Factor
About
Who we help
Compare Vendors
Advisory
Platforms
Events
eLearning
InsightsPlansSign in
The team

Expertise

Cybersecurity Strategy & Governance
Government Cyber Strategy & Policy
Cyber Risk & Board Decision-Making
Cyber Assurance & IRAP
Government Procurement & Supplier Risk
Security Governance & Compliance
Information Security Management
Cyber Transformation & Resilience

Focus regions

Australia & New Zealand
Asia Pacific

Offering

Executive Advisory
Strategic Workshops
Executive Roundtables
Leadership Facilitation
Industry Research & Insights
Board & Executive Briefings

Factor Team

Shane Moffitt

Expert Advisor

Career

Shane Moffitt is a senior cybersecurity leader and Principal of SHM Advisory, with more than two decades of experience across government, professional services and cybersecurity assurance. He specialises in translating complex technical and cyber risk into strategic decisions that boards, executives and government leaders can act on.

As Deputy CISO of the Victorian Government, Shane led cybersecurity responsibilities across 1,854 public entities. He authored the Victorian Cyber Strategy and established the state’s first Cyber State Purchase Contract, helping shape how a major government jurisdiction approached cybersecurity strategy, procurement and governance.

Before this, Shane was Oceania Lead for ISO 27001 at EY, where he developed assurance capabilities across some of the region’s largest enterprises. His experience spans cyber strategy, governance, security assurance, government procurement and the relationship between organisations, suppliers and regulators.

Role at Factor

As an Expert Advisor at Factor, Shane brings a practitioner-led perspective on the strategic and governance decisions that underpin effective cybersecurity.

He advises leaders on translating cyber risk into business decisions, strengthening governance and assurance frameworks, and building greater trust between organisations and technology suppliers.

His experience working across government strategy, commercial engagements and technical assurance enables him to examine cybersecurity from both the policy and implementation perspective, helping leaders navigate the balance between security requirements, operational realities and commercial outcomes.

Shane also brings particular insight into board-level cyber decision-making, helping executives move beyond technical discussions and understand the organisational, financial and governance implications of cybersecurity risk.

Key roles: CISOs, CIOs, CTOs, CEOs, Chief Risk Officers, Government & Public Sector Leaders, Board & Risk Leaders, and Technology & Security Leaders.

Previous Roles

Shane served as Deputy CISO of the Victorian Government, with responsibility for cybersecurity across 1,854 public entities. During this time, he authored the Victorian Cyber Strategy and established the state’s first Cyber State Purchase Contract.

He previously led the Oceania ISO 27001 practice at EY, developing cybersecurity assurance capabilities across major enterprises and advising organisations on information security management and risk.

His broader career has focused on the intersection of cybersecurity strategy, technical assurance, governance and commercial engagement across complex and highly regulated environments.

Media Presence and Industry Contributions

Shane is an ASD-accredited IRAP Assessor and holds CISSP and ISO 27001 Lead Auditor certifications, as well as an MBA in Computing.

He has trained more than 200 board directors through his Cyber for Directors program, helping senior leaders develop a practical understanding of cybersecurity risk and their responsibilities as directors.

Shane is also the founder of ISM Workbench, a platform designed to streamline the mechanics of IRAP and ISM assessment.

Leadership Philosophy

Shane believes the fundamental cybersecurity challenge is no longer simply identifying technical vulnerabilities, but ensuring organisations have the right people, processes and technology to manage risk effectively.

His approach focuses on making cybersecurity a strategic leadership issue rather than solely a technical or compliance function.

He brings a pragmatic perspective on building secure organisations, strengthening trust between government and suppliers, and ensuring cybersecurity decisions are proportionate to business risk and grounded in practical outcomes.

Get in touch

How can we help you today?

Get in touch

Tell us what you’re after and we’ll point you to the right place.

1 / 4

Your details

All fields are required.