Cyber security, in plain language.
Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.
AI and the Essential Eight: Where They Intersect
Generative AI does not replace the Essential Eight, but it changes how every mitigation strategy must be applied. Here is where the…
Application Control Under the Essential Eight: A Practical Guide
Application control is the most powerful and the most feared of the Essential Eight strategies. Done well, it stops most malware cold.…
CPS 234 and Third-Party Service Providers: Managing the Risk
Under CPS 234, outsourcing the processing of your information assets does not outsource the obligation to protect them. This guide explains how…
Cloud Security for Government: ISM and IRAP Considerations
Moving government workloads to the cloud is not a procurement decision alone. This guide explains how the ISM, IRAP assessments and ACSC…
Cyber Due Diligence in Mergers and Acquisitions
Cyber due diligence protects the value of a deal by surfacing a target's hidden security debt, breach history and compliance exposure before…
What Is a Virtual CISO and When Do You Need One?
A virtual CISO provides experienced, board-level cyber security leadership on a flexible, fractional basis. This guide explains the role, responsibilities and the…
The NSW Cyber Security Policy: What Agencies Must Do
The NSW Cyber Security Policy sets mandatory requirements for NSW Government agencies. This guide explains the obligations, the annual attestation and how…
The Essential Eight Explained: A Plain-English Guide for Australian Organisations
The Essential Eight is the ACSC's baseline of eight mitigation strategies that prevent and limit the impact of cyber attacks. This guide…
Cybersecurity for Australian Councils: Where to Start
Local councils hold sensitive ratepayer data and run essential services, yet most run on lean IT teams and tight budgets. This guide…
Prefer a conversation to a newsletter?
Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.