Cyber security, in plain language.
Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.
Building a Cybersecurity Strategy From Scratch
A pile of security tools is not a strategy. Here is how to build a real one from a blank page, aligned…
APRA CPS 230 Operational Risk: What It Means for Cyber
APRA CPS 230 reframes cyber as a core operational risk. This guide explains what the standard requires from 1 July 2025 and…
Cloud Security Posture Management for Australian Organisations
Most cloud breaches are not clever hacks - they are misconfigurations. Cloud security posture management continuously checks your cloud against secure baselines…
AI Vendor Due Diligence: The Questions to Ask
Buying an AI product or a tool with AI baked in means inheriting its data practices and security posture. These are the…
AI and the Essential Eight: Where They Intersect
Generative AI does not replace the Essential Eight, but it changes how every mitigation strategy must be applied. Here is where the…
Application Control Under the Essential Eight: A Practical Guide
Application control is the most powerful and the most feared of the Essential Eight strategies. Done well, it stops most malware cold.…
CPS 234 and Third-Party Service Providers: Managing the Risk
Under CPS 234, outsourcing the processing of your information assets does not outsource the obligation to protect them. This guide explains how…
Cloud Security for Government: ISM and IRAP Considerations
Moving government workloads to the cloud is not a procurement decision alone. This guide explains how the ISM, IRAP assessments and ACSC…
Cyber Due Diligence in Mergers and Acquisitions
Cyber due diligence protects the value of a deal by surfacing a target's hidden security debt, breach history and compliance exposure before…
Prefer a conversation to a newsletter?
Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.