Insights

Cyber security, in plain language.

Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.

★ Featured
VIR
Virtual CISO & Governance7 min read

Building a Vendor and Third-Party Risk Management Program

Your suppliers can breach you. This guide explains how to build a practical vendor and third-party risk management program, from tiering and due diligence to contracts and monitoring.

KA
Ken Armitt
September 4, 2026
Read →
All articles AI Security & Governance APRA & Financial Services Cyber Risk & Strategy Essential Eight Government Compliance Incident Response & Ransomware ISO 27001 Local Government Robotics & OT Security Uncategorized Virtual CISO & Governance
Virtual CISO & Governance VIR

vCISO vs Full-Time CISO: Cost and Capability Compared

Choosing between a virtual CISO and a permanent CISO comes down to cost, capability and how much senior security leadership your organisation…

July 9, 20267 minRead →
Virtual CISO & Governance VIR

Best Virtual CISO Providers in Australia (2026): An Honest Comparison

If you search for the “best” virtual CISO provider in Australia, most of what you will find is marketing written by the…

July 7, 20265 minRead →
Virtual CISO & Governance VIR

How Much Does a Virtual CISO Cost in Australia? (2026 Pricing Guide)

A virtual CISO in Australia typically costs between $3,500 and $9,500 per month on a retainer, depending on the size of the…

July 7, 20264 minRead →
Virtual CISO & Governance VIR

Building a Cybersecurity Strategy From Scratch

A pile of security tools is not a strategy. Here is how to build a real one from a blank page, aligned…

June 5, 20267 minRead →
Virtual CISO & Governance VIR

What Is a Virtual CISO and When Do You Need One?

A virtual CISO provides experienced, board-level cyber security leadership on a flexible, fractional basis. This guide explains the role, responsibilities and the…

June 4, 20267 minRead →
Virtual CISO & Governance VIR

Aligning Cybersecurity With Business Strategy

Security that ignores business strategy gets ignored back. This guide shows how to align cybersecurity with the organisation's goals, risk appetite and…

June 1, 20267 minRead →
Virtual CISO & Governance VIR

Building a Security-Aware Culture

Annual training ticks a box but rarely changes behaviour. This guide explains how to build a security-aware culture that reduces real risk…

May 29, 20267 minRead →

Prefer a conversation to a newsletter?

Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act