27 Aug | CHICC Office Hours: Cyber-Readiness, Compliance and Data Protection with Lyal Collins, Aura Information Security
CHICC Office Hours with Aura Information Security will enable you to dive deep on practical, appropriate cyber and data security measures for your business, with a clear lens on security ROI.

Limited 45-minute, in-person sessions are available:
Date: Thursday 27 August
Time: 9:00 am – 5:00 pm
CHICC Office Hours is powered by ANDHealth and supported by the Victorian Government.
Are you developing a digital and connected health solution and wondering when and how much to invest in security, which controls and frameworks actually matter, or how to explain these decisions to your board and stakeholders?
CHICC Office Hours with Aura Information Security will enable you to dive deep on practical, appropriate cyber and data security measures for your business, with a clear lens on security ROI.
In your one on one session, you can explore the journey towards ISO compliant best practice for your company, understand your phases of cyber readiness and implementation, and unpack the role of governance, technical controls and penetration testing in validating and strengthening your security position.
These CHICC Office Hours are ideal for:
- Digital and connected health founders, product leads and CTOs handling sensitive clinical, patient or customer data
- Companies who need to demonstrate credible security measures and compliance to customers, partners, funders or regulators
- Teams integrating AI or advanced analytics into regulated healthcare products.
Topics you could explore (tailored to your company):
- Identifying and building security capabilities into your product design and operational use, so protection is baked in rather than bolted on
- Balancing innovation, AI and sensitive data, and understanding how all three can coexist with robust, compliant security controls
- When and how to demonstrate effective security outcomes to investors, boards, customers and clinical partners
- Which security implementation, testing and operational steps make sense at different stages of your roadmap, and how to phase these without derailing timelines
- Identifying your key cyber risks across data capture, processing, storage and sharing, and deciding what to do about them in practice.
Common questions we can tackle:
- What do I need to do, and when?
- How do I get clearer visibility of the risks surrounding my data, and how it’s captured, processed and stored?
- How do I test and validate that my outcomes are actually secure?
- Which frameworks or ISO standards do I need to comply with, and when?
- What strategies will help me get the best security value from my limited resources?
About Lyal Collins
Lyal Collins is a Senior Advisory Consultant based in Melbourne, working closely with organisations to transform their security posture. With more than three decades of experience in information management and cybersecurity, Lyal has held senior roles in both government and private sectors, including Chief Information Security Officer for a leading security consultancy. He specialises in PCI DSS, ISO 27001, NIST CSF, AU ISM, NZ ISM, privacy, and governance, and holds several security qualifications.
Lyal’s expertise lies in understanding business drivers and risks, then developing pragmatic, prioritised, and deliverable actions to improve security. He has extensive experience supporting startups and established businesses in the digital health sector, helping them meet compliance requirements, manage risk, and build resilient, scalable security programs.
