Cyber security, in plain language.
Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.
Aligning Cybersecurity With Business Strategy
Security that ignores business strategy gets ignored back. This guide shows how to align cybersecurity with the organisation's goals, risk appetite and…
IoT Security for Councils and Utilities
Smart sensors, connected meters and city devices expand the attack surface faster than most councils and utilities can secure them. This guide…
AI Risk Assessment: A Practical Framework
Adopting AI without assessing the risk is reckless. This practical framework walks through how to identify, evaluate and treat AI risk in…
Board Responsibilities Under APRA CPS 234
A guide for directors of APRA-regulated entities on their CPS 234 responsibilities, including ultimate accountability, oversight expectations and the questions boards should…
Building a Security-Aware Culture
Annual training ticks a box but rarely changes behaviour. This guide explains how to build a security-aware culture that reduces real risk…
Building an Acceptable Use Policy for AI
An AI acceptable use policy turns vague anxiety about staff using ChatGPT into clear, enforceable rules. Here is how to build one…
Conducting a Cybersecurity Risk Assessment
A cybersecurity risk assessment turns vague worry into a ranked list of what to fix and why. This step-by-step guide, aligned to…
CPS 234 Independent Testing and Assurance
A practical guide to CPS 234 independent testing and assurance, covering test scope, frequency, tester independence and how results flow to the…
Common Essential Eight Mistakes That Fail an Assessment
Most Essential Eight assessments fail not because the controls are missing, but because they are partially implemented, inconsistently applied, or undocumented. Here…
Prefer a conversation to a newsletter?
Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.