Independent Cyber Security Advisory · Brisbane

Considered counsel for the questions that matter most.

Frenchelephant is a Brisbane-based cyber security consultancy specialising in identity, governance, and security strategy for Australian organisations navigating an increasingly contested digital landscape.

Principal Consultant Dan — CISSP, GAICD
Based Brisbane, QLD
Engagements Australia & New Zealand
Frenchelephant logo
No. 01 Frenchelephant · MMXXVI
About

A different kind of cyber consultancy.

Most cyber programs fail not on technology, but on translation — between technical risk and board accountability, between vendor promises and operational reality. Frenchelephant exists to close that gap.

Founded by a senior practitioner with deep experience across enterprise identity, security architecture, and Australian regulatory frameworks, Frenchelephant brings vendor-independent counsel to organisations who want clarity, not catalogues.

The practice draws on more than a decade of work alongside Australian enterprises, government, and financial institutions — and on continuing engagement with the global identity and zero-trust ecosystem.

Engagements are deliberately small in number and senior in delivery. You work with the principal, not a team you've never met.

  • FoundedBrisbane, Queensland
  • PracticeIdentity security · Governance · Strategy
  • ApproachVendor-independent, senior-led
  • CoverageAustralia and New Zealand
  • PosturePragmatic. Plain-spoken. Patient.
Services

Four practices. One principal.

Engagements are scoped to specific outcomes — a board paper, an architecture decision, a vendor short-list, a recovery plan — rather than open-ended retainers.

— 01

Identity & Access Management Advisory

Strategy, architecture, and vendor selection for organisations re-platforming or maturing their identity estate.

  • IAM strategy & target-state architecture
  • Workforce, customer & non-human identity
  • Zero-trust and agentic identity readiness
  • Independent vendor evaluation
— 02

Security Strategy & Governance

Translating cyber risk into language that boards can govern and executives can fund.

  • Cyber strategy & uplift roadmaps
  • Board reporting and risk frameworks
  • Essential Eight & ISM alignment
  • Privacy Act & APP advisory
— 03

Vendor & Solution Evaluation

Independent assessment of identity, endpoint, and security platforms — without channel incentives.

  • Capability mapping to business outcomes
  • RFP design & response evaluation
  • Proof-of-value scoping
  • Total cost & renewal analysis
— 04

Board & Executive Advisory

Trusted counsel for directors, CEOs, and CISOs facing material cyber decisions — informed by AICD governance practice.

  • Briefing & education for boards
  • Incident readiness & post-incident review
  • Cyber risk appetite framing
  • CISO mentoring & sounding-board
Experience & Credentials

A practitioner's CV, not a brochure.

Formal credentials matter; lived experience matters more. Both are listed here.

CISSP

Certified Information Systems Security Professional — ISC². The benchmark certification for senior security practitioners.

GAICD

Graduate of the Australian Institute of Company Directors — formal grounding in director duties, governance, and board practice.

Volunteer Chair

Sustained governance experience in the Australian not-for-profit sector, including federated structures and ACNC compliance.

2017 — Present
Senior leadership · Global cyber security vendor

Regional responsibility across identity security, customer engagement, and partner ecosystem development in Australia and New Zealand.

Earlier
Enterprise security & technology roles

Architecture and consulting engagements across financial services, government, and large enterprise customers.

Ongoing
National Chair · Volunteer charitable organisation

Governance leadership of a federated Australian not-for-profit, including policy, member frameworks, and council oversight.

Insights

Notes from the field.

Occasional writing on identity, governance, and the practical reality of running cyber programs in Australia.

Identity

Agentic identity: what every board should be asking now.

As autonomous agents move from demo to deployment, the identity questions shift from "who is using this" to "what is acting on whose behalf, and with what authority."

Coming soon · 6 min read
Governance

Beyond Essential Eight: maturity that the board can actually see.

The Essential Eight is necessary but rarely sufficient as a board narrative. A short note on the metrics that translate, and the ones that quietly mislead.

Coming soon · 8 min read
Market

The Australian identity market in 2026.

A practitioner's view of the platforms, partners, and patterns shaping identity programs across Australian enterprises this year.

Coming soon · 10 min read
Start a conversation

If something on this page resonated, the next step is a conversation.

Initial discussions are confidential and without obligation. Whether you have a specific decision in front of you or a vaguer sense that something needs to change, a thirty-minute call usually clarifies whether and how Frenchelephant can help.