Expertise
Focus regions
Offering
Factor Team
Jimmy Wong
Expert Advisor
Career
Jimmy is a global cybersecurity executive with more than 15 years of experience leading enterprise security, technology risk, governance and cyber transformation across highly regulated financial services environments in Australia and the Asia-Pacific region. He has held senior leadership positions spanning enterprise cybersecurity, technology controls, regulatory risk, third-party risk and security governance, with experience taking major cyber capabilities and transformation programs from strategy and implementation through to executive and Board reporting.
Most recently, Jimmy served as AU CISO and General Manager of Information Security, Technology Controls & Governance at AIA Australia, where he was responsible for enterprise cybersecurity, technology risk and regulatory compliance strategy and execution. His remit included enterprise service provider governance, Board and enterprise risk reporting, major program oversight and frameworks supporting the Financial Accountability Regime. He also served on AIA's AI and Data Councils, giving him a direct perspective on the intersection between emerging technology adoption, security, governance and organisational risk.
Jimmy's earlier career includes senior technology risk and regulatory leadership roles at Commonwealth Bank, AIA, NTT Security and JPMorgan Chase across Australia and Hong Kong. His experience spans cyber resilience, security-by-design, technology regulatory change, risk remediation, third-party security, audit and assurance, and complex transformation programs. He holds a first-class honours Master's degree in Executive IT Management from the University of Melbourne and is a Graduate of the Australian Institute of Company Directors (GAICD).
Role at Factor
Jimmy brings a practical enterprise perspective to the challenge of adopting emerging technologies while maintaining appropriate security, governance and accountability. His experience sits directly at the point where organisations must decide not simply whether to adopt AI and automation, but how quickly they can move while remaining operationally sustainable and appropriately controlled.
His advisory perspective is particularly relevant to organisations navigating the shift from experimentation to scaled adoption. Jimmy can help executives assess whether their people, processes, technology, governance and risk foundations are ready to absorb significant technological change, while considering how new capabilities will alter operating rhythms, workforce structures and accountability over the longer term.
Through Factor, Jimmy is well suited to executive advisory engagements, research and peer-led discussions that challenge conventional thinking around cybersecurity, AI adoption and technology risk. His approach recognises that solutions which work in one organisation or market may not translate directly to another, with organisational maturity, culture, governance structures and regulatory environments all influencing the right path forward.
Key roles Jimmy works with include: CISOs, CIOs, CTOs, Chief Risk Officers, Technology Risk Leaders, Chief Digital & AI Officers, and Board & Executive Leaders.
Previous Roles
At AIA Australia, Jimmy served as AU CISO and General Manager of Information Security, Technology Controls & Governance, leading enterprise cybersecurity, technology risk and regulatory compliance. His responsibilities included enterprise service provider management, Board and enterprise risk reporting, AI and Data Council participation, major program governance and Financial Accountability Regime-related technology frameworks.
Prior to this, Jimmy was Technology Information Security Officer at Commonwealth Bank, contributing to cyber governance, secure-by-design implementation, Essential Eight uplift, vulnerability management and data loss prevention incident management. At AIA, he previously held leadership roles across IT audit, technology risk advisory and Group Information Security Governance, including responsibility for third-party risk, security governance, cyber maturity, regulatory engagement and security-by-design.
Jimmy also spent several years with JPMorgan Chase in Hong Kong, progressing through senior technology, cyber and regulatory risk roles. His work included APAC cyber and technology controls, regulatory risk management, supervisory engagement across multiple Asian markets, major technology risk remediation and third-party vendor management.
Earlier in his career, Jimmy worked in security and infrastructure program delivery at JPMorgan Chase and Dell, building a foundation in complex technology environments, professional services and large-scale program management before progressing into enterprise cyber, risk and governance leadership.
Media Presence and Industry Contributions
Jimmy is the current President of the ISC2 Melbourne Chapter, contributing to the development of the cybersecurity profession and the broader security community. He has also taught Cyber Security Management as a tutor at the University of Melbourne, supporting the development of emerging cybersecurity talent and leadership capability.
His professional perspective is particularly relevant to the rapidly evolving relationship between cybersecurity, AI and enterprise transformation. He brings practical experience from regulated environments where organisations must balance technological opportunity with security, regulatory obligations and operational resilience.
Jimmy is also active in peer-led discussions and advisory work, with a particular interest in challenging assumptions and exploring how different organisations can approach technology adoption according to their own maturity, culture, governance and risk environment.
Leadership Philosophy
Jimmy believes the challenge of emerging technology is not simply how quickly an organisation can adopt it, but whether the organisation is prepared to absorb the change sustainably. Effective adoption requires consideration of technology, people, processes, governance and accountability together.
He advocates for a balanced approach between opportunity and risk, particularly as AI and automation begin to reshape how work is performed. Organisations need to understand where human oversight remains essential, how accountability will operate, and how the balance between machines and people will evolve as technology becomes more embedded in everyday operations.
For Jimmy, the right technology is not necessarily the most advanced technology. Strong leadership means understanding the problem that needs to be solved, selecting the appropriate level of capability and building the foundations required to sustain it. The objective is not adoption for its own sake, but technology that is secure, proportionate, commercially sustainable and genuinely useful to the organisation.
