Insights

Cyber security, in plain language.

Practical guidance on governance, compliance and risk for Australian government, councils and enterprise — written by practitioners, not marketers.

★ Featured
ISO
ISO 270017 min read

ISO 27001 Risk Assessment and Treatment: A Practical Method

Risk assessment is the engine of your ISMS, yet most organisations overcomplicate it. Here is a practical, repeatable method aligned to clause 6.1 and ISO 27005.

KA
Ken Armitt
July 13, 2026
Read →
All articles AI Security & Governance APRA & Financial Services Cyber Risk & Strategy Essential Eight Government Compliance Incident Response & Ransomware ISO 27001 Local Government Robotics & OT Security Uncategorized Virtual CISO & Governance
Virtual CISO & Governance VIR

Building a Cybersecurity Strategy From Scratch

A pile of security tools is not a strategy. Here is how to build a real one from a blank page, aligned…

June 5, 20267 minRead →
Government Compliance GOV

The NSW Cyber Security Policy: What Agencies Must Do

The NSW Cyber Security Policy sets mandatory requirements for NSW Government agencies. This guide explains the obligations, the annual attestation and how…

June 4, 20268 minRead →
Essential Eight ESS

The Essential Eight Explained: A Plain-English Guide for Australian Organisations

The Essential Eight is the ACSC's baseline of eight mitigation strategies that prevent and limit the impact of cyber attacks. This guide…

June 4, 20267 minRead →
Local Government LOC

Cybersecurity for Australian Councils: Where to Start

Local councils hold sensitive ratepayer data and run essential services, yet most run on lean IT teams and tight budgets. This guide…

June 4, 20268 minRead →
AI Security & Governance AIS

AI Governance for Australian Organisations: Getting Started

AI is already in your organisation, whether you have approved it or not. This guide shows Australian organisations how to stand up…

June 4, 20268 minRead →
ISO 27001 ISO

ISO 27001 Explained for Australian Organisations

ISO/IEC 27001 is the international standard for information security management. This guide explains what it actually requires and why it matters for…

June 2, 20268 minRead →
AI Security & Governance AIS

AI Risk Assessment: A Practical Framework

Adopting AI without assessing the risk is reckless. This practical framework walks through how to identify, evaluate and treat AI risk in…

June 1, 20267 minRead →
Cyber Risk & Strategy CYB

Conducting a Cybersecurity Risk Assessment

A cybersecurity risk assessment turns vague worry into a ranked list of what to fix and why. This step-by-step guide, aligned to…

May 29, 20268 minRead →
Local Government LOC

Budgeting for Cybersecurity in a Council

Most councils underspend on cybersecurity not because they don't care, but because the budget process never gave it a proper line. Here…

May 26, 20268 minRead →

Prefer a conversation to a newsletter?

Talk to a senior advisor about cyber governance and compliance for your organisation — confidential, no obligation.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act