Threat intel and news.Evidence before momentum.
Analysis and news for Australian leaders across AI security, ISO 42001 and ISO 27001 compliance, cyber risk, automation and technology leadership.
Read our editorial and review policyEvery article, latest first.
Showing 42 of 42 articles

The OpenAI agent Medicare breach: what happened, how it happened and what it means for Australian organisations
A fact-checked breakdown of the OpenAI agent breach of the Medicare Statistics Reporting Service portal: the timeline, how the agent got in, the potential damage, and the controls Australian organisations need now.
Read insight
Connected fleet vehicles with foreign operating systems: the cyber risk Australian boards are missing
A practical guide to the cyber security and data sovereignty risks of fleet vehicles running Chinese-built connected platforms, and what Australian organisations should do about them.
Read insight
Essential Eight maturity levels explained: a practical guide for Australian businesses
What each Essential Eight maturity level actually requires, how assessment works, what it costs, and how Australian businesses can reach Maturity Level Two without stalling.
Read insight
AI readiness assessment: how to run one that changes decisions
A working AI readiness assessment for Australian organisations — the six dimensions to score, the evidence behind each score, how to weight them, and what the output should authorise.
Read insight
ISO 27001 certification in Australia: the realistic path, cost and timeline
What ISO 27001 certification actually involves for an Australian organisation — scope decisions, the mandatory documents, Stage 1 and Stage 2 audits, realistic cost and timeline, and the mistakes that cause a failed audit.
Read insight
The apps your staff already built: governing low-code and AI sprawl
Every organisation has internal apps nobody approved — Power Apps, Copilot Studio agents, automations wired to personal accounts. How to inventory them, keep the good ones under proper controls, and retire the rest.
Read insight
Third-party cyber risk: governing the suppliers you cannot control
Most Australian breaches now arrive through a supplier. How to tier vendors by consequence, ask questions that produce evidence, write contract clauses that hold, and monitor risk between reviews.
Read insight
DSPM and AI security: what enterprises get wrong about data posture
Data security posture management (DSPM) is the control that decides whether enterprise AI is safe to switch on. What DSPM does, how it maps to Copilot and agents, and how to sequence it in Australia.
Read insight
Shadow AI: finding and controlling unsanctioned AI use
How Australian organisations discover unsanctioned AI tools, assess the real exposure, and bring shadow AI under governance without stopping useful work.
Read insight
AI incident response: planning for when the model fails
How to extend an Australian incident response plan to cover AI failures — bad output, prompt injection, data leakage and agent actions — with clear roles and evidence.
Read insight
ISO 42001 scope and leadership: getting clauses 4 and 5 right
How to define AI management system scope, identify interested parties, write an AI policy and establish leadership accountability under ISO 42001 clauses 4 and 5.
Read insight
ISO 42001 AI risk and impact assessment: how to run both
How to run ISO 42001 clause 6 AI risk assessment alongside an ISO 42005 AI system impact assessment, including criteria, scoring, treatment and evidence.
Read insight
ISO 42001 Statement of Applicability: Annex A controls explained
How to work through the ISO 42001 Annex A control set, justify inclusions and exclusions, and produce a Statement of Applicability that survives audit.
Read insight
ISO 42001 lifecycle controls: from design to decommission
How to implement ISO 42001 AI system lifecycle controls — requirements, design documentation, verification, deployment gates, monitoring and retirement — without stalling delivery.
Read insight
ISO 42001 data governance: provenance, quality and privacy
Implementing ISO 42001 data controls — provenance, quality, preparation and labelling — and reconciling them with Australian Privacy Act obligations.
Read insight
ISO 42001 internal audit and certification readiness
How to run ISO 42001 internal audit and management review under clauses 9 and 10, handle nonconformities, and prepare for Stage 1 and Stage 2 certification audits.
Read insight
Fractional CIO vs virtual CISO: which leadership model fits
How Australian organisations should choose between a fractional CIO and a virtual CISO — scope, accountability, cost, and when one accountable leader covers both.
Read insight
Network design security for large enterprises: beyond the perimeter
How to design, segment and operate a secure enterprise network that supports zero trust, resilience and Australian regulatory expectations.
Read insight
Securing enterprise AI adoption: a practical AI security control set
The AI security controls that matter first — identity, data boundaries, model access, logging, human oversight and supplier assurance.
Read insight
AI risk assessment: how to assess an AI system before it ships
A repeatable AI risk assessment covering purpose, data, model behaviour, integration, human oversight, failure modes and evidence.
Read insight
ISO 42001 vs ISO 27001: how the two management systems interlock
What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.
Read insight
The AI governance operating model: roles, gates and evidence
How to design an AI governance framework that approves useful work quickly and stops harmful work early, without a committee bottleneck.
Read insight
LLM and agentic AI threat model: from prompt injection to data exfiltration
The realistic attack paths against LLM and agent-based systems, and the controls that actually reduce each one.
Read insight
AI vendor and model due diligence: the questions that matter
A practical due-diligence checklist covering data use, retention, tenancy, subprocessors, evaluation, incident terms and exit.
Read insight
Making an enterprise AI-ready: the compliance and process foundations
The unglamorous foundations — data quality, access hygiene, process clarity, records and ownership — that decide whether AI adoption succeeds.
Read insight
AI compliance in Australia: what boards must be able to evidence
The Australian AI compliance landscape — privacy, sector obligations, ethics principles and standards — and the evidence directors should expect.
Read insight
An AI compliance checklist for Australian businesses
A working checklist that maps ISO 42001, ISO 27001, the Privacy Act and the Essential Eight onto one set of artefacts instead of four parallel programmes.
Read insight
Privacy Act reform and AI: preparing for automated decision transparency
What tightening Australian privacy expectations around automated decision-making mean for organisations already running AI in customer-facing processes.
Read insight
The first 90 days of AI adoption in an Australian SME
A week-by-week sequence for getting one AI use case into production safely, without a governance programme that outlasts the benefit.
Read insight
Microsoft Copilot for enterprises: custom experiences, DSPM and secure AI enablement
How Microsoft 365 Copilot, Copilot Studio and Copilot Cowork fit together in an enterprise, and the DSPM, data security and AI governance work that makes the rollout safe.
Read insight
AI readiness for SMEs: what to assess before buying tools
A practical readiness assessment spanning business value, process, data, security, governance and delivery capacity.
Read insight
ISO 42001 for SMEs: a practical AI governance roadmap
How smaller organisations can use an AI management system without creating enterprise bureaucracy.
Read insight
How to choose high-value AI workflow automation opportunities
A repeatable method for finding workflows with real net benefit and manageable operational risk.
Read insight
Measuring AI ROI through net benefit, risk and adoption
Why hours saved is not enough, and how to build a decision-grade AI value case.
Read insight
When an SME needs a fractional CIO
Signals that technology has become an executive issue, and how a fractional model can close the leadership gap.
Read insight
A 90-day technology roadmap for growing SMEs
A practical sequence for stabilising risk, clarifying priorities and creating delivery momentum.
Read insight
Building a board-ready technology investment case
Translate technical need into value, exposure, decision paths and an accountable execution case.
Read insight
Vendor rationalisation: cost, resilience and lock-in
How SMEs can reduce supplier complexity without creating a new concentration or transition risk.
Read insight
A risk-based cybersecurity roadmap for SMEs
Build a sequenced cyber programme around business exposure rather than an unprioritised control list.
Read insight
ISO 27001 vs Essential Eight for Australian SMEs
How the management-system and technical-control approaches differ, overlap and can work together.
Read insight
AI vendor security due diligence
Questions and evidence for assessing AI suppliers across data, models, identity, contracts and exit risk.
Read insight
Reporting cyber risk to a board without technical noise
A board reporting structure centred on exposure, decisions, evidence and accountable action.
Read insight