4 August 2026
Since June 2025, anyone can sue for a serious privacy invasion, no hack, no financial loss required, and the small business exemption doesn't help you. A court has already used it, over leaked wedding photos, not a cyber incident.
Read the article →
31 July 2026
Four AI models converged on the correct figure. Two confidently cited one that doesn't appear to exist anywhere. What a simple verification test reveals about trusting AI-generated statistics.
Read the article →
30 July 2026
Two numbers dominate breach-cost headlines in Australia: $4.26 million and $56,571. Neither is the number a genuine SME should budget against — here’s what the real number is closer to.
Read the article →
The Breach Ledger Series
21 July 2026
A hacked telemarketing vendor cascaded to 70 charities. A ransomware attack sent Brisbane hospitals back to paper for two months. The OAIC doesn’t even track this sector separately — here’s what six named incidents say about the least visible high-risk target in Australia.
Read the article →
The Breach Ledger Series
16 July 2026
Seventy-three NDB notifications in the first half of 2025. A 66 per cent malicious attack rate — well above the national average. From a hedge fund collapse to a credential-stuffing attack on super accounts, here’s what six named incidents say about who’s being hunted.
Read the article →
Updated 7 July 2026
APP 1.4 penalties now reach $66,000 per deficiency. Trust isn’t built in complaint resolution — it’s built in the decisions that happen before a complaint is ever lodged. Here’s what genuine compliance requires from an Australian SME.
Read the article →
30 June 2026
Two frameworks. Two regulators. One compliance gap. Aged care operators with a clean ACQSC audit may still be fully exposed under the Privacy Act — and most don’t know it.
Read the article →
The Breach Ledger Series
22 June 2026
Thirty-seven NDB notifications in the first half of 2025. An 86 per cent malicious attack rate — the highest of any top-five reporting sector. Nine named incidents across law firms, accountants, and management consultants. Here’s what the data says.
Read the article →
The Breach Ledger Series
12 June 2026
Seven years of named Australian school incidents, OAIC data, and what Loyola, Waverley, and Belmont tell us about who ransomware groups are targeting — and why.
Read the article →
1 June 2026
Approximately 92% of Australian businesses have never had to comply with the Privacy Act. The Tranche 2 reforms will change that. Here’s what it means and where to start.
Read the article →
1 June 2026
Handala wiped up to 200,000 Stryker devices using Microsoft Intune. No zero-day. One compromised admin account. The attack vector is universal — here’s what it means for your organisation.
Read the article →
22 May 2026
Most MSPs deliver solid technical support but leave clients exposed. The modern MSP closes the gap — governance, risk management, and compliance, right-sized for SMEs.
Read the article →
14 May 2026
OAIC's Children's Online Privacy Code is registered 10 December 2026. Independent schools are APP entities. Here's what business managers must do now.
Read the article →
5 May 2026
Healthcare tops Australia's breach charts again. OAIC data shows health led every reporting period since 2018. Here's what the numbers actually mean for private practices.
Read the article →
28 April 2026
Australia's Privacy Act changed on 10 December 2024. New fines, new enforcement powers, new legal liability. Here's what your organisation needs to know now.
Read the article →
Coming soon
Why your MSP shouldn't be your vCISO
The conflict of interest is real, documented, and surprisingly common. Here's what to look for and what to do about it.
Coming soon
Coming soon
What the Cyber Security Act 2024 actually requires - and what it doesn't
A plain-English breakdown of mandatory ransomware reporting, critical infrastructure obligations, and what applies to your organisation.
Coming soon
Coming soon
The Essential Eight in 2025: what actually changed and what it means for your program
The ASD updated the Essential Eight Maturity Model in 2025 — tighter patching windows, phishing-resistant MFA at ML2, and revised application control requirements. What shifted and what it means in practice.
Coming soon
Coming soon
CPS 234 in plain English: what APRA actually wants to see
APRA's information security prudential standard isn't complicated - but the gap between what regulated entities think it requires and what APRA actually looks for is surprisingly wide.
Coming soon
Coming soon
AI governance isn't an IT problem. Here's what your board should be asking.
AI adoption is moving faster than governance frameworks. The boards asking the right questions now will be in a materially better position in 12 months.
Coming soon