Insights

Cyber security, in plain language.

Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.

★ Featured
ISO
ISO 270014 min read

How to Choose an ISO 27001 Consultant in Australia (2026 Guide)

Choosing an ISO 27001 consultant in Australia comes down to one structural fact most buyers learn too late: the consultant who builds your ISMS cannot be the body that certifies it. Certification…

KA
Ken Armitt
July 16, 2026
Read →
All articles AI Security & Governance APRA & Financial Services Cyber Risk & Strategy Essential Eight Government Compliance Incident Response & Ransomware ISO 27001 Local Government Robotics & OT Security Uncategorized Virtual CISO & Governance
ISO 27001 ISO

ISO 27001 vs SOC 2: Choosing the Right Framework

A clear comparison of ISO 27001 and SOC 2, how they differ, where they overlap, and how Australian organisations should decide which…

July 15, 20267 minRead →
ISO 27001 ISO

ISO 27001 Stage 1 vs Stage 2 Audits: What to Expect

A clear breakdown of the two-stage ISO/IEC 27001:2022 certification audit, what each stage tests, and how to prepare so you pass without…

July 14, 20267 minRead →
ISO 27001 ISO

ISO 27001 Risk Assessment and Treatment: A Practical Method

Risk assessment is the engine of your ISMS, yet most organisations overcomplicate it. Here is a practical, repeatable method aligned to clause…

July 13, 20267 minRead →
ISO 27001 ISO

Building an ISMS That Auditors Trust

An ISMS is not a folder of policies. It is a living management system that auditors expect to see operating, improving and…

June 3, 20268 minRead →
ISO 27001 ISO

ISO 27001 Explained for Australian Organisations

ISO/IEC 27001 is the international standard for information security management. This guide explains what it actually requires and why it matters for…

June 2, 20268 minRead →
ISO 27001 ISO

ISO 27001 Annex A Controls: The 2022 Themes Explained

The 2022 revision reorganised Annex A into 93 controls across four themes, with eleven new controls. Here is what each theme covers…

May 27, 20267 minRead →
ISO 27001 ISO

ISO 27001 for SaaS and Cloud Businesses

A focused guide to ISO/IEC 27001:2022 for SaaS and cloud companies: defining scope, the shared responsibility model, cloud-specific controls and audit evidence.

May 26, 20267 minRead →

Prefer a conversation to a newsletter?

Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act