Independent Cyber Security Advisory · Brisbane

Considered counsel for the questions that matter most.

Frenchelephant is a Brisbane-based cyber security consultancy specialising in identity, governance, and security strategy for Australian organisations navigating an increasingly contested digital landscape.

Principal Consultant Dan Boucaut — CISSP, GAICD
Based Brisbane, QLD
Engagements Australia & New Zealand
Frenchelephant logo
No. 01 Frenchelephant · MMXXVI
About

A different kind of cyber consultancy.

Most cyber programs fail not on technology, but on translation — between technical risk and board accountability, between vendor promises and operational reality. Frenchelephant exists to close that gap.

Founded by a senior practitioner with deep experience across enterprise identity, security architecture, and Australian regulatory frameworks, Frenchelephant brings vendor-independent counsel to organisations who want clarity, not catalogues.

The practice draws on more than a decade of work alongside Australian enterprises, government, and financial institutions — and on continuing engagement with the global identity and zero-trust ecosystem.

Engagements are deliberately small in number and senior in delivery. You work with the principal, not a team you've never met.

  • FoundedBrisbane, Queensland
  • PracticeIdentity security · Governance · Strategy
  • ApproachVendor-independent, senior-led
  • CoverageAustralia and New Zealand
  • PosturePragmatic. Plain-spoken. Patient.
The Principal

Who you'll work with.

No account managers, no rotating team. Every engagement is delivered by the same person — which is the point.

Dan Boucaut — Principal Consultant, Frenchelephant

Principal Consultant · Frenchelephant

Dan Boucaut

CISSP GAICD IAM Specialist Board Advisory

Dan Boucaut is a senior cyber security practitioner with more than eight years of regional leadership across the Australian and New Zealand identity and security market. His career spans enterprise security architecture, customer and partner engagement at a global cyber security vendor, and governance practice at board level.

He is a Certified Information Systems Security Professional (CISSP) and a Graduate of the Australian Institute of Company Directors (GAICD) — a combination that lets him operate fluently in both the technical and governance layers of security decision-making. He currently serves as a volunteer National Chair of an Australian not-for-profit, bringing active board-level governance experience to every client engagement.

His primary focus is identity — specifically the intersection of workforce, customer, and non-human identity with zero-trust architectures and the emerging challenge of agentic systems acting at scale on behalf of humans. He works exclusively with organisations where independent, senior counsel matters more than headcount.

Services

Four practices. One principal.

Engagements are scoped to specific outcomes — a board paper, an architecture decision, a vendor short-list, a recovery plan — rather than open-ended retainers.

— 01

Identity & Access Management Advisory

Strategy, architecture, and vendor selection for organisations re-platforming or maturing their identity estate.

  • IAM strategy & target-state architecture
  • Workforce, customer & non-human identity
  • Zero-trust and agentic identity readiness
  • Independent vendor evaluation
— 02

Security Strategy & Governance

Translating cyber risk into language that boards can govern and executives can fund.

  • Cyber strategy & uplift roadmaps
  • Board reporting and risk frameworks
  • Essential Eight & ISM alignment
  • Privacy Act & APP advisory
— 03

Vendor & Solution Evaluation

Independent assessment of identity, endpoint, and security platforms — without channel incentives.

  • Capability mapping to business outcomes
  • RFP design & response evaluation
  • Proof-of-value scoping
  • Total cost & renewal analysis
— 04

Board & Executive Advisory

Trusted counsel for directors, CEOs, and CISOs facing material cyber decisions — informed by AICD governance practice.

  • Briefing & education for boards
  • Incident readiness & post-incident review
  • Cyber risk appetite framing
  • CISO mentoring & sounding-board
Experience & Credentials

A practitioner's CV, not a brochure.

Formal credentials matter; lived experience matters more. Both are listed here.

CISSP

Certified Information Systems Security Professional — ISC². The benchmark certification for senior security practitioners.

GAICD

Graduate of the Australian Institute of Company Directors — formal grounding in director duties, governance, and board practice.

Volunteer Chair

Sustained governance experience in the Australian not-for-profit sector, including federated structures and ACNC compliance.

2017 — Present
Senior leadership · Global cyber security vendor

Regional responsibility across identity security, customer engagement, and partner ecosystem development in Australia and New Zealand.

Earlier
Enterprise security & technology roles

Architecture and consulting engagements across financial services, government, and large enterprise customers.

Ongoing
National Chair · Volunteer charitable organisation

Governance leadership of a federated Australian not-for-profit, including policy, member frameworks, and council oversight.

Insights

Notes from the field.

Occasional writing on identity, governance, and the practical reality of running cyber programs in Australia.

Work with us

Tell us what you're facing.

Every engagement starts with a conversation. This form helps us make sure the first call is useful from the outset.

Frenchelephant works best where there is a specific decision or challenge in front of you — not where the brief is to simply "improve security" without a focal point. If any of the following sound familiar, we should talk.

  • You are re-platforming your identity estate and need someone who has no interest in which vendor you choose.
  • Your board is asking for cyber risk reporting and you are unsure how to frame it without alarming or under-informing them.
  • You are evaluating an IAM vendor and want an independent view before you commit.
  • Your organisation is deploying AI agents and nobody has asked the identity questions yet.
  • You have a CISO vacancy or interim gap and need experienced counsel at pace.

Initial discussions are confidential and without obligation. Response within one business day.

New enquiry

All fields are held in confidence. We do not share your information with third parties.

By submitting this form you agree that Frenchelephant may contact you regarding your enquiry. We will not subscribe you to mailing lists or share your details.

Enquiry received.

Thank you. Dan will be in touch within one business day to arrange an initial conversation.

Start a conversation

Prefer to reach out directly?

Initial discussions are confidential and without obligation. Whether you have a specific decision in front of you or a vaguer sense that something needs to change, a thirty-minute call usually clarifies whether and how Frenchelephant can help.