Jamie Norton - Global CISO and Cyber Governance Expert
NACD.DC GAICD FGIA

Jamie Norton

CISA CISM CISSP CGEIT CIPM
Global CISO • Non-Executive Director • Cyber Expert

I bridge the gap between cybersecurity, AI governance, emerging technology risks, and corporate boardroom strategy. By transforming robust governance into a catalyst for innovation, my focus is establishing the resilient strategies required to navigate complex geopolitical security threats and secure critical institutions through 2030 and beyond.

For media enquries and speaking engagement requests, please contact me via the Engage button below

Connect on LinkedIn ExecAtlas Board Profile Engage
The Perspective

"As we face escalating cyber threats and rapid developments in AI and technology, the role of our profession has never been more vital."

As technology accelerates, from the pervasive integration of AI in boardrooms expected by 2027, to the looming reality of geopolitical tension, Frontier-AI and post-quantum cryptography, organizations face an unprecedented volume of risk. My goal is to ensure that critical global institutions do not merely survive these events, but build enduring resilience and public trust.

Over a 25-year career that began in the Intelligence Community, I have navigated complex global threat landscapes. I have served as the Chief Information Security Officer (CISO) for three of the world’s most consequential organizations: the Australian Securities and Investments Commission (ASIC), the Australian Taxation Office (ATO), and the World Health Organization (WHO).

This breadth shapes how I engage at board level. The organisations navigating AI adoption and emerging technology risk most effectively aren't necessarily the best resourced — they're the ones with clear governance structures, well-tested strategic risk appetite, and a leadership culture that prioritizes innovation as vital to delivering meaningful growth and value.

Keynotes & Advocacy

Speaking & Public Discourse

Delivering strategic foresight at the intersection of technology and corporate governance.

Audio & Broadcasting

Media & Podcasts

KBI
KBKAST Deep Dive

Quantum Computing Preparedness

In Episode 328, Jamie Norton and Rob Clyde break down the ISACA global survey on organizational quantum roadmaps and how cyber professionals must prepare for the post-quantum transition.

Listen on Apple
BoC
Business of Cyber

Discussing Security with a Non-Technical Audience

Drawing on his experience as CISO for the ATO and WHO, Jamie discusses strategies for presenting complex, highly-technical security concepts to non-technical executive audiences and boards.

Stream Episode
Strategic IP & Insights

Executive Perspectives

Original perspectives on systemic governance failures, organizational resilience, and leading through crisis.

Executive Strategy

Governance Frameworks

Translating cyber and AI threats into quantifiable business risk in alignment with global regulatory and governance standards.

NIST Cybersecurity Framework (CSF 2.0)

Aligning the new 'Govern' function directly to corporate oversight, ensuring cyber risk is managed alongside financial and legal risk.

NIST AI Risk Management (AI RMF)

Establishing trustworthy AI adoption strategies for the enterprise, mapping generative AI capabilities against data privacy and compliance guardrails.

APRA CPS 234

Advising financial and regulated entities on maintaining information security capabilities commensurate with their specific vulnerabilities and threats.

ISO/IEC 27001 & 27002

Deploying internationally recognized best practices for Information Security Management Systems (ISMS) across complex, multi-jurisdictional organizations.