Mitch Riley-Meijer

Lead Consultant - Cyber

Mitch is a nationally recognised cyber security expert with 15 years of experience in national security, cyber risk management and major incident response.

Mitch has extensive experience in major incident response, cyber risk management and protective security. He has led responses to major cyber incidents and complex data breaches impacting millions of Australians, complex ICT environments and organisations in highly regulated industries.

Through his career in the Public Service, he has advised Cabinet Ministers, government boards, agency heads and industry leaders on the major national security issues impacting the nation and has been responsible for designing innovative solutions to those challenges.

Prior to joining the Mills Oakley team, Mitch was responsible for coordinating whole-of-government cyber incident management in the National Office of Cyber Security, where he and his team worked with Critical Infrastructure operators in the health, energy, water, transport, and grocery sectors to respond to the consequences of nationally significant cyber security incidents.

He was previously responsible for the Australian Government’s own internal security requirements, as the lead author and advisor on the Protective Security Policy Framework—the Australian Government’s capstone security policy, and as the architect of the Commonwealth Cyber Security Uplift plan. In this role, Mitch led efforts to protect Australian Government data, and previously managed the Australian Government’s Hosting Certification Framework for Data Centre and Cloud Service Providers.

Mitch started his career as an officer in the Royal Australian Navy and is a graduate of the Australian Defence Force Academy and the University of New South Wales.

* Mitch is not a legal practitioner.

Expertise

Mitch’s expertise includes:

  • Major cyber incident response
  • Data breaches and ransomware attacks
  • Post-incident recovery, analysis and reviews
  • Organisational cyber security compliance
  • Security of critical infrastructure regulation
  • Government security requirements (including IRAP, HCF, AGSVA)
  • Information systems assurance, cyber risk
  • Security compliance, auditing
  • Complex cyber security uplift
  • Countering foreign interference, supply chain security, supply chain cyber risk management
  • Cyber security incident simulations, exercises.

Recent Matters

  • Coordinated whole-of-government response to the consequences of a nationally significant ransomware attack, and subsequent data breach, impacting an Australian healthcare provider
  • Advised leading security officials, agency heads and industry bodies on operational and policy options to address significant cyber security challenges impacting national security
  • Designed and delivered cyber security simulations and response exercises for a Critical Infrastructure operator, operating a multi-tenant environment, with representation from major supply chain stakeholders, Australian Government entities and technical response firms
  • Established and managed systems assurance and cyber risk assessment capabilities for a significant Australian asset and managed ICT service provider.