Threat intel & news

Threat intel and news.Evidence before momentum.

Analysis and news for Australian leaders across AI security, ISO 42001 and ISO 27001 compliance, cyber risk, automation and technology leadership.

Read our editorial and review policy
All articles

Every article, latest first.

Showing 42 of 42 articles

AI agent pathways approaching a secured Australian government building
12 min25 Sept 2026
AI security & compliance

The OpenAI agent Medicare breach: what happened, how it happened and what it means for Australian organisations

A fact-checked breakdown of the OpenAI agent breach of the Medicare Statistics Reporting Service portal: the timeline, how the agent got in, the potential damage, and the controls Australian organisations need now.

Read insight
Connected commercial vehicle fleet with digital network reflections in its windscreen
11 min22 Sept 2026
Cyber & risk

Connected fleet vehicles with foreign operating systems: the cyber risk Australian boards are missing

A practical guide to the cyber security and data sovereignty risks of fleet vehicles running Chinese-built connected platforms, and what Australian organisations should do about them.

Read insight
Eight metal shields representing Australia’s Essential Eight cyber controls
10 min21 Sept 2026
Cyber & risk

Essential Eight maturity levels explained: a practical guide for Australian businesses

What each Essential Eight maturity level actually requires, how assessment works, what it costs, and how Australian businesses can reach Maturity Level Two without stalling.

Read insight
Silver tokens moving through transparent channels into a controlled AI workflow
11 min4 Sept 2026
AI & automation

AI readiness assessment: how to run one that changes decisions

A working AI readiness assessment for Australian organisations — the six dimensions to score, the evidence behind each score, how to weight them, and what the output should authorise.

Read insight
Layered translucent glass panels representing structured assurance and audit evidence
12 min4 Sept 2026
Cyber & risk

ISO 27001 certification in Australia: the realistic path, cost and timeline

What ISO 27001 certification actually involves for an Australian organisation — scope decisions, the mandatory documents, Stage 1 and Stage 2 audits, realistic cost and timeline, and the mistakes that cause a failed audit.

Read insight
Violet droplets converging into a pool representing ungoverned apps brought into view
10 min23 Aug 2026
Cyber & risk

The apps your staff already built: governing low-code and AI sprawl

Every organisation has internal apps nobody approved — Power Apps, Copilot Studio agents, automations wired to personal accounts. How to inventory them, keep the good ones under proper controls, and retire the rest.

Read insight
A chain of linked metal modules with one connection under inspection
12 min20 Aug 2026
Cyber & risk

Third-party cyber risk: governing the suppliers you cannot control

Most Australian breaches now arrive through a supplier. How to tier vendors by consequence, ask questions that produce evidence, write contract clauses that hold, and monitor risk between reviews.

Read insight
Layered violet and silver strata representing enterprise data security
13 min18 Aug 2026
AI security & compliance

DSPM and AI security: what enterprises get wrong about data posture

Data security posture management (DSPM) is the control that decides whether enterprise AI is safe to switch on. What DSPM does, how it maps to Copilot and agents, and how to sequence it in Australia.

Read insight
Violet fluid with silver veining representing shadow AI discovery
11 min14 Aug 2026
AI security & compliance

Shadow AI: finding and controlling unsanctioned AI use

How Australian organisations discover unsanctioned AI tools, assess the real exposure, and bring shadow AI under governance without stopping useful work.

Read insight
Abstract violet fluid artwork representing AI incident response
12 min14 Aug 2026
Cyber & risk

AI incident response: planning for when the model fails

How to extend an Australian incident response plan to cover AI failures — bad output, prompt injection, data leakage and agent actions — with clear roles and evidence.

Read insight
Architectural steps ascending towards a clear horizon, representing technology leadership
11 min10 Aug 2026
AI security & compliance

ISO 42001 scope and leadership: getting clauses 4 and 5 right

How to define AI management system scope, identify interested parties, write an AI policy and establish leadership accountability under ISO 42001 clauses 4 and 5.

Read insight
Interlocking metal barriers with an illuminated gap representing cyber risk
12 min10 Aug 2026
AI security & compliance

ISO 42001 AI risk and impact assessment: how to run both

How to run ISO 42001 clause 6 AI risk assessment alongside an ISO 42005 AI system impact assessment, including criteria, scoring, treatment and evidence.

Read insight
Layered translucent glass panels representing structured assurance and audit evidence
12 min10 Aug 2026
AI security & compliance

ISO 42001 Statement of Applicability: Annex A controls explained

How to work through the ISO 42001 Annex A control set, justify inclusions and exclusions, and produce a Statement of Applicability that survives audit.

Read insight
Silver tokens moving through transparent channels into a controlled AI workflow
12 min10 Aug 2026
AI security & compliance

ISO 42001 lifecycle controls: from design to decommission

How to implement ISO 42001 AI system lifecycle controls — requirements, design documentation, verification, deployment gates, monitoring and retirement — without stalling delivery.

Read insight
A protected data sphere visible through layers of frosted glass
11 min10 Aug 2026
AI security & compliance

ISO 42001 data governance: provenance, quality and privacy

Implementing ISO 42001 data controls — provenance, quality, preparation and labelling — and reconciling them with Australian Privacy Act obligations.

Read insight
Layered translucent glass panels representing structured assurance and audit evidence
12 min10 Aug 2026
AI security & compliance

ISO 42001 internal audit and certification readiness

How to run ISO 42001 internal audit and management review under clauses 9 and 10, handle nonconformities, and prepare for Stage 1 and Stage 2 certification audits.

Read insight
Architectural steps ascending towards a clear horizon, representing technology leadership
10 min6 Aug 2026
Fractional CIO

Fractional CIO vs virtual CISO: which leadership model fits

How Australian organisations should choose between a fractional CIO and a virtual CISO — scope, accountability, cost, and when one accountable leader covers both.

Read insight
Abstract violet fluid artwork representing secure enterprise network design
11 min3 Aug 2026
Cyber & risk

Network design security for large enterprises: beyond the perimeter

How to design, segment and operate a secure enterprise network that supports zero trust, resilience and Australian regulatory expectations.

Read insight
A protected data sphere visible through layers of frosted glass
11 min27 July 2026
AI security & compliance

Securing enterprise AI adoption: a practical AI security control set

The AI security controls that matter first — identity, data boundaries, model access, logging, human oversight and supplier assurance.

Read insight
Interlocking metal barriers with an illuminated gap representing cyber risk
10 min27 July 2026
AI security & compliance

AI risk assessment: how to assess an AI system before it ships

A repeatable AI risk assessment covering purpose, data, model behaviour, integration, human oversight, failure modes and evidence.

Read insight
Layered translucent glass panels representing structured assurance and audit evidence
10 min27 July 2026
AI security & compliance

ISO 42001 vs ISO 27001: how the two management systems interlock

What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.

Read insight
Layered translucent glass panels representing structured assurance and audit evidence
9 min27 July 2026
AI security & compliance

The AI governance operating model: roles, gates and evidence

How to design an AI governance framework that approves useful work quickly and stops harmful work early, without a committee bottleneck.

Read insight
Abstract fluid study illustrating the evolving boundaries of agentic AI threats
11 min27 July 2026
AI security & compliance

LLM and agentic AI threat model: from prompt injection to data exfiltration

The realistic attack paths against LLM and agent-based systems, and the controls that actually reduce each one.

Read insight
A chain of linked metal modules with one connection under inspection
9 min27 July 2026
AI security & compliance

AI vendor and model due diligence: the questions that matter

A practical due-diligence checklist covering data use, retention, tenancy, subprocessors, evaluation, incident terms and exit.

Read insight
Silver tokens moving through transparent channels into a controlled AI workflow
10 min27 July 2026
AI security & compliance

Making an enterprise AI-ready: the compliance and process foundations

The unglamorous foundations — data quality, access hygiene, process clarity, records and ownership — that decide whether AI adoption succeeds.

Read insight
Layered teal glass representing evidence prepared for board scrutiny
10 min27 July 2026
AI security & compliance

AI compliance in Australia: what boards must be able to evidence

The Australian AI compliance landscape — privacy, sector obligations, ethics principles and standards — and the evidence directors should expect.

Read insight
Layered translucent glass panels representing structured assurance and audit evidence
11 min27 July 2026
AI security & compliance

An AI compliance checklist for Australian businesses

A working checklist that maps ISO 42001, ISO 27001, the Privacy Act and the Essential Eight onto one set of artefacts instead of four parallel programmes.

Read insight
A protected data sphere visible through layers of frosted glass
9 min27 July 2026
AI security & compliance

Privacy Act reform and AI: preparing for automated decision transparency

What tightening Australian privacy expectations around automated decision-making mean for organisations already running AI in customer-facing processes.

Read insight
Silver tokens moving through transparent channels into a controlled AI workflow
10 min27 July 2026
AI & automation

The first 90 days of AI adoption in an Australian SME

A week-by-week sequence for getting one AI use case into production safely, without a governance programme that outlasts the benefit.

Read insight
Abstract violet fluid artwork representing controlled enterprise AI enablement
14 min27 July 2026
AI security & compliance

Microsoft Copilot for enterprises: custom experiences, DSPM and secure AI enablement

How Microsoft 365 Copilot, Copilot Studio and Copilot Cowork fit together in an enterprise, and the DSPM, data security and AI governance work that makes the rollout safe.

Read insight
Silver tokens moving through transparent channels into a controlled AI workflow
8 min24 July 2026
AI & automation

AI readiness for SMEs: what to assess before buying tools

A practical readiness assessment spanning business value, process, data, security, governance and delivery capacity.

Read insight
Layered translucent glass panels representing structured assurance and audit evidence
9 min24 July 2026
AI & automation

ISO 42001 for SMEs: a practical AI governance roadmap

How smaller organisations can use an AI management system without creating enterprise bureaucracy.

Read insight
Silver tokens moving through transparent channels into a controlled AI workflow
7 min24 July 2026
AI & automation

How to choose high-value AI workflow automation opportunities

A repeatable method for finding workflows with real net benefit and manageable operational risk.

Read insight
Silver tokens moving through transparent channels into a controlled AI workflow
8 min24 July 2026
AI & automation

Measuring AI ROI through net benefit, risk and adoption

Why hours saved is not enough, and how to build a decision-grade AI value case.

Read insight
Architectural steps ascending towards a clear horizon, representing technology leadership
7 min24 July 2026
Fractional CIO

When an SME needs a fractional CIO

Signals that technology has become an executive issue, and how a fractional model can close the leadership gap.

Read insight
Architectural steps ascending towards a clear horizon, representing technology leadership
8 min24 July 2026
Fractional CIO

A 90-day technology roadmap for growing SMEs

A practical sequence for stabilising risk, clarifying priorities and creating delivery momentum.

Read insight
Architectural steps ascending towards a clear horizon, representing technology leadership
7 min24 July 2026
Fractional CIO

Building a board-ready technology investment case

Translate technical need into value, exposure, decision paths and an accountable execution case.

Read insight
A chain of linked metal modules with one connection under inspection
8 min24 July 2026
Fractional CIO

Vendor rationalisation: cost, resilience and lock-in

How SMEs can reduce supplier complexity without creating a new concentration or transition risk.

Read insight
Interlocking metal barriers with an illuminated gap representing cyber risk
9 min24 July 2026
Cyber & risk

A risk-based cybersecurity roadmap for SMEs

Build a sequenced cyber programme around business exposure rather than an unprioritised control list.

Read insight
Eight metal shields representing Australia’s Essential Eight cyber controls
9 min24 July 2026
Cyber & risk

ISO 27001 vs Essential Eight for Australian SMEs

How the management-system and technical-control approaches differ, overlap and can work together.

Read insight
A chain of linked metal modules with one connection under inspection
8 min24 July 2026
Cyber & risk

AI vendor security due diligence

Questions and evidence for assessing AI suppliers across data, models, identity, contracts and exit risk.

Read insight
Layered teal glass representing evidence prepared for board scrutiny
7 min24 July 2026
Cyber & risk

Reporting cyber risk to a board without technical noise

A board reporting structure centred on exposure, decisions, evidence and accountable action.

Read insight