Insights

Cyber security, in plain language.

Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.

★ Featured
UNC
Uncategorized4 min read

The exploit window has collapsed: when a CVE drops, you have hours — not weeks

When a vulnerability is disclosed today, the question is no longer “when will we get around to patching it?” It’s “are we already too late?” For most of the last two decades,…

KA
Ken Armitt
June 15, 2026
Read →
Virtual CISO & Governance VIR

Building a Cybersecurity Strategy From Scratch

A pile of security tools is not a strategy. Here is how to build a real one from a blank page, aligned…

June 5, 20267 minRead →
APRA & Financial Services APR

APRA CPS 230 Operational Risk: What It Means for Cyber

APRA CPS 230 reframes cyber as a core operational risk. This guide explains what the standard requires from 1 July 2025 and…

June 5, 20266 minRead →
Cyber Risk & Strategy CYB

Cloud Security Posture Management for Australian Organisations

Most cloud breaches are not clever hacks - they are misconfigurations. Cloud security posture management continuously checks your cloud against secure baselines…

June 5, 20267 minRead →
AI Security & Governance AIS

AI Vendor Due Diligence: The Questions to Ask

Buying an AI product or a tool with AI baked in means inheriting its data practices and security posture. These are the…

June 5, 20267 minRead →
AI Security & Governance AIS

AI and the Essential Eight: Where They Intersect

Generative AI does not replace the Essential Eight, but it changes how every mitigation strategy must be applied. Here is where the…

June 5, 20268 minRead →
Essential Eight ESS

Application Control Under the Essential Eight: A Practical Guide

Application control is the most powerful and the most feared of the Essential Eight strategies. Done well, it stops most malware cold.…

June 4, 20267 minRead →
APRA & Financial Services APR

CPS 234 and Third-Party Service Providers: Managing the Risk

Under CPS 234, outsourcing the processing of your information assets does not outsource the obligation to protect them. This guide explains how…

June 4, 20267 minRead →
Government Compliance GOV

Cloud Security for Government: ISM and IRAP Considerations

Moving government workloads to the cloud is not a procurement decision alone. This guide explains how the ISM, IRAP assessments and ACSC…

June 4, 20267 minRead →
Cyber Risk & Strategy CYB

Cyber Due Diligence in Mergers and Acquisitions

Cyber due diligence protects the value of a deal by surfacing a target's hidden security debt, breach history and compliance exposure before…

June 4, 20268 minRead →

Prefer a conversation to a newsletter?

Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act