Governance and Risk Consultant Australia
Former Chief Risk Officer for a 26-division NSW Government department, now working as a governance risk consultant to Australian boards and executive teams. Delivering ISO 27001 certification, board risk advisory, and fractional CISO leadership to organisations who need enterprise risk governance done properly — fast.
I'll reply personally within 4 business hours — no sales pitch, just a clear read on your options.
As featured in
Governance advice that's been tested where it matters most
Most cyber security consultants have never had to defend a risk decision in front of a Minister, a board, or a regulator. Dr Edward Phelps has — as Chief Risk Officer for a 26-division NSW Government department managing risk across a multi-billion-dollar portfolio, and now as a chief risk officer consultant to boards and executive teams across Australia.
If your organisation is navigating the ASD's retirement of the Essential Eight, preparing for a tender that demands ISO 27001, or simply needs an enterprise risk governance advisory partner the board can call — this is what we do.
Who this governance risk consultant works with
As a governance and risk consultant with a background spanning Australian government, mining, energy and regulated industry, Dr Edward Phelps works with organisations that need more than a generic compliance checklist. Clients typically fall into a few groups: government departments and suppliers needing a chief risk officer consultant who has actually sat inside a 26-division state department and briefed Ministers directly; mining, energy and critical infrastructure operators navigating operational technology risk and frameworks like AESCSF; and mid-market and enterprise businesses across finance, technology and professional services who need an Australian governance and risk consultant capable of translating ISO 27001, NIST CSF and APRA CPS 234 obligations into practical, board-ready governance rather than theoretical policy.
Three ways we help
ISO 27001 gap assessment
Know exactly where you stand against ISO 27001 — and what it will take to close the gap — in a fixed-price report delivered in 2–3 weeks.
Get my fixed-price quoteBoard risk register & reporting
A board-ready enterprise risk register and reporting pack, built by someone who's presented risk to Ministers and boards for over a decade.
Book my risk register buildFractional CISO — 90-day sprint
Executive security leadership without the full-time salary. A fixed 90-day engagement, delivered by a named senior governance and risk consultant.
Start my 90-day sprintAbout Dr Edward Phelps: Governance and Risk Consultant Australia
PhD in Political Science, 15+ years leading governance, risk and compliance across Australian and UK government, consulting, and industry. Former Chief Risk Officer for a NSW Government department spanning agriculture, fisheries, water, energy and resources across 26 divisions — now working as a cyber security consultant and chief risk officer consultant to boards and executive teams across Australia.
Based in Cairns, delivering nationally — remote-first, with on-site engagement where it's genuinely needed.

Ready to get your governance sorted?
Pick a moment that works — no obligation, no sales pitch, just a clear read on what you actually need.
Get in touch
Three quick fields — I'll come back to you personally within 4 business hours.
No sales pitch. Just a clear read on your options.