Insights

Written for the person who has to make the decision

Not thought leadership. Practical writing on the things Australian organisations actually get asked about — with enough detail to act on and no gated download.

Latest
ANALYSIS · 7 MIN

The Essential Eight is becoming the Essentials

ASD will retire the Essential Eight and replace it with a multi-chapter Essentials series. What changes, what carries over, and why pausing your uplift is the expensive option.

Read the analysis
ANALYSIS · 8 MIN

The attack that actually empties the account

Email compromise is the most reported cyber threat to Australian businesses. No malware, nothing for your stack to catch, and one procedural control that stops it.

Read the analysis
GUIDE · 7 MIN

Copilot does not overshare. Permissions do

Copilot honours your permissions exactly. That is the problem — it removes the obscurity holding ten years of file sprawl together. What to fix before you deploy.

Read the guide
COMPLIANCE · 7 MIN

If you pay a ransom, you have 72 hours

Mandatory ransomware payment reporting has been law since May 2025, and active enforcement began in January. Who it covers, and the notification nobody owns.

Read the guide
COMPLIANCE · 8 MIN

The automated decisions you forgot you were making

From 10 December your privacy policy must disclose automated decision-making. The hard part is finding where it already runs — including features nobody switched on.

Read the guide
COMPLIANCE · 6 MIN

The privacy law that applies even if the Privacy Act does not

Under $3 million turnover has always meant exempt. Since June 2025 that exemption no longer stops an individual suing you directly for a serious invasion of privacy.

Read the guide
GUIDE · 12 MIN

The Essential Eight, explained without the jargon

What each of the eight mitigation strategies actually asks of you, what the three maturity levels mean in practice, and the two controls where nearly everyone stalls.

Read the guide
ANALYSIS · 8 MIN

MFA is not the finish line

Push fatigue, session token theft and adversary-in-the-middle phishing kits. Why the second factor you deployed in 2021 may already be bypassable, and what to do about it.

Read the analysis
BUYER'S GUIDE · 10 MIN

Twelve questions to ask an MSP before you sign

The questions that separate a genuine security practice from a reseller with a monitoring agent — including the four answers that should end the conversation.

Read the guide
On the list

What we are writing next

If one of these would be useful sooner, tell us and we will bring it forward — or just answer the question directly.

  • Business email compromise: the payment verification control that actually works
  • What your cyber insurer is really asking in the renewal questionnaire
  • Application control without breaking the finance team
  • Notifiable Data Breaches: how to decide, and how long you have
  • Microsoft 365 licence tiers, compared on what they actually include
  • Running a tabletop incident exercise with a leadership team that has never done one

Rather have the answer for your environment

General writing only goes so far. An assessment tells you where you actually stand against everything on this page.