About

One person. 25 years' experience. No handover.

Cyber Wave is deliberately just me: the person who scopes the work, does it, and sits in the room.

Bill Robson

I'm Bill Robson. I started Cyber Wave because I've spent 25 years watching security advice get delivered by whoever was available rather than whoever was right, and watching clients pay for seniority they never actually received.

So Cyber Wave is deliberately just me. When you engage a Fractional CISO retainer or book an incident response exercise, I'm the person who scopes it, does the work, and sits in the room. There's no bench to delegate to, which is the point.

Where the experience comes from

Two things from those years shape how I work now.

The first is that I know how attacks actually unfold, because I've run them. When I design an incident response scenario, the attack chain is one I've either executed or investigated. That's why the exercises hold up under scrutiny from technical teams. If a scenario isn't plausible, your engineers will say so within ten minutes, and they'd be right to.

The second is translation. A large part of my career has been explaining highly technical findings to partners and executives without a security background, in terms that changed what they decided to do. That skill turned out to be most of a CISO's job. Your board doesn't need to understand the vulnerability. It needs to understand the exposure, the obligation and the decision in front of it.

I've worked across offensive and defensive security, governance and compliance, and the resource-constrained end of the market where security has to be practical or it doesn't happen at all.

How I work

Three principles

Practical over theoretical

I'd rather close three real gaps than document thirty. Most organisations I meet don't need a bigger risk register. They need the top five items actually fixed.

Honest, even when it costs me

If a retainer isn't the right answer, I'll say so in the first call. If you'd be better served by an MSP, by hiring internally, or by doing nothing for another six months, that's what I'll tell you.

Independent by design

No parent company, no reseller agreements, no vendor commissions. It's the reason I can recommend against buying something.

Who I work with

Companies of roughly 50 to 500 people, usually in one of three situations:

  • Carrying real regulatory weight: APRA, the SOCI Act, Essential Eight or the Privacy Act.
  • Running modern cloud or serverless infrastructure where traditional security advice doesn't quite fit.
  • Growing fast enough that security has become a board question before anyone had time to build the function.

The common thread is constraint. These organisations can't throw headcount at the problem and need the thinking to be right the first time.

Outside work

I dive wrecks, mostly deep ones, beyond recreational limits. Every dive is a risk exercise before it's anything else, and that's the whole argument for incident response exercises. The 2am breach is the dive at depth: whatever your team has rehearsed is what they'll do, because they won't invent it on the spot.

Cyber Wave Consulting is an Australian cyber security consultancy founded by Bill Robson and based in Victoria, Australia. We are not affiliated with Cyber Wave LLC (Longwood, Florida), cyberWAVE (United Kingdom), CyberWave Information Security, or any other similarly named business.

Let's talk

Book a free 30-minute call to see whether I'm the right fit for you.