Threat intel & news

Threat intel and news.Evidence before momentum.

Analysis and news for Australian leaders across AI security, ISO 42001 and ISO 27001 compliance, cyber risk, automation and technology leadership.

Read our editorial and review policy
Latest

Latest threat intel

AI & automation

AI readiness assessment: how to run one that changes decisions

A working AI readiness assessment for Australian organisations — the six dimensions to score, the evidence behind each score, how to weight them, and what the output should authorise.

Read article
Cyber & risk

ISO 27001 certification in Australia: the realistic path, cost and timeline

What ISO 27001 certification actually involves for an Australian organisation — scope decisions, the mandatory documents, Stage 1 and Stage 2 audits, realistic cost and timeline, and the mistakes that cause a failed audit.

Read article
Cyber & risk

The apps your staff already built: governing low-code and AI sprawl

Every organisation has internal apps nobody approved — Power Apps, Copilot Studio agents, automations wired to personal accounts. How to inventory them, keep the good ones under proper controls, and retire the rest.

Read article
Cyber & risk

Third-party cyber risk: governing the suppliers you cannot control

Most Australian breaches now arrive through a supplier. How to tier vendors by consequence, ask questions that produce evidence, write contract clauses that hold, and monitor risk between reviews.

Read article
AI security & compliance

DSPM and AI security: what enterprises get wrong about data posture

Data security posture management (DSPM) is the control that decides whether enterprise AI is safe to switch on. What DSPM does, how it maps to Copilot and agents, and how to sequence it in Australia.

Read article
AI security & compliance

Shadow AI: finding and controlling unsanctioned AI use

How Australian organisations discover unsanctioned AI tools, assess the real exposure, and bring shadow AI under governance without stopping useful work.

Read article
Editorial series

AI security & compliance

11 min27 July 2026

Securing enterprise AI adoption: a practical AI security control set

The AI security controls that matter first — identity, data boundaries, model access, logging, human oversight and supplier assurance.

Read insight
10 min27 July 2026

AI risk assessment: how to assess an AI system before it ships

A repeatable AI risk assessment covering purpose, data, model behaviour, integration, human oversight, failure modes and evidence.

Read insight
10 min27 July 2026

ISO 42001 vs ISO 27001: how the two management systems interlock

What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.

Read insight
9 min27 July 2026

The AI governance operating model: roles, gates and evidence

How to design an AI governance framework that approves useful work quickly and stops harmful work early, without a committee bottleneck.

Read insight
11 min27 July 2026

LLM and agentic AI threat model: from prompt injection to data exfiltration

The realistic attack paths against LLM and agent-based systems, and the controls that actually reduce each one.

Read insight
9 min27 July 2026

AI vendor and model due diligence: the questions that matter

A practical due-diligence checklist covering data use, retention, tenancy, subprocessors, evaluation, incident terms and exit.

Read insight
10 min27 July 2026

Making an enterprise AI-ready: the compliance and process foundations

The unglamorous foundations — data quality, access hygiene, process clarity, records and ownership — that decide whether AI adoption succeeds.

Read insight
10 min27 July 2026

AI compliance in Australia: what boards must be able to evidence

The Australian AI compliance landscape — privacy, sector obligations, ethics principles and standards — and the evidence directors should expect.

Read insight
11 min27 July 2026

An AI compliance checklist for Australian businesses

A working checklist that maps ISO 42001, ISO 27001, the Privacy Act and the Essential Eight onto one set of artefacts instead of four parallel programmes.

Read insight
9 min27 July 2026

Privacy Act reform and AI: preparing for automated decision transparency

What tightening Australian privacy expectations around automated decision-making mean for organisations already running AI in customer-facing processes.

Read insight
14 min27 July 2026

Microsoft Copilot for enterprises: custom experiences, DSPM and secure AI enablement

How Microsoft 365 Copilot, Copilot Studio and Copilot Cowork fit together in an enterprise, and the DSPM, data security and AI governance work that makes the rollout safe.

Read insight
11 min10 Aug 2026

ISO 42001 scope and leadership: getting clauses 4 and 5 right

How to define AI management system scope, identify interested parties, write an AI policy and establish leadership accountability under ISO 42001 clauses 4 and 5.

Read insight
12 min10 Aug 2026

ISO 42001 AI risk and impact assessment: how to run both

How to run ISO 42001 clause 6 AI risk assessment alongside an ISO 42005 AI system impact assessment, including criteria, scoring, treatment and evidence.

Read insight
12 min10 Aug 2026

ISO 42001 Statement of Applicability: Annex A controls explained

How to work through the ISO 42001 Annex A control set, justify inclusions and exclusions, and produce a Statement of Applicability that survives audit.

Read insight
12 min10 Aug 2026

ISO 42001 lifecycle controls: from design to decommission

How to implement ISO 42001 AI system lifecycle controls — requirements, design documentation, verification, deployment gates, monitoring and retirement — without stalling delivery.

Read insight
11 min10 Aug 2026

ISO 42001 data governance: provenance, quality and privacy

Implementing ISO 42001 data controls — provenance, quality, preparation and labelling — and reconciling them with Australian Privacy Act obligations.

Read insight
12 min10 Aug 2026

ISO 42001 internal audit and certification readiness

How to run ISO 42001 internal audit and management review under clauses 9 and 10, handle nonconformities, and prepare for Stage 1 and Stage 2 certification audits.

Read insight
11 min14 Aug 2026

Shadow AI: finding and controlling unsanctioned AI use

How Australian organisations discover unsanctioned AI tools, assess the real exposure, and bring shadow AI under governance without stopping useful work.

Read insight
13 min18 Aug 2026

DSPM and AI security: what enterprises get wrong about data posture

Data security posture management (DSPM) is the control that decides whether enterprise AI is safe to switch on. What DSPM does, how it maps to Copilot and agents, and how to sequence it in Australia.

Read insight
Editorial series

Cyber & risk

9 min24 July 2026

A risk-based cybersecurity roadmap for SMEs

Build a sequenced cyber programme around business exposure rather than an unprioritised control list.

Read insight
9 min24 July 2026

ISO 27001 vs Essential Eight for Australian SMEs

How the management-system and technical-control approaches differ, overlap and can work together.

Read insight
8 min24 July 2026

AI vendor security due diligence

Questions and evidence for assessing AI suppliers across data, models, identity, contracts and exit risk.

Read insight
7 min24 July 2026

Reporting cyber risk to a board without technical noise

A board reporting structure centred on exposure, decisions, evidence and accountable action.

Read insight
11 min3 Aug 2026

Network design security for large enterprises: beyond the perimeter

How to design, segment and operate a secure enterprise network that supports zero trust, resilience and Australian regulatory expectations.

Read insight
12 min14 Aug 2026

AI incident response: planning for when the model fails

How to extend an Australian incident response plan to cover AI failures — bad output, prompt injection, data leakage and agent actions — with clear roles and evidence.

Read insight
12 min20 Aug 2026

Third-party cyber risk: governing the suppliers you cannot control

Most Australian breaches now arrive through a supplier. How to tier vendors by consequence, ask questions that produce evidence, write contract clauses that hold, and monitor risk between reviews.

Read insight
10 min23 Aug 2026

The apps your staff already built: governing low-code and AI sprawl

Every organisation has internal apps nobody approved — Power Apps, Copilot Studio agents, automations wired to personal accounts. How to inventory them, keep the good ones under proper controls, and retire the rest.

Read insight
12 min4 Sept 2026

ISO 27001 certification in Australia: the realistic path, cost and timeline

What ISO 27001 certification actually involves for an Australian organisation — scope decisions, the mandatory documents, Stage 1 and Stage 2 audits, realistic cost and timeline, and the mistakes that cause a failed audit.

Read insight