Skip to the main content.

AI Security and Governance

Matt Miller, Co-Founder, CEO and Fractional CISO, Insicon Cyber

An AI security and governance specialist based in Sydney, Australia, advising boards and executive teams across Australia and New Zealand on AI risk, AI assurance and secure AI architecture. Matt sits in the fractional CISO seat, which means he is accountable for the AI decisions he recommends, not just for the advice.

Speak with Matt

Areas of expertise

Matt Miller is a cybersecurity leader who has spent more than a decade advising Australian and New Zealand organisations on security strategy, and the past several years focused specifically on how artificial intelligence changes the risk picture for boards. He co-founded Insicon Cyber in 2013 with Greg Bunt and continues to work directly in client engagements as a fractional CISO.

His work spans the full arc of enterprise AI adoption. That includes the governance question of whether an AI system should be deployed at all, the assurance question of how its behaviour is tested and evidenced, and the architectural question of how inference, data and tooling are secured once it is in production. He is a consistent advocate for treating AI risk as a business problem rather than a technology procurement exercise.

AI governance for boards and executive teams

Board level AI risk briefings, director education, AI risk appetite setting, and translating regulatory expectation into decisions a board can actually make. Matt regularly works with directors on the AICD and ASD guidance for boards, the APRA letter to industry on AI of 30 April 2026, and ASIC open letter 26-092MR of 8 May 2026.

ISO 42001 and AI management systems

Designing and implementing AI management systems aligned to ISO/IEC 42001, and preparing organisations for independent certification by an accredited certification body. Matt has led the same journey for ISO 27001 many times over, which is why he is direct with clients about what certification does and does not prove.

AI security architecture and LLM repatriation

Token economics, model routing, inference latency, local Model Context Protocol server governance, and moving inference workloads onto sovereign Australian and New Zealand infrastructure where the economics and the data classification justify it. Matt's position is that cost, latency and security in an AI stack are decided by the same architectural choices, so they should be solved together.

Trans-Tasman regulatory advisory

Essential Eight, the Australian Privacy Act, the SOCI Act, the Aged Care Act 2024 information management obligations, the New Zealand Privacy Act 2020 and the New Zealand Information Security Manual. Matt advises organisations operating on both sides of the Tasman where obligations differ and a single control set has to satisfy both.

Fractional CISO leadership

Acting as the accountable security executive for organisations that need CISO-level judgement without a full-time appointment. This is where most of Matt's AI work originates, because AI decisions arrive at the CISO desk before they arrive anywhere else.

Recognition and credentials

  • Finalist, CISO of the Year, 2026 Australian Cyber Awards
  • Co-Founder and CEO of Insicon Cyber, winner of Retail Cyber Security Partner of the Year at the 2025 Benchmark Security Awards
  • Insicon Cyber is a finalist in the Healthcare Security Partners category at the 2026 Benchmark Security Awards, and a finalist for Cyber Consulting Business of the Year, SME, at the 2026 Australian Cyber Awards
  • Insicon Cyber is a finalist in the SMB of the Year category at the AISA Cyber Security Awards 2026
  • Leads an ISO 27001 certified organisation headquartered in North Sydney with Australian data sovereignty
  • Co-founded Insicon Cyber in 2013 and remains directly involved in client engagements

Point of view

Treat cybersecurity as a business problem, not a technology one. There is always more tech you can throw at the problem, but is it solving it or shifting it?

Matt's view on enterprise AI is that most organisations bought it before they architected it. Licences went out, agents got built, staff connected tools to models, and nobody costed the token bill or drew the data path. The result is an AI estate that is expensive, opaque and difficult to evidence to a board or a regulator.

He is also sceptical of AI security positioning that relies on a single control. Traditional web application firewalls do not stop prompt injection. API security cannot defend against an attack that complies with the API specification. Native model guardrails move slowly relative to adversary technique. Defence in depth is not a slogan here, it is the only architecture that survives contact.

The Insicon Cyber approach to AI reflects that position: test it, govern it, maintain it. Assurance is continuous rather than a point-in-time certificate, and controls are proven through adversarial testing rather than asserted in a policy document.

Speaking, media and commentary

Matt is available for media commentary, conference speaking, board briefings and podcast appearances on AI security, AI governance, ISO 42001, sovereign AI infrastructure and cyber risk for Australian and New Zealand boards. For media enquiries and speaking requests, contact info@insiconcyber.com.

Work with Matt

Matt leads engagements across Board Cyber Advisory, CISO-as-a-Service, and AI Security and Governance, supported by Greg Bunt, Co-Founder, Director and Fractional CISO, and an experienced management and consultant team who deliver the work day to day.

AI Security and Governance

Test it. Govern it. Maintain it.

If your organisation is moving AI from pilot into production across Australia or New Zealand, start with an honest read of where the risk actually sits.

Engage Insicon Cyber AI Readiness Assessment