Handy Hint Friday Series
29 August 2026
ACSC's free technical example for application control doesn't clear the Essential Eight maturity bar it's meant to demonstrate. Here's the genuinely free path that does, and the licence-tier fact worth getting exactly right.
Read the article →
20 August 2026
DSI's new SCAP framework gives buyers a structured way to tier supplier cyber risk using the SMB1001 standard. Bronze, Silver and Gold are still self-attested, here's what that means before you rely on a badge.
Read the article →
4 August 2026
Since June 2025, anyone can sue for a serious privacy invasion, no hack, no financial loss required, and the small business exemption doesn't help you. A court has already used it, over leaked wedding photos, not a cyber incident.
Read the article →
31 July 2026
Four AI models converged on the correct figure. Two confidently cited one that doesn't appear to exist anywhere. What a simple verification test reveals about trusting AI-generated statistics.
Read the article →
30 July 2026
Two numbers dominate breach-cost headlines in Australia: $4.26 million and $56,571. Neither is the number a genuine SME should budget against — here’s what the real number is closer to.
Read the article →
Handy Hint Friday Series
29 July 2026
Most IT teams already know they need to patch. The gap is logistics, not awareness. Here's the free, staged rollout that stops one bad update taking out the whole fleet.
Read the article →
Handy Hint Friday Series
23 July 2026
Exchange keeps deleted items for 14 to 30 days. SharePoint gives you 93. Essential Eight expects considerably more. The one control in this series without a fully free fix, and what it costs to close.
Read the article →
The Breach Ledger Series
21 July 2026
A hacked telemarketing vendor cascaded to 70 charities. A ransomware attack sent Brisbane hospitals back to paper for two months. The OAIC doesn’t even track this sector separately — here’s what six named incidents say about the least visible high-risk target in Australia.
Read the article →
Handy Hint Friday Series
17 July 2026
Patching, backups and access controls all assume you know what you're protecting. Most schools have never written that down. Here's the free way to start, and why it's a governance decision, not an IT one.
Read the article →
Handy Hint Friday Series
17 July 2026
“Just turn on MFA” is bad advice for a school. Security Defaults is all-or-nothing across every account, staff and students alike. Here's the governance-safe path, and it forks by licence tier.
Read the article →
The Breach Ledger Series
16 July 2026
Seventy-three NDB notifications in the first half of 2025. A 66 per cent malicious attack rate — well above the national average. From a hedge fund collapse to a credential-stuffing attack on super accounts, here’s what six named incidents say about who’s being hunted.
Read the article →
Updated 7 July 2026
APP 1.4 penalties now reach $66,000 per deficiency. Trust isn’t built in complaint resolution — it’s built in the decisions that happen before a complaint is ever lodged. Here’s what genuine compliance requires from an Australian SME.
Read the article →
Handy Hint Friday Series
3 July 2026
If your IT lead's day-to-day login is also the domain admin account, someone has already accepted a risk on the school's behalf. Here's the free fix, and the licence tier that changes it.
Read the article →
Handy Hint Friday Series
3 July 2026
A free, ready-made Group Policy package covers two Essential Eight controls for schools on Active Directory. Here's what it is, and the one governance question to ask before you import it.
Read the article →
30 June 2026
Two frameworks. Two regulators. One compliance gap. Aged care operators with a clean ACQSC audit may still be fully exposed under the Privacy Act — and most don’t know it.
Read the article →
The Breach Ledger Series
22 June 2026
Thirty-seven NDB notifications in the first half of 2025. An 86 per cent malicious attack rate — the highest of any top-five reporting sector. Nine named incidents across law firms, accountants, and management consultants. Here’s what the data says.
Read the article →
The Breach Ledger Series
12 June 2026
Seven years of named Australian school incidents, OAIC data, and what Loyola, Waverley, and Belmont tell us about who ransomware groups are targeting — and why.
Read the article →
1 June 2026
Approximately 92% of Australian businesses have never had to comply with the Privacy Act. The Tranche 2 reforms will change that. Here’s what it means and where to start.
Read the article →
1 June 2026
Handala wiped up to 200,000 Stryker devices using Microsoft Intune. No zero-day. One compromised admin account. The attack vector is universal — here’s what it means for your organisation.
Read the article →
22 May 2026
Most MSPs deliver solid technical support but leave clients exposed. The modern MSP closes the gap — governance, risk management, and compliance, right-sized for SMEs.
Read the article →
14 May 2026
OAIC's Children's Online Privacy Code is registered 10 December 2026. Independent schools are APP entities. Here's what business managers must do now.
Read the article →
5 May 2026
Healthcare tops Australia's breach charts again. OAIC data shows health led every reporting period since 2018. Here's what the numbers actually mean for private practices.
Read the article →
28 April 2026
Australia's Privacy Act changed on 10 December 2024. New fines, new enforcement powers, new legal liability. Here's what your organisation needs to know now.
Read the article →
Coming soon
Why your MSP shouldn't be your vCISO
The conflict of interest is real, documented, and surprisingly common. Here's what to look for and what to do about it.
Coming soon
Coming soon
What the Cyber Security Act 2024 actually requires - and what it doesn't
A plain-English breakdown of mandatory ransomware reporting, critical infrastructure obligations, and what applies to your organisation.
Coming soon
Coming soon
The Essential Eight in 2025: what actually changed and what it means for your program
The ASD updated the Essential Eight Maturity Model in 2025 — tighter patching windows, phishing-resistant MFA at ML2, and revised application control requirements. What shifted and what it means in practice.
Coming soon
Coming soon
CPS 234 in plain English: what APRA actually wants to see
APRA's information security prudential standard isn't complicated - but the gap between what regulated entities think it requires and what APRA actually looks for is surprisingly wide.
Coming soon
Coming soon
AI governance isn't an IT problem. Here's what your board should be asking.
AI adoption is moving faster than governance frameworks. The boards asking the right questions now will be in a materially better position in 12 months.
Coming soon