John Macpherson is an Ashurst Risk Advisory partner in Australia
John is the leader of Ashurst's cyber response team working with clients to prepare for, and respond to high impact cyber incidents. As a strategic advisor to Boards and leadership teams in Australia and internationally, he supports them in their recovery from acute crisis. Alongside the Ashurst risk and legal teams, he has advised on many of the high profile cyber-attacks across Australia and the United Kingdom. He regularly helps clients build sustainable resilience frameworks and risk-led approaches to cyber and digital security, bridging expertise in crisis management and business continuity, stakeholder management and communication, customer remediation and complaints, data governance and privacy, third party risk management, and regulatory notifications and investigations.
Throughout a 20 year career in international security and crisis management, John has been retained to assist clients recover from high impact incidents and critical issues affecting operations and reputation, including ransomware attacks and cyber breaches, commercial and joint venture disputes, CEO misconduct and corporate governance failures, environmental disasters, regulatory enforcement and cross-broader corruption, intellectual property theft and corporate espionage. John has extensive experience advising clients on the successful implementation of risk, compliance and business operations in challenging, high risk markets. He has held leadership roles in China and Asia Pacific and brings expertise in managing complex reputation, social, geo-political and regulatory risks throughout Asia. He is a leading expert in managing the risk of unlawful state-actor detention and regulatory interference in opaque nation states.
Latest thinking
Carousel: clicking the "Previous" or "Next" button changes the content between the buttons.
-
Case studies
Post-incident cyber governance review - Listed Transport Company
08 Apr 2026
Discover more -
Case studies
Responding to a global cyber incident - Major Multinational Corporation
08 Apr 2026
Discover more -
Case studies
End-to-end cyber incident support - CS Energy
08 Apr 2026
Discover more -
Case studies
Cyber readiness review & simulation - Tier 1 Bank
08 Apr 2026
Discover more -
Case studies
Cyber incident transport & operational disruption - UK Public Transport Authority
08 Apr 2026
Discover more -
Case studies
Critical infrastructure sector resilience - Industry Owned Governance Body
08 Apr 2026
Discover more -
Case studies
Strategic cyber adviser to the CEO & Board - Medibank Private
08 Apr 2026
Discover more -
Podcasts
Governance & Compliance: The changing nature of cyberattacks and cyber regulation
10 Feb 2026
Listen now -
Business Insight
Redefining cyber readiness: From perimeter defence to Board-level resilience
19 Jan 2026
Discover more -
Legal development
A rise in malicious domain name activity: How a surge in "lookalike" domains impacts brand protection and trade marks in 2025
18 Nov 2025
Discover more -
Business Insight
Cyber readiness lessons from Australian Clinical Labs and Australia's first privacy penalty
20 Oct 2025
Discover more -
Business Insight
Redefining cyber readiness – Three ways to outpace Australia's new cyber laws
20 Dec 2024
Discover more
Latest news, deals and awards
Carousel: clicking the "Previous" or "Next" button changes the content between the buttons.