PM247 Consulting · Melbourne, Australia

Independent advisory for CIOs, CISOs, and executives who need someone genuinely on their side.

No agency markup. No junior handoffs. No conflicts of interest. Senior practitioners, regulated sectors, fixed-fee engagements — from scoping call to final deliverable.

Why PM247 Consulting was established

A pattern observed across 20+ years.
A practice built to interrupt it.

Over more than 20 years of independent consulting, the same failure pattern appeared with enough consistency to become a diagnosis. Projects that appeared to be progressing well would surface critical problems during UAT or at rollout. The business would examine what had been built and conclude that the solution was not fit for purpose.

The failure rarely started at UAT. It started in the analysis phase — weeks or months earlier, when teams under pressure to show delivery momentum compressed or skipped problem definition. Requirements were written before the problem was understood. Solutions were designed before requirements were validated. PM247 was established to interrupt that pattern — bringing structured problem-solving, financial rigour, and the sector depth of 20 years of regulated-sector delivery in Australia.

The founding principle

"If I had an hour to solve a problem, I'd spend 55 minutes thinking about the problem and 5 minutes thinking about solutions."

— Albert Einstein

The financial dimension

Most projects track planned spend. Very few track actuals against plan with the rigour required to see a problem forming early enough to act. Applied Finance expertise means PM247 brings the financial management discipline that gives project directors early warning — not post-mortem visibility.

What PM247 offers

Three service lines.
One independent practice.

Senior practitioners with regulated-sector depth. Every engagement scoped and priced before work begins.

🛡️
Cyber Governance

Cyber Governance & Compliance

Essential Eight assessment, IS audit, governance framework design, SOCI Act advisory, and cyber risk translated to dollar exposure for boards and executives.

📋
Project Advisory

Project Audit & Recovery

Independent health checks, vendor performance audits, recovery roadmaps, and program governance design. Fixed fee, written findings, no conflicts of interest.

🎯
Capability Uplift

Delivery Capability Uplift

Structured uplift for BA and PM teams — working directly on your live project artefacts, in your sector, improving the quality of what your team produces before it becomes a problem.

Ready to start a conversation?

Tell us what you're dealing with. We'll tell you honestly whether PM247 is the right fit.

Our Services → Let's discuss your project
What PM247 offers

Services & Engagements

Three service lines. Every engagement begins with a no-cost scoping conversation. Scope confirmed in writing before work commences.

Cyber Governance Under Construction

Cyber Governance & Compliance

This service offering is currently being documented and will be available shortly. PM247 provides Essential Eight assessment, IS audit, governance framework design, SOCI Act advisory, and cyber risk quantification for boards and executives.

For enquiries about cyber governance advisory, please get in touch directly.

Project Advisory

Project Audit & Recovery

Independent project health checks, vendor performance audits, recovery assessments, and governance design. Fixed fee, written findings, no conflict of interest. For organisations that need an objective view of what is actually happening on a program of work — and what to do about it.

Project Health Check
2–3 weeks · Independent assessment of where your project actually stands
Vendor Performance Audit
3–4 weeks · Independent assessment of vendor delivery against contracted obligations
Recovery Assessment
3–5 weeks · Diagnosis, options, and a clear path forward for a program in distress
Governance Design
2–4 weeks · The governance structure your program needs before delivery begins
Capability Uplift

Delivery Capability Uplift

Structured uplift for BA and PM teams, working directly on live project artefacts. Fit for purpose starts with understanding the problem — not the solution. PM247 works with organisations to lift the quality of what their teams produce, in the context of real projects, before poor analysis becomes a delivery failure.

Business Analysis
Requirements quality, elicitation discipline, traceability, and workshop facilitation — on your live project artefacts
Project Management
Budget tracking, E2E planning, change control, and steering committee discipline — built for the project you are actually running
The practitioner

About Arpad Marton

20 years of independent delivery across cyber governance, infrastructure, and program management. Melbourne, Australia.

The practitioner CISOs call when they need it done, not just advised.

Twenty years of independent delivery — not twenty years at a firm where the first ten were shadowing someone else. Arpad Marton has operated as a practitioner-for-hire since the beginning: scoped, delivered, and accountable for the outcome from day one.

The work has spanned sectors few consultants navigate with genuine depth: healthcare information systems at Epworth, national research infrastructure at CSIRO, insurance program governance at IAG, and logistics technology at Toll. Each sector added a layer of regulatory nuance, stakeholder complexity, and technology constraint that informs every engagement PM247 takes on today.

The intersection Arpad occupies is rare: technical enough to understand the risk, commercially fluent enough to explain it to a board, and experienced enough to actually execute the fix. Most practitioners sit on one side of that intersection. PM247 sits at the middle of it.

The Master of Applied Finance is not decorative. When a CISO needs to make a cyber investment case to a CFO, or a program director needs to quantify the cost of a vendor underperforming, the ability to speak in dollar exposure — not just risk likelihood — is what gets the decision made. That is the differentiator no certification alone provides.

Three differentiators
🏛️

Govern

CISM certified. CISA in progress. Governance credentials grounded in 20 years of practice — not study alone.

⚙️

Deliver

20 years of hands-on execution across AU's most demanding sectors, programs, and regulatory environments.

📊

Translate

Applied Finance converts cyber risk into dollar exposure. Boards make decisions — advisors make the case.

Career development

BA/PM Career Mentoring

Direct, honest mentoring for delivery practitioners in healthcare, government, and regulated sectors. Not FAANG product management. Not a coaching marketplace. One practitioner. Genuine sector depth.

Before you enquire

This mentoring is not for everyone.

Most online mentoring platforms offer hundreds of PM coaches. If what you need is there, use them. PM247 mentoring is for a specific practitioner in a specific situation. Read both columns before you decide.

This is not for you if…

  • You want to break into product management at Google, Meta, or a US tech company
  • You're looking for a generic career coach with broad industry coverage
  • You want a platform with 50+ mentor options to choose from
  • You need someone available at scale across multiple mentees simultaneously
  • You're early career and need foundational PM training — a course will serve you better

This is for you if…

  • You're a BA or delivery PM in healthcare, government, financial services, or a regulated sector
  • You're working on or targeting cyber uplift or Essential Eight programs
  • You've received vague feedback and want someone who will be direct and specific
  • You're stalled mid-career and can't work out why — and you want an honest answer
  • You're preparing for your first senior or lead role and want someone who has done it
How we can work together
Ad Hoc

Single Session

$150–$300/hr
1–2 hours · specific topic · no ongoing commitment
  • Resume or LinkedIn review with written notes
  • Interview preparation for specific role or sector
  • Honest assessment of a specific career decision
  • No ongoing commitment required
Book a Session
Fixed Engagement

Career Positioning

Fixed fee
Scope and fee on enquiry
  • Full resume audit and rewrite
  • LinkedIn repositioning for target sector
  • Interview preparation — role-specific
  • Target role and organisation strategy
  • Written job search playbook
Enquire
Who this is for

PM247 mentoring is right for you if…

Junior BAs or PMs working on cyber uplift or Essential Eight programs who need someone who actually knows that environment

Career changers moving into technology delivery from other fields and struggling to translate their experience

Mid-level practitioners who feel stalled and aren't sure why — and want a direct, honest answer, not reassurance

Practitioners targeting roles in healthcare, government, or financial services — sectors that have specific norms most mentors don't understand

First-time senior or lead role candidates who want someone who has been on both sides of the hiring table in these sectors

Those who've received vague feedback from employers or interviews and want someone direct enough to tell them what's actually happening

⚠️

Maximum 3–6 mentees at any time

This is intentional — not a coaching factory. Every mentee receives genuine attention, direct feedback, and personal accountability. When capacity is full, a waitlist is maintained. If you're interested, starting the conversation early is recommended.

Perspectives from the field

Insights

Written for practitioners and executives — not vendors, not academics. Commentary on cyber governance, program recovery, and regulated sector delivery.

Queensland agencies must reach Essential Eight Level 2 by mid-2026. Here is what most of them are getting wrong.

The deadline is fixed. The compliance gap is real. Most agencies have prioritised the documentation of their Essential Eight posture over the actual controls — and there is a significant difference. This is the gap PM247 sees in almost every assessment, and it is fixable, but not by accident.

Four signs your cyber program is failing before the audit catches it

The warning signs are visible months before a formal review flags them. Leadership teams that know what to look for can intervene before recovery becomes remediation.

Your board doesn't understand the threat vector. That's the CISO's problem to solve.

Technical accuracy without commercial translation is advisory malpractice. Boards make risk decisions in dollar terms — and cyber advisors who can't make that translation are leaving the organisation exposed.

Healthcare is the most targeted sector and the least cyber-mature. Here's why that gap persists.

Legacy clinical systems, high-value patient data, and underinvested security teams create structural vulnerability that threat actors have exploited consistently since 2020.

When to fire your cyber vendor — and how to do it without losing coverage

Most organisations hold onto underperforming vendors for too long because transition risk feels greater than status quo risk. A vendor performance audit tells you which side of that equation you're actually on.

Stay connected

Follow Arpad on LinkedIn

Weekly commentary on cyber governance, program recovery, Essential Eight implementation, and regulated sector delivery — written for practitioners, not vendors.

LinkedIn Profile →
Get in touch

Start a conversation

All engagements begin with a no-cost scoping call. Share what you're dealing with and PM247 will confirm fit within 48 business hours.

Send an enquiry

The more context you share, the better prepared we will be for your call.