Threat intel & news

Threat intel and news.Evidence before momentum.

Analysis and news for Australian leaders across AI security, ISO 42001 and ISO 27001 compliance, cyber risk, automation and technology leadership.

Read our editorial and review policy
Latest

Latest threat intel

Cyber & risk

Third-party cyber risk: governing the suppliers you cannot control

Most Australian breaches now arrive through a supplier. How to tier vendors by consequence, ask questions that produce evidence, write contract clauses that hold, and monitor risk between reviews.

Read article
AI security & compliance

DSPM and AI security: what enterprises get wrong about data posture

Data security posture management (DSPM) is the control that decides whether enterprise AI is safe to switch on. What DSPM does, how it maps to Copilot and agents, and how to sequence it in Australia.

Read article
AI security & compliance

Shadow AI: finding and controlling unsanctioned AI use

How Australian organisations discover unsanctioned AI tools, assess the real exposure, and bring shadow AI under governance without stopping useful work.

Read article
Cyber & risk

AI incident response: planning for when the model fails

How to extend an Australian incident response plan to cover AI failures — bad output, prompt injection, data leakage and agent actions — with clear roles and evidence.

Read article
AI security & compliance

ISO 42001 scope and leadership: getting clauses 4 and 5 right

How to define AI management system scope, identify interested parties, write an AI policy and establish leadership accountability under ISO 42001 clauses 4 and 5.

Read article
AI security & compliance

ISO 42001 AI risk and impact assessment: how to run both

How to run ISO 42001 clause 6 AI risk assessment alongside an ISO 42005 AI system impact assessment, including criteria, scoring, treatment and evidence.

Read article
Editorial series

AI security & compliance

11 min27 July 2026

Securing enterprise AI adoption: a practical AI security control set

The AI security controls that matter first — identity, data boundaries, model access, logging, human oversight and supplier assurance.

Read insight
10 min27 July 2026

AI risk assessment: how to assess an AI system before it ships

A repeatable AI risk assessment covering purpose, data, model behaviour, integration, human oversight, failure modes and evidence.

Read insight
10 min27 July 2026

ISO 42001 vs ISO 27001: how the two management systems interlock

What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.

Read insight
9 min27 July 2026

The AI governance operating model: roles, gates and evidence

How to design an AI governance framework that approves useful work quickly and stops harmful work early, without a committee bottleneck.

Read insight
11 min27 July 2026

LLM and agentic AI threat model: from prompt injection to data exfiltration

The realistic attack paths against LLM and agent-based systems, and the controls that actually reduce each one.

Read insight
9 min27 July 2026

AI vendor and model due diligence: the questions that matter

A practical due-diligence checklist covering data use, retention, tenancy, subprocessors, evaluation, incident terms and exit.

Read insight
10 min27 July 2026

Making an enterprise AI-ready: the compliance and process foundations

The unglamorous foundations — data quality, access hygiene, process clarity, records and ownership — that decide whether AI adoption succeeds.

Read insight
10 min27 July 2026

AI compliance in Australia: what boards must be able to evidence

The Australian AI compliance landscape — privacy, sector obligations, ethics principles and standards — and the evidence directors should expect.

Read insight
11 min27 July 2026

An AI compliance checklist for Australian businesses

A working checklist that maps ISO 42001, ISO 27001, the Privacy Act and the Essential Eight onto one set of artefacts instead of four parallel programmes.

Read insight
9 min27 July 2026

Privacy Act reform and AI: preparing for automated decision transparency

What tightening Australian privacy expectations around automated decision-making mean for organisations already running AI in customer-facing processes.

Read insight
14 min27 July 2026

Microsoft Copilot for enterprises: custom experiences, DSPM and secure AI enablement

How Microsoft 365 Copilot, Copilot Studio and Copilot Cowork fit together in an enterprise, and the DSPM, data security and AI governance work that makes the rollout safe.

Read insight
11 min10 Aug 2026

ISO 42001 scope and leadership: getting clauses 4 and 5 right

How to define AI management system scope, identify interested parties, write an AI policy and establish leadership accountability under ISO 42001 clauses 4 and 5.

Read insight
12 min10 Aug 2026

ISO 42001 AI risk and impact assessment: how to run both

How to run ISO 42001 clause 6 AI risk assessment alongside an ISO 42005 AI system impact assessment, including criteria, scoring, treatment and evidence.

Read insight
12 min10 Aug 2026

ISO 42001 Statement of Applicability: Annex A controls explained

How to work through the ISO 42001 Annex A control set, justify inclusions and exclusions, and produce a Statement of Applicability that survives audit.

Read insight
12 min10 Aug 2026

ISO 42001 lifecycle controls: from design to decommission

How to implement ISO 42001 AI system lifecycle controls — requirements, design documentation, verification, deployment gates, monitoring and retirement — without stalling delivery.

Read insight
11 min10 Aug 2026

ISO 42001 data governance: provenance, quality and privacy

Implementing ISO 42001 data controls — provenance, quality, preparation and labelling — and reconciling them with Australian Privacy Act obligations.

Read insight
12 min10 Aug 2026

ISO 42001 internal audit and certification readiness

How to run ISO 42001 internal audit and management review under clauses 9 and 10, handle nonconformities, and prepare for Stage 1 and Stage 2 certification audits.

Read insight
11 min14 Aug 2026

Shadow AI: finding and controlling unsanctioned AI use

How Australian organisations discover unsanctioned AI tools, assess the real exposure, and bring shadow AI under governance without stopping useful work.

Read insight
13 min18 Aug 2026

DSPM and AI security: what enterprises get wrong about data posture

Data security posture management (DSPM) is the control that decides whether enterprise AI is safe to switch on. What DSPM does, how it maps to Copilot and agents, and how to sequence it in Australia.

Read insight