Insights

Cyber security, in plain language.

Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.

★ Featured
CYB
Cyber Risk & Strategy7 min read

Penetration Testing vs Vulnerability Scanning

They sound similar and are often confused, but penetration testing and vulnerability scanning answer different questions. Knowing which you need saves money and prevents false confidence.

KA
Ken Armitt
July 12, 2026
Read →
All articles AI Security & Governance APRA & Financial Services Cyber Risk & Strategy Essential Eight Government Compliance Incident Response & Ransomware ISO 27001 Local Government Robotics & OT Security Uncategorized Virtual CISO & Governance
Cyber Risk & Strategy CYB

Technical Due Diligence in Australia: Process, Checklist & Costs (2026 Guide)

Technical due diligence is the independent, read-only assessment of a software platform before you buy it, invest in it, or bet your…

July 7, 20264 minRead →
Cyber Risk & Strategy CYB

How Much Does a Penetration Test Cost in Australia? (2026 Price Guide)

A professionally delivered web-application penetration test in Australia starts from $7,500, and a combined engagement that adds social-engineering testing — controlled phishing…

July 7, 20264 minRead →
Cyber Risk & Strategy CYB

Cloud Security Posture Management for Australian Organisations

Most cloud breaches are not clever hacks - they are misconfigurations. Cloud security posture management continuously checks your cloud against secure baselines…

June 5, 20267 minRead →
Cyber Risk & Strategy CYB

Cyber Due Diligence in Mergers and Acquisitions

Cyber due diligence protects the value of a deal by surfacing a target's hidden security debt, breach history and compliance exposure before…

June 4, 20268 minRead →
Cyber Risk & Strategy CYB

Conducting a Cybersecurity Risk Assessment

A cybersecurity risk assessment turns vague worry into a ranked list of what to fix and why. This step-by-step guide, aligned to…

May 29, 20268 minRead →
Cyber Risk & Strategy CYB

Cyber Insurance: What It Covers and What It Won’t

Cyber insurance can be a vital safety net or an expensive false comfort. This guide explains what policies actually cover, what they…

May 28, 20267 minRead →

Prefer a conversation to a newsletter?

Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act