Insights

Cyber security, in plain language.

Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.

★ Featured
LOC
Local Government7 min read

Cyber Awareness Training That Works for Council Staff

Annual click-through training rarely changes behaviour, yet staff remain the most targeted part of any council. This guide shows how to run awareness training that actually works on a council budget.

KA
Ken Armitt
June 1, 2026
Read →
Virtual CISO & Governance VIR

Aligning Cybersecurity With Business Strategy

Security that ignores business strategy gets ignored back. This guide shows how to align cybersecurity with the organisation's goals, risk appetite and…

June 1, 20267 minRead →
Robotics & OT Security ROB

IoT Security for Councils and Utilities

Smart sensors, connected meters and city devices expand the attack surface faster than most councils and utilities can secure them. This guide…

June 1, 20268 minRead →
AI Security & Governance AIS

AI Risk Assessment: A Practical Framework

Adopting AI without assessing the risk is reckless. This practical framework walks through how to identify, evaluate and treat AI risk in…

June 1, 20267 minRead →
APRA & Financial Services APR

Board Responsibilities Under APRA CPS 234

A guide for directors of APRA-regulated entities on their CPS 234 responsibilities, including ultimate accountability, oversight expectations and the questions boards should…

May 29, 20267 minRead →
Virtual CISO & Governance VIR

Building a Security-Aware Culture

Annual training ticks a box but rarely changes behaviour. This guide explains how to build a security-aware culture that reduces real risk…

May 29, 20267 minRead →
AI Security & Governance AIS

Building an Acceptable Use Policy for AI

An AI acceptable use policy turns vague anxiety about staff using ChatGPT into clear, enforceable rules. Here is how to build one…

May 29, 20267 minRead →
Cyber Risk & Strategy CYB

Conducting a Cybersecurity Risk Assessment

A cybersecurity risk assessment turns vague worry into a ranked list of what to fix and why. This step-by-step guide, aligned to…

May 29, 20268 minRead →
APRA & Financial Services APR

CPS 234 Independent Testing and Assurance

A practical guide to CPS 234 independent testing and assurance, covering test scope, frequency, tester independence and how results flow to the…

May 28, 20267 minRead →
Essential Eight ESS

Common Essential Eight Mistakes That Fail an Assessment

Most Essential Eight assessments fail not because the controls are missing, but because they are partially implemented, inconsistently applied, or undocumented. Here…

May 28, 20267 minRead →

Prefer a conversation to a newsletter?

Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act