Skip to content

Office Hours with 6clicks, Adelaide

Prove your controls once. Report against every obligation.

CIRMP annual report due: Monday, 28 September 2026, board-approved. For most entities that means the last board meeting before it. This session is a working breakfast for senior GRC, cyber and risk leaders in Australia, ahead of the September reporting cycle.

The 2026 tour
SEP 10

Adelaide

Thursday • The Playford Adelaide

OPEN
SEP 16

Brisbane

Wednesday · Deery’s Hotel

OPEN
Oct 20

Sydney

Tuesday · The Commons George St

OPEN

Choose your city and register now.

FORMAT Roundtable Breakfast included
Up next Thursday, 10 September 2026 8:30 am to 11:00 am
COST Free You're welcome to bring a +1
The problem

SOCI and the CIRMP annual report

Essential Eight and the ISM. ISO 27001. DISP and prime contract flow-down. Privacy obligations. Different regulators, different language, largely the same underlying controls.

Most teams are evidencing the same control three or four times because each regime asks for it differently. That isn't a governance problem. It's a capacity problem, and it compounds every year the list grows.

8:30

Doors open, breakfast served

Hot breakfast and coffee as the room fills.

8:45

Welcome and introductions

A quick round so everyone knows who's in the room.

9:00

What the room is facing

The obligations stacking up, and where they overlap. Built on what you told us at registration.

9:15

The 6clicks response, with Andrew Robinson

What it takes to move from asserting your controls work to proving it.

9:30

Solutions in action

Your challenges, run end to end in 6clicks, live in the room.

10:15

Roundtable

Open discussion on what's working and what isn't, with the people facing the same thing.

11:00

Networking

Coffee and conversation for those who can stay.

Why now

Assertion is being replaced by evidence.

The September reporting cycle is the near-term pressure, but the shift is broader than one regime. Across SOCI, Essential Eight, ISO 27001 and prime contract flow-down, regulators and customers are moving from asking whether you have controls to asking you to prove they work. Here's what's changed. 

28 SEPTEMBER, BOARD APPROVED

Responsible entities under the SOCI Act submit their annual CIRMP report within 90 days of financial year end. This year that's 28 September, which for most boards means the sitting before it.

AN ATTESTATION, NOT A NOTING ITEM

The board isn't acknowledging the report, it's approving it. Which makes the evidence underneath it matter more than the document itself.

INDEPENDENT ASSURANCE IS PROPOSED

Home Affairs has consulted on mandatory periodic independent assurance. If it proceeds, program maturity stops being an internal judgement and becomes externally visible.

THE SAME DIRECTION EVERYWHERE

Not captured by SOCI? Essential Eight, ISO 27001, DISP and privacy obligations are all moving the same way. The frameworks differ. The underlying controls mostly don't.

Who it’s for

Senior operators who are accountable for what the evidence says, not just that it exists.

Small rooms. Senior operators.

Roles

CISOs and Deputy CISOs Heads of Risk / CROs GRC and compliance leads Internal audit leaders CIO/CTO (government + critical infrastructure)

Also relevant if you carry

SOCI / CIRMP Essential Eight ISO 27001 DISP or prime contract flow-down APRA CPS 234 / CPS 230 Privacy and data obligations
CHOOSE YOUR FOCUS

Pick what you want to see run.

Tell us at registration and we'll build the session around it. Whatever you choose, we run it end to end in 6clicks live in the room, and you leave with outputs your team can use straight away.

1

Control Assurance (Evidence validation + gap findings)

“I need to upload evidence, validate it, and make sure it actually meets the control requirements.”

Validate evidence against clear criteria and surface gaps with recommended actions, so you can prove control effectiveness, not just tick it off.

2

Risk Accountability

“Show me every risk we’ve accepted at medium or above, and who signed off on it.”

Surface high-impact accepted risks and make ownership explicit, so accountability is clear and nothing sits unowned.

3

Privileged Access Compliance

"We run quarterly access reviews across AD and Entra ID. I need them tested against ISM controls and packaged for audit, without chasing evidence by email."

Bring your access review evidence together, test it against your controls, and package it audit-ready, so you can prove privileged access compliance without the email chase.

4

Continuous Assessment Management

"I need my team to review and update assessments together, and keep answers current as our evidence and posture change, without losing track of who changed what."

Collaborate on assessments at the question level, with comments and reopen in context, so reviews stay in one place and your records stay accurate and audit-ready.

5

Third Party Risk Management

"I need to be able to automate the onboarding and assessment of third-party suppliers. Understanding the level of risk, they pose and ensure their compliance to my required frameworks and standards."

Onboard and assess suppliers automatically, score the risk they carry, and track their compliance against your frameworks.

6

Issue & Incident Management

"I need to be able to capture our Issues and Incidents and manage them effectively ensuring that they follow our required process."

Capture issues and incidents and run them through your required process, start to finish, with nothing slipping through.

7

Risk Approvals

"I need any risk added and accepted onto our Risk Register to be approved by the right level of the organisation."

Route risk acceptances through approval workflows, so sign-off sits at the right level and nothing is accepted without authority.

8

Multi-Framework Mapping

"We comply with multiple frameworks. I need to streamline evidence collection so my Control Owners aren't duplicating work across them."

Map one control to many frameworks and reuse evidence across them, so Control Owners collect once and satisfy multiple requirements.

9

Connected Compliance

"Our tools don't talk to each other, so GRC data ends up stranded and we reconcile by hand."

Connect 6clicks to your existing stack through new APIs and integrations, so your data flows into one system instead of living in silos.

10

Registers, Built Your Way

"I need registers that match how we actually work, with the right people seeing the right records."

Create custom register types for controls, tests, tasks and evidence, with role-based access, so your structure fits your team and stays secure.

What you’ll leave with

You’ll leave with outcomes, not impressions

Validated evidence criteria (what “good” looks like, before you upload)

Clear findings and gaps, prioritised with recommended actions

Accountable owners and tasks created as you go

An audit‑ready narrative your team can use immediately

How it works

Steps

1. Request an invite (choose your city)

2. We confirm fit and send your calendar invite

3. Bring a real GRC problem (or choose a guided use case)

4. Watch the build: evidence → validation → findings → posture

5. Leave with your output pack

FAQs

Frequently asked questions

We've compiled the most important information to help you get the most out of your experience. Can't find what you're looking for? Contact us.

6clicks delivers sovereign GRC infrastructure built for government, defence, and critical infrastructure operators. The platform combines AI-powered risk and compliance workflows, flexible sovereign deployment models, and agentic connectivity across complex environments.

Yes. Office Hours is an in-person working session in each city. We’ll send venue details and a calendar invite once you register and we confirm capacity. 
You’ll join a small group of peers for a live build. We’ll run a real scenario end-to-end in 6clicks, show evidence validation and findings in real time, and leave time for open operator discussion. You’ll leave with clear outputs you can take back to your team. 
Yes. You can bring up to +2 additional team members, as long as they are operators who can influence decision makers (for example, GRC, cyber, risk, compliance, or platform leaders). 
Yes. Share as much context as you can in the registration form. If you’re invited, we’ll follow up to confirm the scenario and tailor the session so the live build is relevant to your environment. 
No. This is for senior operators in regulated organisations. 
Ready to see intelligent GRC run end‑to‑end?

Register for your city. Seats are limited.