# Kode-1 > Kode-1 is a digital technology advisory firm for the modern enterprise — partner-led across strategy, systems, delivery, and resilience. Head office: Level 2, 161 Collins St, Melbourne VIC 3000, Australia; also 68 Circular Road, #02-01, Singapore. ABN 42 653 469 544. Contact: partner@kode-1.com · https://www.kode-1.com/contact ## What we do - [Strategy & Architecture](https://www.kode-1.com/what-we-do/strategy-architecture): Set direction. Technology strategy that shapes the next horizon — business ambition translated into target architectures, investment cases, and operating models. - [Systems & Platforms](https://www.kode-1.com/what-we-do/systems-platforms): Build the systems that run the modern enterprise — platform engineering across cloud, data, integration, and modernised applications, resilient-by-design from day one. - [Delivery & Adoption](https://www.kode-1.com/what-we-do/delivery-adoption): Land outcomes, then keep improving them. Program leadership, change and adoption, value realisation, and ongoing optimisation. - [Risk, Resilience & Assurance](https://www.kode-1.com/what-we-do/risk-resilience-assurance): A practice principle, not a fourth pillar — operational resilience, cyber, privacy, regulatory, and AI governance designed into every engagement, and available standalone. ## Capabilities - [Data](https://www.kode-1.com/capabilities/data): Data governance and data strategy consulting — awareness, control, platforms, and governance that make data a board-ready asset. Partner-led. - [AI](https://www.kode-1.com/capabilities/ai): AI governance and AI strategy consulting across the full arc — strategy, engineering, adoption, and governance under ISO 42001 and the NIST AI RMF. - [Cyber](https://www.kode-1.com/capabilities/cyber): Cyber resilience and security strategy consulting — designed in, not bolted on. CPS 234/230, SOCI, Essential Eight. Assurance boards can trust. - [Infrastructure](https://www.kode-1.com/capabilities/infrastructure): Cloud strategy and migration advisory — landing zones, platform engineering, integration, and modernisation for regulated Australian workloads. ## Industries - [Financial Services](https://www.kode-1.com/industries/financial-services): APRA-regulated banks, insurers, and superannuation funds modernising under CPS 234 and CPS 230. Cloud foundations, data platforms, operational resilience. - [Critical Infrastructure](https://www.kode-1.com/industries/critical-infrastructure): Energy, water, transport, and other critical infrastructure operators working under SOCI Act/CIRMP obligations. Risk management, secure-by-design platforms, AI governance. - [Healthcare](https://www.kode-1.com/industries/healthcare): Hospitals, aged care, and health services modernising under intensifying privacy, security, and digital-health obligations. Resilient platforms, defensible privacy, governed AI. - [Insurance](https://www.kode-1.com/industries/insurance): General, life, and health insurers modernising claims, underwriting, and core platforms under APRA prudential obligations. Resilient-by-design, governed AI. - [Government](https://www.kode-1.com/industries/government): Federal, state, and local government agencies modernising citizen services and legacy estates under the PSPF, the ISM, and data-sovereignty obligations. - [Mining](https://www.kode-1.com/industries/mining): Miners, METS providers, and resources operators converging OT and IT — autonomous operations, safety-critical systems, and climate disclosure built on engineered foundations. ## Case studies - [From data-risk findings to action in twelve weeks.](https://www.kode-1.com/case-studies/data-risk-assessment-remediation): From findings to action in twelve weeks — data discovery and classification, exposure remediation, least-privilege realignment, and retention. A Kode-1 case study. - [From the server room to a private cloud.](https://www.kode-1.com/case-studies/on-premises-to-private-cloud-healthcare): How Kode-1 moved a national healthcare distribution company from on-premises infrastructure to a private cloud — sequenced, verified, no interruption. - [Data governance that leadership could finally see.](https://www.kode-1.com/case-studies/data-governance-superannuation): How Kode-1 helped one of Australia's largest pension payers build a scalable data governance program — operating model, policies, standards, and platform. - [A cyber strategy the whole business could execute.](https://www.kode-1.com/case-studies/cyber-strategy-roadmap-resources): How Kode-1 brought structure to cyber risk management for an ASX-listed resources company — aligned stakeholders, a clear roadmap, and practices that stuck. - [Guardrails that let AI move fast, safely.](https://www.kode-1.com/case-studies/ai-security-guardrails-marketplace): How Kode-1 built an AI security program — governance, guardrails, SOC readiness, and AI red-teaming — that let generative AI scale safely. - [One identity program across many brands.](https://www.kode-1.com/case-studies/identity-strategy-multi-brand): How Kode-1 unified password management, privileged access, and identity governance across a diversified ASX-listed services company. ## Insights - [CPS 230 is not a compliance project](https://www.kode-1.com/insights/cps-230-is-not-a-compliance-project): APRA's operational resilience standard is written as an outcome, not a checklist. Treating it as paperwork produces paperwork — treating it as an engineering problem produces resilience. - [Where AI earns its place](https://www.kode-1.com/insights/where-ai-earns-its-place): Boards are not short of AI ambition or use-case lists. The missing artefact is a fundable path — a prioritised view of where AI earns its place, what it costs to run properly, and the governance that makes it defensible. - [Your AI is only as good as your data platform](https://www.kode-1.com/insights/ai-is-only-as-good-as-your-data-platform): Model quality has a ceiling, and it isn't the model. Lineage, access, and ownership — the unglamorous disciplines of the data platform — decide whether AI can be trusted at scale. - [FinOps when the regulator is watching](https://www.kode-1.com/insights/finops-when-the-regulator-is-watching): In a regulated enterprise, some of your most expensive architecture exists because a regulator expects it. Cost discipline starts with knowing which dollars are the floor and which are waste. - [What an AI interaction costs](https://www.kode-1.com/insights/what-an-ai-interaction-costs): AI spend has reached board level, but total spend is the wrong number to govern. The unit a board can actually manage is the cost of an interaction — measured honestly, governance premium included. - [Agentic AI, without the hype](https://www.kode-1.com/insights/agentic-ai-without-the-hype): An agent that acts is not a chat interface — it is an operational actor with access, permissions, and failure modes. Where agents earn their place in a regulated enterprise. - [Why your board still can't see its technology risk](https://www.kode-1.com/insights/why-your-board-cant-see-its-technology-risk): Cyber gets agenda time. AI gets a working group. The digital estate underneath them — where operational risk actually accumulates — appears on no agenda at all. That is a visibility problem, and boards can fix it. - [Fragmented systems are a competitive disadvantage your competitors can see](https://www.kode-1.com/insights/fragmented-systems-competitive-disadvantage): From the inside, fragmentation feels like history — every system had a reason. From the outside it reads as slow quotes, inconsistent service, and offers that arrive late. Customers feel it. Competitors count on it. - [The data question your board should be asking](https://www.kode-1.com/insights/the-data-question-your-board-should-be-asking): Not "are we doing something with AI" but "which of our critical decisions run on data we trust — and which only look like they do." One question separates the data-driven enterprise from the data-decorated one. ## Playbooks - [The AI governance operating model](https://www.kode-1.com/playbooks/ai-governance-operating-model): Decision rights, policy hierarchy, and operating cadence — the working parts of AI governance that survives scrutiny, mapped to ISO 42001 and the NIST AI RMF. - [AI evidence and audit readiness](https://www.kode-1.com/playbooks/ai-evidence-audit-readiness): The evidence architecture to build before the auditor, regulator, or board asks — what to capture at design, deploy, and run, and how to rehearse the questions. - [Leading AI-fluent teams](https://www.kode-1.com/playbooks/leading-ai-fluent-teams): The four adoption failure modes, work design that builds fluency, and policy that enables adoption instead of killing it. - [The data governance operating model](https://www.kode-1.com/playbooks/data-governance-operating-model): Ownership, classification, lineage, and cadence — the working parts of data governance that make analytics, AI, and privacy obligations defensible. - [Finding and securing sensitive data](https://www.kode-1.com/playbooks/finding-and-securing-sensitive-data): You cannot protect what you have not found. Discovery, classification, access right-sizing, and monitoring — the posture discipline for the data that matters most. - [Data breach readiness](https://www.kode-1.com/playbooks/data-breach-readiness): The NDB scheme gives you thirty days to assess and no time to prepare. The runbook, the evidence, and the rehearsal — built before the day they are needed. - [Cyber awareness that changes behaviour](https://www.kode-1.com/playbooks/cyber-awareness-that-changes-behaviour): Completion rates measure compliance, not risk. Treating the human layer as a managed risk — measured behaviour, targeted intervention, and a culture where reporting is safe. - [Securing identity end to end](https://www.kode-1.com/playbooks/securing-identity-end-to-end): Attackers log in more often than they break in. Closing the MFA coverage gaps, governing the identities that aren't people, and cutting off lateral movement. - [Bringing your APIs under management](https://www.kode-1.com/playbooks/bringing-apis-under-management): APIs are the connective tissue of the enterprise — and most estates cannot list theirs. The catalogue, the gateway, the lifecycle, and the AI traffic now flowing through all of it. - [Securing AI systems](https://www.kode-1.com/playbooks/securing-ai-systems): AI is software with new failure modes — poisoned models, injected prompts, leaking context, agents off the leash. The attack surface, and the disciplines that hold it. - [Building security into software delivery](https://www.kode-1.com/playbooks/building-security-into-software-delivery): Vulnerabilities are cheapest at the keyboard. Scanning in the pipeline, prioritising by real risk, keeping developers in flow — and holding the line as AI writes more of the code. - [Seeing the network you actually run](https://www.kode-1.com/playbooks/seeing-the-network-you-run): You defend what you can see — and most estates cannot see sideways. East-west traffic, encrypted flows, and the network as the ground truth detection stands on. ## Campaigns - [Cybersecurity Awareness Month, without the box-ticking.](https://www.kode-1.com/campaigns/cybersecurity-awareness-month): A ready-to-run Cybersecurity Awareness Month pack for security and technology leaders — briefings, posters, and role-based cards, curated by Kode-1. ## Company - [About](https://www.kode-1.com/about): Who we are and what we believe. - [How we work](https://www.kode-1.com/how-we-work): Six principles that hold across every engagement. - [Security](https://www.kode-1.com/security): How Kode-1 approaches its own security. - [Contact](https://www.kode-1.com/contact): Talk to a partner. One-business-day response.