Insights

Cyber security, in plain language.

Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.

★ Featured
VIR
Virtual CISO & Governance5 min read

Best Virtual CISO Providers in Australia (2026): An Honest Comparison

If you search for the “best” virtual CISO provider in Australia, most of what you will find is marketing written by the providers themselves — including, in the interest of full disclosure,…

KA
Ken Armitt
July 7, 2026
Read →
Essential Eight ESS

How Much Does an Essential Eight Assessment Cost? (2026 Australian Guide)

An Essential Eight maturity assessment in Australia starts from $8,500 as a fixed fee, and a combined assessment plus uplift program —…

July 7, 20264 minRead →
Cyber Risk & Strategy CYB

How Much Does a Penetration Test Cost in Australia? (2026 Price Guide)

A professionally delivered web-application penetration test in Australia starts from $7,500, and a combined engagement that adds social-engineering testing — controlled phishing…

July 7, 20264 minRead →
Virtual CISO & Governance VIR

How Much Does a Virtual CISO Cost in Australia? (2026 Pricing Guide)

A virtual CISO in Australia typically costs between $3,500 and $9,500 per month on a retainer, depending on the size of the…

July 7, 20264 minRead →
Uncategorized UNC

A point-in-time guess is not a security posture: what a full audit actually covers

“We passed our audit last year.” “We’re patched.” “We have the tools.” Three sentences that have preceded a great many breaches —…

June 15, 20264 minRead →
Uncategorized UNC

AI just found a zero-day no human had reported — both sides now have it

In late 2024, an AI agent did something no AI had publicly done before: it found a real, exploitable, previously-unknown vulnerability in…

June 15, 20264 minRead →
Uncategorized UNC

The exploit window has collapsed: when a CVE drops, you have hours — not weeks

When a vulnerability is disclosed today, the question is no longer “when will we get around to patching it?” It’s “are we…

June 15, 20264 minRead →
Virtual CISO & Governance VIR

Building a Cybersecurity Strategy From Scratch

A pile of security tools is not a strategy. Here is how to build a real one from a blank page, aligned…

June 5, 20267 minRead →
APRA & Financial Services APR

APRA CPS 230 Operational Risk: What It Means for Cyber

APRA CPS 230 reframes cyber as a core operational risk. This guide explains what the standard requires from 1 July 2025 and…

June 5, 20266 minRead →
Cyber Risk & Strategy CYB

Cloud Security Posture Management for Australian Organisations

Most cloud breaches are not clever hacks - they are misconfigurations. Cloud security posture management continuously checks your cloud against secure baselines…

June 5, 20267 minRead →

Prefer a conversation to a newsletter?

Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act