Consulting Practice — Enterprise · Critical Infrastructure · Government

Principal-level consulting across cyber security and AI.

Aceline works with security and technology leaders who need senior, Australian-based expertise — helping you move from strategy to delivery while meeting the framework and regulatory obligations that apply to your organisation. Available for contract, statement-of-work and advisory engagements.

Six domains. One practitioner. No handoffs.

Each domain is backed by delivered engagements, not capability statements — and cyber security and AI carry equal weight across all of them.

AI Security & Governance

ACE-01

Secure AI adoption, shadow AI discovery, AI data security posture, governance aligned to Australia's Guidance for AI Adoption, Privacy Act automated decision-making readiness, and continuity for AI-dependent processes.

AI governance · Shadow AI · AI DSPM · Privacy Act ADM

Cyber Security Consulting

ACE-02

Security strategy and roadmap development, risk and maturity assessment, governance and compliance uplift, and executive advisory — framework-aligned consulting that turns obligations into a defensible, funded program of work.

NIST CSF · ISO 27001 · APRA CPS 234 · GRC

Cyber Resilience & Recovery

ACE-03

DR and BCP program development, cyber recovery capability, ransomware readiness, exercising programs and board-level resilience reporting — from business impact analysis through witnessed restore testing.

DR / BCP · ISO 22301 · Exercising · Board reporting

Human Risk Management

ACE-04

Trust-centric insider risk programs built on original practice IP — behavioural risk intelligence that protects people and information without surveillance-first thinking. Non-punitive by design, privacy-preserving by architecture — including the new human-risk surface created by everyday AI use.

BRIM · TRUST-R · Insider risk · DLP strategy · Security culture

Enterprise Security Architecture

ACE-05

Architecture frameworks, security pattern suites, Zero Trust and identity strategy, cloud and integration security standards — adopted by engineering teams, aligned to your architecture practice, and defensible in review.

Zero Trust · Identity · Cloud · OT / IEC 62443

Australian Government Assurance

ACE-06

ISM and PSPF alignment, Essential Eight uplift to target maturity, and SOCI/CIRMP compliance for critical infrastructure entities. Assurance work that anticipates the assessor.

ISM · PSPF · Essential Eight · SOCI / CIRMP

Engage the way your program needs.

Three models, one standard of delivery — the person who scopes the work is the person who does it.

M-01

Contract & interim roles

Principal consultant, security architect or program lead engagements — daily rate, direct or through recruitment partners, security-cleared work considered.

M-02

Statement of work

Defined outcomes delivered end to end: architecture frameworks, assessments, uplift programs, migration and platform security workstreams.

M-03

Executive advisory

Standing advisory to CISOs, CIOs and boards — roadmap ownership, assurance oversight, deal and RFP support, and a senior sounding board on retainer.

Delivery record

Selected engagements. Client names available in conversation where confidentiality allows.

GOVERNMENT · WA

State road authority

Designed the full enterprise Cyber Security Architecture Framework and security pattern suite — IAM, cloud, OT/ITS, integration, remote access and supply chain assurance — with Essential Eight uplift consulting and privileged access guidance.

CRITICAL MANUFACTURING

National packaging manufacturer

Delivered disaster recovery and business continuity capability for a critical manufacturing execution system — safeguarding production infrastructure of national significance.

GOVERNMENT · NSW

State justice agency

Delivered cyber transformation across the agency, spanning risk, governance and security operations uplift.

HPE · ASIA PACIFIC

Global technology enterprise

Led the APAC Integrated Risk Management capability and served as global lead for PCI DSS data centre compliance — enterprise risk, compliance and resilience programs across the region, alongside large-scale user transformation programs at HPE and IBM.

Principal

Leon Hutcheson is a principal cyber security consultant with deep senior practitioner delivery across government, critical infrastructure and enterprise — HPE as IRM Director Asia Pacific and global PCI DSS lead, IBM Asia Pacific, Sun Microsystems and CSO Group Australia.

Trusted advisor to CIOs, CISOs and executive stakeholders — known for translating complex technical issues into clear business value, and for combining strategy, governance and delivery to win and execute complex engagements with measurable outcomes.

Trained at the Massachusetts Institute of Technology (MIT) in applied generative AI, with the practice deliberately positioned where the risk now lives: the intersection of cyber security, AI adoption and human behaviour.

MIT — Applied Generative AIAI security & governance
University of Oxford (Saïd Business School)Cyber Security for Business Leaders
ISM · Essential Eight · PSPFAustralian Government frameworks
SOCI / CIRMP · ISO 22301 · NIST CSF · IEC 62443Critical infrastructure & resilience

Start a conversation

Scoping a program, a role, or a problem that crosses domains? Direct conversation, quick assessment of fit, and a straight answer on availability. Recruiters and delivery partners welcome.