Insights

Cyber security, in plain language.

Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.

★ Featured
ESS
Essential Eight7 min read

How an Essential Eight Maturity Assessment Actually Works

An Essential Eight maturity assessment is more than a questionnaire. This guide walks through how a credible assessment is scoped, evidenced, tested and scored, and how Australian organisations should prepare.

KA
Ken Armitt
July 10, 2026
Read →
All articles AI Security & Governance APRA & Financial Services Cyber Risk & Strategy Essential Eight Government Compliance Incident Response & Ransomware ISO 27001 Local Government Robotics & OT Security Uncategorized Virtual CISO & Governance
Local Government LOC

Essential Eight for Local Government: A Practical Roadmap

The Essential Eight is the clearest framework for council cyber maturity. This roadmap shows lean council teams how to implement all eight…

July 8, 20267 minRead →
AI Security & Governance AIS

AI and the Essential Eight: Where They Intersect

Generative AI does not replace the Essential Eight, but it changes how every mitigation strategy must be applied. Here is where the…

June 5, 20268 minRead →
Essential Eight ESS

Application Control Under the Essential Eight: A Practical Guide

Application control is the most powerful and the most feared of the Essential Eight strategies. Done well, it stops most malware cold.…

June 4, 20267 minRead →
Government Compliance GOV

Cloud Security for Government: ISM and IRAP Considerations

Moving government workloads to the cloud is not a procurement decision alone. This guide explains how the ISM, IRAP assessments and ACSC…

June 4, 20267 minRead →
Government Compliance GOV

The NSW Cyber Security Policy: What Agencies Must Do

The NSW Cyber Security Policy sets mandatory requirements for NSW Government agencies. This guide explains the obligations, the annual attestation and how…

June 4, 20268 minRead →
Essential Eight ESS

The Essential Eight Explained: A Plain-English Guide for Australian Organisations

The Essential Eight is the ACSC's baseline of eight mitigation strategies that prevent and limit the impact of cyber attacks. This guide…

June 4, 20267 minRead →
Essential Eight ESS

Essential Eight Maturity Level One: What It Really Requires

Maturity Level One is the entry point of the Essential Eight Maturity Model. This article breaks down what ML1 genuinely requires for…

June 3, 20268 minRead →
Essential Eight ESS

Common Essential Eight Mistakes That Fail an Assessment

Most Essential Eight assessments fail not because the controls are missing, but because they are partially implemented, inconsistently applied, or undocumented. Here…

May 28, 20267 minRead →
Incident Response & Ransomware INC

Building an Incident Response Plan That Works

Most incident response plans fail at the worst possible moment because they were written to satisfy an auditor, not to be used…

May 27, 20268 minRead →

Prefer a conversation to a newsletter?

Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act