Insights

Cyber security, in plain language.

Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.

★ Featured
ISO
ISO 270014 min read

How to Choose an ISO 27001 Consultant in Australia (2026 Guide)

Choosing an ISO 27001 consultant in Australia comes down to one structural fact most buyers learn too late: the consultant who builds your ISMS cannot be the body that certifies it. Certification…

KA
Ken Armitt
July 16, 2026
Read →
All articles AI Security & Governance APRA & Financial Services Cyber Risk & Strategy Essential Eight Government Compliance Incident Response & Ransomware ISO 27001 Local Government Robotics & OT Security Uncategorized Virtual CISO & Governance
ISO 27001 ISO

ISO 27001 vs SOC 2: Choosing the Right Framework

A clear comparison of ISO 27001 and SOC 2, how they differ, where they overlap, and how Australian organisations should decide which…

July 15, 20267 minRead →
ISO 27001 ISO

ISO 27001 Stage 1 vs Stage 2 Audits: What to Expect

A clear breakdown of the two-stage ISO/IEC 27001:2022 certification audit, what each stage tests, and how to prepare so you pass without…

July 14, 20267 minRead →
ISO 27001 ISO

ISO 27001 Risk Assessment and Treatment: A Practical Method

Risk assessment is the engine of your ISMS, yet most organisations overcomplicate it. Here is a practical, repeatable method aligned to clause…

July 13, 20267 minRead →
Cyber Risk & Strategy CYB

Penetration Testing vs Vulnerability Scanning

They sound similar and are often confused, but penetration testing and vulnerability scanning answer different questions. Knowing which you need saves money…

July 12, 20267 minRead →
Essential Eight ESS

How to Choose an Essential Eight Consultant in Australia (2026 Guide)

The Essential Eight consulting market in Australia ranges from genuinely evidence-based assessors to questionnaire mills that will happily rate you Maturity Level…

July 11, 20264 minRead →
Essential Eight ESS

How an Essential Eight Maturity Assessment Actually Works

An Essential Eight maturity assessment is more than a questionnaire. This guide walks through how a credible assessment is scoped, evidenced, tested…

July 10, 20267 minRead →
Virtual CISO & Governance VIR

vCISO vs Full-Time CISO: Cost and Capability Compared

Choosing between a virtual CISO and a permanent CISO comes down to cost, capability and how much senior security leadership your organisation…

July 9, 20267 minRead →
Local Government LOC

Essential Eight for Local Government: A Practical Roadmap

The Essential Eight is the clearest framework for council cyber maturity. This roadmap shows lean council teams how to implement all eight…

July 8, 20267 minRead →
Cyber Risk & Strategy CYB

Technical Due Diligence in Australia: Process, Checklist & Costs (2026 Guide)

Technical due diligence is the independent, read-only assessment of a software platform before you buy it, invest in it, or bet your…

July 7, 20264 minRead →

Prefer a conversation to a newsletter?

Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act