmentBroad incumbents
- Trustwave: Global cyber security services firm offering advisory, managed detection and response, and consulting to enterprise clients. Comparable to CRA in delivering cyber governance and risk advisory, particularly to financial services and critical infrastructure organisations.
- Deloitte (Cyber Risk Services): Global Big 4 firm offering enterprise cyber strategy, GRC, transformation, and incident response as part of its wider advisory portfolio. Directly competes with CRA for large enterprise cyber mandates, particularly in financial services and critical infrastructure.
- BAE Systems Digital Intelligence (Applied Intelligence): Global cyber security and intelligence firm offering advisory, threat detection, and managed security services to governments and critical infrastructure. Comparable to CRA in serving board-level cyber governance and risk advisory needs in regulated, high-assurance environments.
- PwC (Cyber and Privacy): Global Big 4 firm offering enterprise cyber security, privacy, and risk advisory as part of its wider consulting practice. Competes with CRA for large enterprise cyber transformation and governance mandates, particularly in regulated industries.
- EY (Cyber Security Advisory): Global Big 4 firm where CRA's founder previously led Asia Pacific cyber security for a decade. Offers enterprise cyber strategy, GRC, and transformation advisory as part of its wider consulting portfolio — a direct competitor for large enterprise cyber mandates, particularly where CRA's founder-pedigree messaging is leveraged.
- KPMG (Cyber Security Services): Global Big 4 firm (and former employer of CRA's founder) offering cyber security strategy, governance, and transformation advisory. Comparable to CRA in serving enterprise boards and CISOs with cyber risk advisory, and competes for mandates in the same financial services and critical infrastructure segments.
Direct peers
- Mandiant (Google Cloud): Specialist cyber security advisory firm (now part of Google Cloud) with deep incident response, threat intelligence, and cyber governance advisory capabilities. Comparable to CRA in serving CISOs and boards with strategic cyber advisory, though Mandiant operates globally at much greater scale.
- Protiviti: Global consulting firm specialising in risk, compliance, and internal audit, with a strong cyber security practice serving boards and C-suite. Comparable to CRA in delivering independent cyber risk advisory and governance services to enterprise clients, with a similar boutique-feel positioning within a larger firm.
- CyberCX: Australia's largest pure-play cyber security services firm, offering advisory, managed security, and incident response to enterprise clients including critical infrastructure. Directly comparable to CRA in targeting Australian enterprise boards and CISOs with cyber governance and risk advisory services, though at significantly greater scale.
Regional players
- Loop Secure: Australian cyber security advisory and managed services firm serving mid-market and enterprise clients. Comparable to CRA as a regional Australian cyber advisory competitor targeting boards and executive management, though with a stronger managed services component.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat3 records
Key risks5 records
Key highlights6 records
Customer concentration
Cyber Risk Advisors financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cyber Risk Advisors leadership team
Management profileNumber of profiles
Profiles1 record
Cyber Risk Advisors funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cyber Risk Advisors M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cyber Risk Advisors
What does Cyber Risk Advisors do?
Cyber Risk Advisors is a boutique cyber security and technology risk advisory firm serving boards, board risk committees, executive management (CEOs, CIOs, CISOs, CROs), and transformation program leaders. It delivers advisory engagements across four core areas: Governance, Management and Transformation, Crisis Risk Management, and Privacy and Data Protection (via the merged IIS Partners brand). The firm also operates as a hub introducing market-leading US and Israeli cyber security solutions to Australian clients.
Is Cyber Risk Advisors a public or private company?
Cyber Risk Advisors is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Cyber Risk Advisors founded?
Cyber Risk Advisors was founded in 2018. It employs 1 to 10 people.
Where is Cyber Risk Advisors based?
Cyber Risk Advisors is headquartered in Port Melbourne, Australia, in the Oceania region.
How does Cyber Risk Advisors make money?
One revenue line is on record: advisory and Consulting Services.
Who are Cyber Risk Advisors's main competitors?
Broad incumbents on record are Trustwave, Deloitte (Cyber Risk Services), BAE Systems Digital Intelligence (Applied Intelligence), PwC (Cyber and Privacy), EY (Cyber Security Advisory) and KPMG (Cyber Security Services). Direct peers are Mandiant (Google Cloud), Protiviti and CyberCX. Loop Secure is listed as a regional player.
Does Cyber Risk Advisors have an API?
No public API is recorded for Cyber Risk Advisors.
What industry is Cyber Risk Advisors in?
Cyber Risk Advisors's product category is Cyber Security Advisory Services. Its primary akta.pro industry code is BPAKADAA, Enterprise Security Strategy & Program Advisory, with a secondary code of BPAKADAG, Security Governance, Risk & Compliance (GRC) Advisory.