RESOURCES

Playbooks for the next decision on your desk.

Practical, Australian-grounded guidance for CIOs, CISOs and IT leaders — anchored to the ACSC Essential Eight, ISO 27001:2022, APRA CPS 234 and the Cyber Security Act 2024.

PLAYBOOK · 8 MIN

How to Prioritise Cybersecurity Investments

A board-grade, five-step playbook for Australian leaders — anchored to ACSC Essential Eight, ISO 27001:2022 and APRA CPS 234.

Read playbook

AEO BRIEF · 7 MIN

Why Online Safety Fails Without Cyber Protection Services

How CIOs and CISOs close blind spots between threat protection, incident response, data privacy and executive decision-making.

Read playbook

HOME CYBER · 9 MIN

Home Cyber Protection in Australia

The defensible household stack IT leaders recommend to family, seniors and staff — beyond basic antivirus.

Read playbook

SUBSCRIPTIONS · 8 MIN

Personal Cyber Security and Identity Protection Subscriptions in Australia

A capability-based framework for picking personal cyber subscriptions for seniors, families and working adults.

Read playbook

FRAUD RECOVERY · 10 MIN

Recovering After Online Fraud in Australia: The First 72 Hours

A first-72-hour recovery playbook IT and security leaders can run with family, staff or small businesses.

Read playbook

AI STRATEGY · 10 MIN

AI Decision Support for IT Leaders in Australia

How CIOs, CISOs and tech executives use AI decision support to translate cyber risk, framework gaps and investment trade-offs into board-grade calls.

Read playbook

BOARD REPORTING · 9 MIN

How to Present Cyber Risk to the Board in Australia

A board-grade structure for CISOs and CIOs to brief directors on cyber risk, posture, investment and APRA / SOCI obligations.

Read playbook

FRAMEWORKS · 12 MIN

Essential Eight vs ISO 27001 vs NIST CSF — Which Framework Fits Australian Organisations?

A side-by-side comparison of the three frameworks Australian IT leaders are asked about most — when to pick each, and how they stack together.

Read playbook

STRATEGY · 11 MIN

Building a Cybersecurity Strategy and Roadmap (Australia, 18–36 Months)

A practical 18–36 month cybersecurity strategy structure CIOs and CISOs can defend to the board, audit committee and regulators.

Read playbook

COMPLIANCE · 11 MIN

APRA CPS 234 Compliance — A Practical Guide for Australian Financial Services

What CPS 234 actually requires, where APRA-regulated entities most often fall short, and how to evidence information security obligations.

Read playbook

BUYER GUIDE · 9 MIN

How to Evaluate AI Cybersecurity Tools (Australian Buyer Checklist)

A capability, risk and data-sovereignty checklist for evaluating AI security tooling — built for Australian CISO and procurement teams.

Read playbook

GOVERNANCE · 10 MIN

Cybersecurity Governance for Australian SMEs and Mid-Market

A lean governance model for Australian SMEs and mid-market: roles, cadence, registers and reporting without enterprise overhead.

Read playbook

AI RISK · 10 MIN

Managing AI Cyber Risk in Australia (Shadow AI, Model Risk and Data Exposure)

How Australian IT leaders are containing shadow AI, model risk and data leakage while still letting the business move fast.

Read playbook

CATEGORY GUIDE · 9 MIN

Best AI Cybersecurity Decision-Support Tools for Australian Leaders

Category round-up of AI cybersecurity decision-support platforms — what to evaluate, how categories differ, and where FORTE/CYBERx fits.

Read playbook

COMPARISON · 9 MIN

AI CISO Copilot vs Fractional CISO — Which Fits Australian Organisations?

A side-by-side comparison of AI CISO copilots and traditional fractional CISO engagements — speed, cost, defensibility and where each one wins.

Read playbook

BUYER’S GUIDE · 10 MIN

Cyber Decision-Support Platforms — Australian Buyer’s Guide

Structured procurement guide for Australian CISOs and CIOs — evaluation matrix, data sovereignty checklist, and the questions to ask every vendor.

Read playbook

COMPLIANCE · 12 MIN

SOCI Act Cyber Compliance — A Practical Guide for Australian Critical Infrastructure

What the SOCI Act requires of responsible entities — CIRMP, mandatory incident reporting timeframes and board accountability.

Read playbook

RISK QUANTIFICATION · 11 MIN

Cyber Risk Quantification for Australian Boards

Translate cyber risk into defensible dollar ranges the board can act on — FAIR-style quantification anchored to APRA, SOCI and ISO 27001.

Read playbook

DATA BREACH REPORT · 14 MIN

Australian Data Breach Analysis Report: Trends, Causes and Decision Frameworks

A 2026 analysis of the biggest Australian data breaches — Optus, Medibank, Latitude, HWL Ebsworth, MediSecure — with the root causes, regulatory shift and decision frameworks CISOs and CIOs use to prevent the next one.

Read playbook

DATA BREACH GUIDE · 12 MIN

Biggest Data Breaches in Australia: A Guide for Boards and IT Leaders

A board-level guide to Australia’s biggest data breaches — Optus, Medibank, Latitude, HWL Ebsworth, MediSecure, Ticketmaster Australia, Outabox — with root causes, regulatory backdrop and the five lessons IT leaders should act on now.

Read playbook

TPRM · 11 MIN

Third-Party Risk Management in Australia: A Practical TPRM Guide

Vendor tiering, due diligence, continuous monitoring and AU framework mapping (CPS 230, CPS 234, SOCI, ISO 27001) for Australian CISOs and CIOs.

Read playbook

DATA BREACH · 12 MIN

The Notifiable Data Breach Scheme in Australia: What CISOs and Boards Must Do

Eligible-breach assessment, the 30-day clock, OAIC notification and the first-72-hour response playbook — anchored to NDB, CPS 234 and SOCI.

Read playbook

RANSOMWARE · 13 MIN

Ransomware Readiness and Response in Australia: A CISO and Board Playbook

Prevention stack, 72-hour response sequence, ransom-payment decision frame and parallel ASD, OAIC, APRA and SOCI obligations for Australian leaders.

Read playbook

ISO 27001 · 11 MIN

ISO 27001:2022 Gap Analysis — A Practical Template for Australian Teams

Annex A control coverage, evidence gaps, prioritised remediation and the five-step structure ISMS owners use to get to stage-1 in 90 days.

Read playbook

INCIDENT RESPONSE · 12 MIN

Cyber Incident Response Plan Template — Australian CISO Playbook

A CIRP template Australian regulators expect — severity rubric, CIRT roles, NDB / CPS 234 / SOCI clocks and the first-60-minute sequence.

Read playbook

RISK REGISTER · 10 MIN

A Cyber Risk Register the Board Will Actually Read

Defensible columns, scoring scales, ISO 27001 / APRA / SOCI mapping and the quarterly cadence CISOs use to make the register the top-cited board artefact.

Read playbook

PRIVACY ACT · 11 MIN

Privacy Act Reform Australia — Tranche 2 & What CISOs Must Prepare

Tranche 1 obligations already in force, Tranche 2 on the horizon, the new $50m penalty regime and the controls Australian privacy leaders are putting in place now.

Read playbook

SUPPLY CHAIN · 11 MIN

Supply Chain Cyber Risk in Australia — The Decisions You Can’t Outsource

Vendor tiering, fourth-party exposure, SBOM, CPS 230 material service providers and the Cyber Security Act 2024 — operationalised for Australian CISOs.

Read playbook

AI POLICY · 10 MIN

An AI Acceptable Use Policy Australian Employees Will Actually Read

Sanctioned tools, data classification, prohibited uses, ISO 42001 anchor and a 30-day amnesty rollout — the pragmatic structure that lands.

Read playbook

ISO 42001 · 12 MIN

ISO 42001 Implementation — A 6-Month AIMS Roadmap for Australian Teams

AIMS scope, Annex A controls, AI Impact Assessments and the phase-by-phase plan organisations are using to get certification-ready.

Read playbook

AWARENESS · 9 MIN

Security Awareness Training — From Tick-Box to Behaviour Change

Programme design, role-targeted content, phishing simulations and the metrics that actually move human risk — anchored to ISO 27001 and CPS 234.

Read playbook

Bring one real decision. Get three defensible options.

FORTE/CYBERx runs a 7-advisor AI council on your decision in under 60 seconds. Two free missions. No credit card.

Run your first mission free