Partner – Technology risk & cyber resilience
Daniel Farthing is a Sydney-based Partner who helps organisations build confidence in their technology, cyber security and control environments. His experience spans financial services, government, higher education, critical infrastructure, technology and professional services organisations, including many of Australia's largest and most highly regulated institutions.
With nearly 20 years of experience across Australia and the United States, Daniel advises boards, executives and risk leaders on complex technology, cyber security and governance challenges. His expertise focuses on understanding how controls, risk management frameworks and assurance programs perform when organisations face regulatory scrutiny, significant change, cyber incidents or operational pressure.
Throughout his career, Daniel has worked on some of Australia's most significant technology risk and governance matters. He served as a cyber expert witness in one of the first cases brought under Australia's revised Privacy Act regime, acted as APRA's independent tri-partite auditor for approximately 30 regulated entities and contributed to Treasury consultations supporting the implementation of Australia's Open Banking regime. These experiences have provided first-hand insight into how organisations respond when controls, governance and accountability arrangements are tested in the real world.
Daniel has led hundreds of engagements spanning SOC 2, GS 007 and ASAE 3402 reporting, technology internal audit, cyber security reviews, third-party assurance and regulatory assurance programs. He also leads Grant Thornton's Sydney Technology Risk practice, which he has grown into a multidisciplinary team spanning cyber security, privacy, data governance, penetration testing, technology resilience and technology controls assurance.
Experience:
- Technology assurance, including SOC 2, GS 007 and ASAE 3402
- Technology internal audit
- Cyber security reviews
- APRA CPS 234, CPS 230 and prudential reviews
- Privacy Act
- Third-party assurance
- Operational resilience
- Data governance
- Security of Critical Infrastructure (SOCI)
Qualifications
- Bachelor of Business Administration (Accounting)
- Master of Business Administration (Assurance and Audit)
- Member of Chartered Accountants Australia and New Zealand
- Member Information Systems Audit and Control Association (ISACA)
- Member Institute of Internal Auditors (IIA)
- Certified Public Accountant (USA)