Written for the person who has to make the decision
Not thought leadership. Practical writing on the things Australian organisations actually get asked about — with enough detail to act on and no gated download.
The Essential Eight is becoming the Essentials
ASD will retire the Essential Eight and replace it with a multi-chapter Essentials series. What changes, what carries over, and why pausing your uplift is the expensive option.
Read the analysis ANALYSIS · 8 MINThe attack that actually empties the account
Email compromise is the most reported cyber threat to Australian businesses. No malware, nothing for your stack to catch, and one procedural control that stops it.
Read the analysis GUIDE · 7 MINCopilot does not overshare. Permissions do
Copilot honours your permissions exactly. That is the problem — it removes the obscurity holding ten years of file sprawl together. What to fix before you deploy.
Read the guide COMPLIANCE · 7 MINIf you pay a ransom, you have 72 hours
Mandatory ransomware payment reporting has been law since May 2025, and active enforcement began in January. Who it covers, and the notification nobody owns.
Read the guide COMPLIANCE · 8 MINThe automated decisions you forgot you were making
From 10 December your privacy policy must disclose automated decision-making. The hard part is finding where it already runs — including features nobody switched on.
Read the guide COMPLIANCE · 6 MINThe privacy law that applies even if the Privacy Act does not
Under $3 million turnover has always meant exempt. Since June 2025 that exemption no longer stops an individual suing you directly for a serious invasion of privacy.
Read the guide GUIDE · 12 MINThe Essential Eight, explained without the jargon
What each of the eight mitigation strategies actually asks of you, what the three maturity levels mean in practice, and the two controls where nearly everyone stalls.
Read the guide ANALYSIS · 8 MINMFA is not the finish line
Push fatigue, session token theft and adversary-in-the-middle phishing kits. Why the second factor you deployed in 2021 may already be bypassable, and what to do about it.
Read the analysis BUYER'S GUIDE · 10 MINTwelve questions to ask an MSP before you sign
The questions that separate a genuine security practice from a reseller with a monitoring agent — including the four answers that should end the conversation.
Read the guideWhat we are writing next
If one of these would be useful sooner, tell us and we will bring it forward — or just answer the question directly.
- Business email compromise: the payment verification control that actually works
- What your cyber insurer is really asking in the renewal questionnaire
- Application control without breaking the finance team
- Notifiable Data Breaches: how to decide, and how long you have
- Microsoft 365 licence tiers, compared on what they actually include
- Running a tabletop incident exercise with a leadership team that has never done one
Rather have the answer for your environment
General writing only goes so far. An assessment tells you where you actually stand against everything on this page.